隐私政策

最后更新时间:2026 年 6 月
01

数据控制者

对于客户数据(商户/机构账户)及平台运营,数据控制者为 Riyad El Otmani(MANI CONSEIL),SIRET 106 929 375 00017。联系方式:contact@getkard.fr

For Cardholder data collected within a Customer’s programme, the Customer is generally the controller and KARD acts as processor under the GDPR, following the Customer’s instructions and applicable contractual documentation.

02

收集的数据

Customers / Users: identity, email, business or organisation details, preferences, technical login logs, billing and subscription data.

Cardholders (depending on Customer setup): first name, last name, phone, email where applicable, visit history, points, stamps, sessions, benefits, and data needed to issue/update the Wallet card.

Technical data: cookies/trackers required for operation, server logs, diagnostics, within the limits below.

03

目的与法律依据

Providing and improving the Service, account management, support, billing and fraud prevention: contract performance and/or legitimate interest.

Service-related (transactional) communications: contract performance. KARD marketing to Customers: legitimate interest or consent where required.

Push notifications and Customer communications to Cardholders: under the Customer’s responsibility; legal bases determined by the Customer.

Legal obligations (accounting, authority requests): legal obligation.

04

接收方与处理者

Data may be accessed by authorised KARD staff and providers acting on its behalf, including hosting (Vercel), database/infrastructure (Supabase), payments (Stripe), and where needed messaging or analytics tools strictly required.

Providers act only on instruction under appropriate contractual safeguards. Data is not sold.

05

向欧盟以外的传输

Some providers may be located outside the European Economic Area (including the United States). Where required, KARD relies on recognised mechanisms (standard contractual clauses, adequacy decisions or other appropriate safeguards).

06

保存期限

Customer account data: for the contractual relationship, then archiving/deletion within a reasonable period, subject to legal obligations (including accounting).

Cardholder data: according to the Customer’s instructions and programme duration; deletion or anonymisation after account closure or a valid request, unless a legal obligation requires otherwise.

Technical logs: kept only as needed for security and diagnostics.

07

安全

KARD implements reasonable technical and organisational measures to protect data (access control, encryption in transit where applicable, isolation, backups per infrastructure).

No system is infallible; Customers and Users must also protect their credentials and devices.

08

个人权利

Under the GDPR you have rights of access, rectification, erasure, restriction, objection, portability where applicable, and the right to withdraw consent.

For data processed by KARD as controller: contact@getkard.fr. For Cardholder data managed for a business/club: contact that Customer first; KARD may assist the Customer in handling the request.

You may lodge a complaint with the CNIL (https://www.cnil.fr) or your local supervisory authority.

09

Cookie 与追踪器

The site may place strictly necessary cookies (session, authentication, language preference, security).

Where applicable, analytics or marketing cookies are placed only with your consent when required by law. You can manage choices in your browser settings and, where available, the cookie banner.

10

变更

This policy may be updated to reflect Service or regulatory changes. The version in force is the one published on the site.

Questions: contact@getkard.fr.

对这些文件有疑问?

contact@getkard.fr →