Privacy policy

Privacy Policy

Last updated: April 5, 2026

CardForge ("we," "us," or "our") operates the CardForge mobile application and the website at thecardforge.com. This Privacy Policy explains how we collect, use, and protect your personal information when you use our app and services.

By using CardForge, you agree to the collection and use of information as described in this policy.

Information We Collect

1. Account Information
When you create an account, we collect your email address and password (stored securely via Supabase Auth). If you sign in with Google, we receive your Google account name and email address through Google OAuth. We do not receive or store your Google password.

2. Bluetooth Device Identifiers
When you pair a label printer, we collect Bluetooth device identifiers (device name and MAC address) to establish and maintain the connection. This data is stored locally on your device only.

3. Imported Spreadsheet Data
When you upload CSV or spreadsheet files for label generation, we process the data you provide (e.g., product names, card numbers, conditions, prices). This data is used solely to generate labels and is stored on your device and in your Supabase account.

4. Print History and Label Designs
Your print queue, label templates, and pricing rule configurations are stored locally on your device and may be synced to your Supabase account for backup and cross-device access.

5. Subscription Information
If you subscribe to CardForge Pro, we store your subscription status. Payment processing is handled entirely by Apple (App Store), Google (Play Store), or Shopify — we do not collect or store your payment card details.

How We Store Your Data

- On-device storage: Bluetooth device identifiers, print history, label designs, and imported data are stored locally on your device using AsyncStorage.
- Cloud storage: Account information, label templates, and pricing profiles are stored in Supabase, which is hosted on Amazon Web Services (AWS) infrastructure.
- We use industry-standard security measures including encrypted connections (HTTPS/TLS) and secure authentication tokens.

How We Use Your Information

We use your information exclusively to:
- Create and manage your account
- Enable Bluetooth printer pairing and communication
- Process your imported data to generate labels
- Store your label templates and pricing configurations
- Manage your subscription status

We do NOT use your information for:
- Advertising or marketing to third parties
- User profiling or behavioral tracking
- Analytics or usage tracking beyond basic app functionality

Third-Party Services

We use the following third-party services:

Service Purpose  Data Shared
Supabase Authentication and cloud storage Email, account data, label templates
Google Sign-In OAuth authentication Email, account name (via Google)
Apple / Google Play Subscription management Subscription status only
Shopify Website and store hosting None from the app


We do not sell, rent, or share your personal information with any other third parties. We do not use any advertising SDKs, analytics trackers, or data brokers.

Data Retention

We retain your data for as long as your account is active. If you delete your account, we will delete your personal data from our servers within 30 days. Locally stored data on your device is removed when you uninstall the app.

Your Rights

Depending on where you live, you may have the right to:

- Access the personal information we hold about you
- Correct inaccurate information
- Delete your account and associated data
- Export your data in a portable format
- Opt out of any future data processing changes

To exercise any of these rights, contact us at the email address below.

Account Deletion

You can delete your account at any time from the Profile screen within the app. This will:
- Remove your authentication credentials from Supabase
- Delete your cloud-stored label templates, pricing profiles, and account data
- Locally stored data will remain on your device until you uninstall the app

Children's Privacy

CardForge is not intended for use by children under 13 (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.

International Data Transfers

Your data may be processed and stored in regions outside your country of residence, including the United States (where AWS infrastructure is located). By using CardForge, you consent to the transfer of your data to these regions. We ensure appropriate safeguards are in place in accordance with applicable data protection laws.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date. Continued use of CardForge after changes constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at:

Email: contact@thecardforge.app
Website: https://thecardforge.app