Privacy
Privacy Notice
How BlackCards handles website visitor, prospect, account, staff, and loyalty-program data.
Last updated July 28, 2026
1. Our role
BlackCards acts as a controller for website, account, billing, security, and sales-contact data. For loyalty-member data submitted by a business customer, BlackCards generally acts as that customer’s processor or service provider under the applicable data-processing terms.
2. Data we handle
Depending on the interaction, we process:
- Account identity, organization, role, locale, authentication, and session data.
- Plan, subscription, invoice, payment status, and provider references; full card details remain with the payment processor.
- Loyalty member, pass, balance, visit, redemption, consent, and campaign data supplied by a customer.
- Support, audit, security, and operational event data.
- Demo-request name, work email, company, optional website, requirements, locale, and contact consent.
- Consent-gated first-party page-view and conversion events linked only to an opaque visitor digest.
3. Why we use data
We use data to provide and secure the service, authenticate users, enforce tenant and plan boundaries, process billing, issue and update passes, provide support, respond to requested sales contact, meet legal obligations, prevent abuse, and—only with consent—understand public-site conversion.
4. Cookies and analytics
Essential cookies support security, sessions, locale, and consent preferences. Optional analytics is disabled by default. If allowed, BlackCards records a small allowlist of first-party events and does not store raw IP addresses or user agents in the marketing event store. We do not use this data to build third-party advertising profiles.
5. Sharing and processors
Data is shared only as needed with contracted infrastructure, database, authentication, payment, communications, and wallet-service providers; professional advisers; a successor in a lawful transaction; or authorities where legally required. We do not sell personal information.
6. Retention and security
We retain data only for the service, contract, fraud-prevention, audit, tax, dispute, and legal periods that apply, then delete or de-identify it. Controls include encryption in transit, access restrictions, tenant isolation, audit logging, credential separation, and least-privilege administration. No system can promise absolute security.
7. International transfers and rights
Where data crosses borders, the responsible party must use an appropriate legal transfer mechanism. Depending on location, individuals may request access, correction, deletion, restriction, portability, objection, or withdrawal of consent, and may complain to a regulator. Some rights are subject to lawful exceptions.
8. Children, changes, and contact
BlackCards is a business service and is not directed to children. Material notice changes will show a revised date. Privacy requests may be submitted through the contact form; identity verification may be required.