🔒 Privacy Policy

Papir Card System

Last Updated: March 2026
Transparency Promise: We collect minimal data necessary to provide our Service. We never sell your personal information. Our data retention practices follow a tiered approach designed to balance functionality, privacy, and legal compliance. This policy is designed to meet or exceed requirements under GDPR, CCPA, PIPEDA, and India's DPDP Act.

1. Information We Collect

1.1 Information You Provide

Data Type Purpose Required
Email Address Account creation, notifications, deletion verification For registered users
Uploaded Media To display on your AR cards Yes, for card creation
Card Metadata File names, sizes, types Automatic with uploads
Payment Information Processing subscriptions (processed by Stripe/PayPal) For paid plans only
Terms Acceptance Legal record of consent (permanently stored) For card activation

1.2 Automatically Collected Information

1.3 QR Code Scan Data

When someone scans your QR code, we collect:

2. Data Retention Policy TIERED APPROACH

We follow a tiered retention strategy that balances operational needs, user privacy, and legal requirements. Backup data is encrypted and inaccessible for normal operations.

Data Category Retention Period Rationale Security Measures
Active Card Content
Media, messages, metadata
Until card deleted by user Core service delivery Encrypted at rest, access logged
IP Addresses (Activation)
Terms acceptance records
Permanent (legal hold) LEGAL Proof of terms acceptance, fraud prevention, legal compliance (GDPR Article 7) Encrypted, access restricted to legal/security team only
Scan Logs
Visitor IPs, timestamps, device info
30 days → then permanently anonymized (IP removed) Analytics + privacy balance (industry standard) Automatic anonymization process, cannot be reversed
User Activity Logs
Feature usage, errors
90 days Operational debugging and improvement Stored in separate secured database
Account Data
Profile, email, preferences
Until account deletion request User control and service delivery Encrypted, requires authentication to access
Payment Transaction Logs 7 years LEGAL Sarbanes-Oxley Act, tax law compliance Processed by Stripe/PayPal, we only store reference IDs
Backup Data 30 days maximum, encrypted, not used for any operational purpose Disaster recovery only, inaccessible for normal operations Encrypted, stored in separate secure location, access requires two-person approval
Inactive Accounts 24 months without access → deletion notice sent → 30 days to respond → permanent deletion Data minimization (GDPR Article 5(1)(e)) Automated review process with human verification
EU User Data (GDPR) As needed only, deleted when purpose fulfilled, maximum 30 days after account deletion GDPR Article 5(1)(e) - storage limitation Separate handling process for EU residents
India User Data 3 years after last use (DPDP Act requirement) DPDP Act compliance Automated deletion process at 3-year mark
📌 Important Legal Notice: IP addresses collected during card activation (when you accept terms) are permanently retained as legal proof of consent. This is required by GDPR Article 7(1) which states that "Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data." All other IP addresses are anonymized after 30 days.

3. How We Use Your Information

4. Data Storage & Security

4.1 Storage Locations

4.2 Security Measures

5. Third-Party Services

We share necessary data with the following service providers. Each has been vetted for security and compliance:

Service Purpose Data Shared Their Certification Their Privacy Policy
Supabase Database & Storage Media files, metadata, IPs SOC 2 Type 2 supabase.com/privacy
Railway.app Hosting Server logs, IP addresses SOC 2 Type 2 railway.app/legal/privacy
Stripe Payment Processing Payment details (not stored by us) PCI DSS Level 1 stripe.com/privacy
PayPal Payment Processing Payment details (not stored by us) PCI DSS Compliant paypal.com/privacy
QR Code API QR Generation Card URLs only - Not retained by service

6. Your Rights & Choices

6.1 Access & Correction

You can access and update your account information through your profile settings. For additional requests, email privacy@papir.ca.

6.2 Data Export (Data Portability)

You have the right to receive a copy of your data in a machine-readable format (JSON/CSV). To request an export:

  1. Email privacy@papir.ca with subject line "Data Export Request"
  2. Include your Card ID or registered email address
  3. We will verify your identity via email response
  4. You will receive your data within 30 days (GDPR requirement)
  5. Exports are provided free of charge once per year

6.3 Data Deletion (Right to Erasure)

To request deletion of your personal data:

  1. Email privacy@papir.ca with subject line "Data Deletion Request"
  2. Include your Card ID or registered email address
  3. We will verify your identity via email response
  4. We will process your request within 30 days and send confirmation
  5. Deletion confirmation will include what was removed and what (if anything) was retained for legal reasons

Important deletion limitations:

6.4 Opt-Out Options

6.5 Right to Restrict Processing

You may request that we restrict processing of your data in certain circumstances (e.g., while disputing accuracy). Contact privacy@papir.ca.

7. Cookies & Tracking

We use minimal cookies, all strictly necessary for functionality:

You can control cookies through your browser settings. Blocking essential cookies may affect functionality.

8. Children's Privacy (COPPA & GDPR Compliance)

Our Service is not intended for children under 13 (or 16 in Europe). We do not knowingly collect data from children under these ages. If we discover we have collected data from a child under the applicable age:

If you are a parent and believe your child has provided data to us, please contact us immediately.

9. International Data Transfers

Data may be processed in Canada, the US, or other countries where our service providers operate. We ensure adequate protection through:

10. Regional Rights

10.1 European Users (GDPR)

10.2 California Users (CCPA/CPRA)

For CCPA requests, email privacy@papir.ca with "CCPA Request" in subject line. We will verify your California residency.

10.3 Indian Users (DPDP Act)

10.4 Canadian Users (PIPEDA)

11. Reporting Inappropriate Content ABUSE REPORTING

If you encounter a card that violates our Terms of Service or contains illegal content:

Our abuse team is trained to handle sensitive content and will escalate to law enforcement if required by law.

12. Data Breach Notification

In the unlikely event of a data breach affecting your personal information:

13. Data Protection Officer

We have appointed a Data Protection Officer (DPO) who oversees our compliance with data protection laws:

14. Contact Information

For privacy concerns, data requests, or general questions:

15. Changes to This Policy

We will notify users of significant changes:

16. Legal Compliance Summary

We comply with the following regulations:

📌 Your Rights Summary: You have the right to access, correct, export, and delete your data. You can report abuse at abuse@papir.ca. We retain activation IPs permanently for legal proof of consent as required by law. All other data is retained per the retention table above. Questions? Contact our DPO at dpo@papir.ca.