Privacy Policy

Last updated: August 15, 2026

1. What Cardifier is

Cardifier tracks credit card spending and cashback for people holding several cards in Vietnam. It captures transactions from bank alert emails you choose to forward, computes the cashback each one actually earns under your card's rules, and checks that against what the bank billed and credited. This policy explains what that requires us to collect and what we do with it.

2. What we collect

Account information.Your email address and password (or your Google account identifier, if you sign in with Google) via Supabase Auth. We never see your password in plain text — it's hashed by our authentication provider before it reaches us.

Card and transaction data. Card details you enter yourself (bank, card name, last 4 digits, statement day, credit limit, cashback rules) and transactions, either entered manually or extracted from bank alert emails you forward to your personal ingest address.

From forwarded bank emails, specifically: we parse the email to extract structured fields — merchant, amount, date, time, and which card it belongs to. Those fields land in your account; the email itself is not stored. Every automatically-parsed transaction sits in a review queue until you approve it — nothing from an email is treated as real spending without your confirmation.

Usage data.If you see error reports or product-analytics tooling mentioned in section 4 below active for your account, they may record that a feature was used (e.g. "a card was added") or that something crashed — see that section for exactly what is and isn't sent.

3. What we never collect

  • Your online/mobile banking username or password.
  • Full card numbers, CVV, or PIN.
  • One-time passcodes (OTPs) or any other bank authentication code.

Cardifier only ever sees the alert emails you choose to forward — never your bank account itself. There is no integration with any bank that requires your banking credentials.

4. Who we share data with

We do not sell your personal data, to anyone, for any purpose. We use a small set of infrastructure providers to run the service, each with a narrow, specific job:

  • Supabase— our database, authentication, and hosting provider. Every table that holds your data is scoped to your account at the database level (row-level security), not just in the app — another account's server request cannot read your rows even if the app had a bug.
  • Netlify — hosts the web app and API.
  • Cloudflare — routes forwarded bank alert emails to our ingest endpoint if you use the email-forwarding setup, and provides the CAPTCHA challenge on sign-up/sign-in forms.
  • Brevo — sends transactional email (account confirmation, password reset, and — only if you use it — the shared-expense settlement emails you explicitly choose to send).
  • Sentry (error monitoring) and PostHog(product analytics) — used, where enabled, to catch bugs and understand which features are actually helping people get set up. Both are configured deliberately narrowly for a finance app: no session recording, no automatic capture of clicks or field contents, and no transaction amounts, merchant names, or card numbers are ever sent to either. PostHog only records a short, fixed list of named events (e.g. "an account was created," "a card was added") tied to an anonymous account id, never your email.

Each of these providers is contractually restricted to using your data only to provide their service to us — not for their own purposes.

5. What's stored on your device

To make the app feel instant on reopen, some aggregate figures (like your monthly spend and cashback totals per card) are cached in your browser's local storage. Raw transaction rows, the cashback ledger, and payment records are deliberately excluded from that cache — they are never written to local storage in plain form, specifically because they're the most sensitive data in the app. Signing out clears everything Cardifier stored in your browser.

6. Account deletion

You can delete your account yourself from Settings, at any time, with no need to contact us. Deletion is immediate and permanent: every row tied to your account — cards, transactions, the cashback ledger, statements, everything — is removed by a database-level cascade the moment your account is deleted, not by a background job that might lag behind.

7. Your rights

Wherever you are, you can ask us to access, correct, or delete the personal data we hold about you, or ask us to stop processing it. Most of this you can already do yourself in the app — editing your cards and transactions directly, or deleting your account per section 6. For anything else, or if you are in a jurisdiction that grants you additional statutory rights (including under the EU's GDPR or Vietnam's personal data protection regulations), contact us using the details below and we will respond.

8. International data transfer

Our infrastructure providers (section 4) operate data centers outside Vietnam. Using Cardifier means your data may be processed on servers in other countries as a normal part of how those providers run their services.

9. Children

Cardifier is not directed at, and is not intended for use by, children.

10. Changes to this policy

If we make a material change to how we handle your data, we'll update the date at the top of this page and, where the change is significant, notify you by email.

11. Contact us

Questions about this policy, or want to exercise a data right beyond what's self-service in the app? Reach us at:

legal@cardifier.cloud