Privacy Policy
Personalised Digital Cards Service
Version 2.1 | Effective: 24.07.2026 | Global Edition
1. Data Controller
The data controller of your personal data is: Dominik Maćkiewicz, sole trader operating under the name Blue Code Dominik Maćkiewicz, VAT ID: 5273170548, address: Sokołowska 24/26/32, Warsaw, Poland, email: contact@sendbloom.io ("Controller").
For matters relating to personal data, contact: contact@sendbloom.io
2. What Data We Collect and Why
2a. Order Data (contract performance)
- First and last name or nickname of the Buyer
- Email address or phone number (for delivery of the Card link)
- Data provided for Card personalisation (e.g. recipient's name, private wishes, photos, voice recordings - if provided)
Personal data related to Card personalization (e.g. content of wishes, photos, voice recordings) are stored for the period the Card remains active in accordance with § 5.2 of the Terms of Service, and may be deleted earlier upon the request of the Buyer or recipient in accordance with section 6a below. Data necessary for billing and tax purposes (e.g. proof of transaction, invoice data) are stored for 5 years from the end of the tax year in which the transaction was made, in accordance with applicable tax regulations, regardless of the earlier deletion of other data.
2b. Voice Recordings and Biometric Identifiers
The voice recording feature is not made available to users using the Service from the United States; access to this feature is restricted based on IP location and data declared in the order form. We take technical measures to ensure the voice recording feature is not available to users in the USA. The Customer agrees not to circumvent these safeguards. In the event of an accidental acquisition of a recording from a person in the USA, please contact us immediately, and the data will be deleted.
Where such laws apply, we process voice recordings only with the Buyer's separate, explicit consent obtained at the point of upload, for the sole purpose of creating and delivering the Card. We do not sell, lease, trade, or otherwise profit from voice recordings, and we do not disclose them to third parties except processors strictly necessary to deliver the Service (see Section 3).
Voice recordings are retained only for the Card link validity period described in Section 5, or until the earlier of: (a) the Buyer or recipient requesting deletion, or (b) our internal retention schedule requiring destruction, whichever occurs first - and in any event, we will delete biometric identifiers within a reasonable period after the initial purpose for collection has been satisfied, consistent with applicable biometric privacy law. Buyers or recipients may request earlier deletion at any time by contacting contact@sendbloom.io.
2c. Payment Data (Stripe - separate controller)
Payment card data and transactions are handled exclusively by Stripe Payments Europe Ltd. The Controller does not have access to full card data. Stripe operates as a separate controller - see stripe.com/privacy. For international customers (outside Poland), Stripe also acts as the Merchant of Record, independently processing transaction data to fulfill its legal and tax compliance obligations.
2d. Analytics Data (PostHog - legitimate interest)
We use PostHog, a product analytics tool, to collect anonymous data about user behaviour (e.g. visited pages, clicks, visit duration) via PostHog's EU Cloud servers. You may object to analytics processing via the site's cookie/privacy settings or by contacting us.
2e. Third-Party Personal Data on the Card
If the Buyer provides data relating to a third party (e.g. recipient's name, photo, or voice), the Buyer represents that they have that person's consent or another valid legal basis to provide it. The Controller processes such data based on its legitimate interest in properly performing the Buyer's order. Due to the nature of the service (creating digital surprise cards), directly notifying the third party before delivery would undermine the purpose of the order; where applicable, the Controller relies on the relevant statutory exemption for indirectly-collected data, based on the Buyer's assurance of lawful authority to share it.
2f. Marketing and Abandoned Cart Communications
If you begin creating a Card and provide your email but do not complete checkout, we may send a reminder email and other marketing content based on your voluntary consent. You may withdraw consent at any time via the unsubscribe link in any email or by contacting us; this does not affect the lawfulness of processing before withdrawal.
3. Data Processors
- Supabase Inc. - database, EU servers - order data, wishes, Card metadata
- Cloudflare, Inc. - Cloudflare R2, EU servers - media files (e.g. voice recordings)
- Stripe Payments Europe Ltd. - payment processing (separate controller)
- PostHog Inc. - product analytics, anonymised, EU Cloud
- Cloudflare, Inc. - website hosting
- Resend, Inc. - delivery of Card links
Each processor operates under a data processing agreement and applies appropriate safeguards.
4. International Data Transfers
Data is generally stored within the European Economic Area (EEA). Where a processor (e.g. Stripe, Cloudflare, Resend) is based in or transfers data to the United States, such transfers are based on appropriate safeguards, such as Standard Contractual Clauses approved by the European Commission and/or certification under the EU-U.S. Data Privacy Framework.
5. Data Retention
- Card content (media files, voice recordings, wishes): retained for as long as the Card remains active in accordance with § 5.2 of the Terms of Service; voice recordings specifically are subject to the shorter retention described in Section 2b where biometric privacy law applies.
- Transaction and billing data: retained per tax/accounting law, typically 5 years from the end of the relevant tax year
- Complaint-related data: retained until the applicable claims limitation period expires (generally up to 6 years)
- PostHog analytics data: anonymised, not attributable to an individual
6. Your Privacy Rights
6a. Rights Under the GDPR (EU/EEA/UK Users)
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17), subject to the Controller's legal obligations. With respect to the Card's content, the Buyer may exercise this right at any time in an automated manner using the deletion link provided in the order confirmation email.
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object to processing based on legitimate interest (Art. 21), including analytics
- Right to lodge a complaint with the Polish Data Protection Authority (www.uodo.gov.pl) or your local supervisory authority
6b. Rights Under U.S. State Privacy Laws (e.g. CCPA/CPRA and similar state laws)
If you are a resident of California or another U.S. state with a comparable privacy law, and to the extent that law applies to us, you may have the right to:
- Know what personal information we collect, use, and disclose about you
- Request deletion of your personal information, subject to legal exceptions
- Correct inaccurate personal information
- Obtain a portable copy of your personal information
- Non-discrimination for exercising your privacy rights
- Opt out of the "sale" or "sharing" of personal information - we do not sell personal information for monetary consideration and do not share it for cross-context behavioural advertising
Requests to exercise these rights may be submitted to contact@sendbloom.io. We may need to verify your identity before fulfilling a request. If we deny a request, you may have the right to appeal by replying to our decision email.
6c. Biometric Privacy Rights (e.g. Illinois BIPA and similar laws)
Where applicable biometric privacy law grants you rights regarding voice recordings or other biometric identifiers, you may request access to, or deletion of, such data at any time by contacting contact@sendbloom.io. See Section 2b for our retention practices regarding voice recordings. Due to the restrictions described in Section 2b, the voice recording feature should not be available to U.S. users; if you nevertheless believe your voice recording was collected in violation of this restriction, please contact us immediately at contact@sendbloom.io.
We respond to verified rights requests within the timeframe required by applicable law (generally within 30 days for GDPR requests; U.S. state laws may specify different timeframes).
7. Cookies and Tracking Technologies
The site uses cookies necessary for its operation (session cookies) and PostHog analytics cookies. On your first visit, we display cookie information; you may manage cookies via your browser settings. Disabling analytics cookies does not affect your ability to use the site or view your Card.
8. Data Security
The Controller applies appropriate technical and organisational measures, including HTTPS encryption in transit, access controls on the Supabase database, and limiting access to personal data to what is strictly necessary. Access to the Card's content is protected by a unique, hard-to-guess URL (security through obscurity). Therefore, the Buyer and Recipient are responsible for not sharing the URL with unauthorized persons to prevent unauthorized access.
9. Children's Privacy
The Service may process a child's personal data (e.g., name, wish content containing information about the child) only if provided by an adult with parental authority. By doing so, the adult consents to their use in the card. If you believe a child's data has been provided without a guardian's consent, please contact us at contact@sendbloom.io so we can delete it.
10. Global Users
The Service is directed to users worldwide. Regardless of your location, we apply the GDPR as our baseline privacy standard, and additionally honour specific statutory rights available under your local law (such as the CCPA/CPRA in California or BIPA in Illinois) to the extent those laws apply to us. Data is processed in Poland and the EEA, and in the United States only to the extent authorised sub-processors are used, under the safeguards described in Section 4.
11. Changes to This Policy
The Controller may amend this Policy for legal, regulatory, or technical reasons. The current version is always available at https://sendbloom.io/privacy. Material changes will be notified by email where we hold your email address.
12. Language
This Privacy Policy is prepared in Polish and English. Both language versions are equally binding.
Privacy Policy v2.1 | Global Edition | GDPR & applicable U.S. state law | 24.07.2026