Privacy Policy
Last updated 6 August 2026 · Effective 6 August 2026
Carded reads the barcode on an identification document on the device to determine whether a Guest meets a venue's age threshold. It retains only a de-identified record — a one-way hash, an age bracket, and the result. It does not retain a name, date of birth, document number, or image, and it does not verify that a document is genuine. This Summary is provided for convenience only and is qualified in its entirety by the full text below.
1. Introduction and scope
This Privacy Policy (the “Policy”) describes how Page Craft LLC, a North Carolina limited liability company (“Carded”, “we”, “us” or “our”), collects, uses, discloses, and otherwise processes Personal Data in connection with the Carded mobile application (the “App”), the associated backend services, and the website at which this Policy is posted (together, the “Service”). This Policy is incorporated into and forms part of our Terms of Service. By accessing or using the Service, you acknowledge that you have read and understood this Policy.
Capitalised terms used but not defined in a given section have the meanings given in Section 2. In the event of any conflict between the Summary above and the body of this Policy, the body governs.
2. Definitions
- “Operator” means a venue owner, manager, or member of door staff who is authorised to use the Service on behalf of a venue.
- “Guest” means an individual whose identification document is scanned by an Operator using the App.
- “Personal Data” (also “Personal Information”) means any information relating to an identified or identifiable natural person, as such terms are defined under applicable data protection law, including the EU and UK General Data Protection Regulation (“GDPR”) and the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the “CCPA”).
- “Scan Record” means the de-identified record generated when an Operator scans an identification document, as described in Section 5.
- “Subject Hash” means the one-way cryptographic value described in Section 6.
- “Sub-processor” means a third party engaged by us to process Personal Data on our behalf.
3. Our role as controller and processor
For the purposes of the GDPR and analogous laws, we act as a controller with respect to Personal Data relating to Operators and their accounts, and to venue configuration data (Sections 4 and 8). With respect to Scan Records generated at a venue, the venue is the controller of that data and, to the extent any Scan Record constitutes Personal Data, we act as a processor on the venue's behalf and process such data only in accordance with the venue's instructions and our agreement with it. It is our good-faith position that the Subject Hash is de-identified and does not, by itself, identify any Guest; nothing in this Policy is an admission that the Subject Hash constitutes Personal Data.
4. Personal Data we process about Operators
To establish and administer accounts and to provide the owner dashboard, we process the following categories of Personal Data relating to Operators:
- Account identifiers. The stable user identifier issued by Apple through Sign in with Apple, and a contact email address. Apple provides the email address to us only upon the Operator's first authorisation; the Operator may thereafter change it.
- Venue configuration. Venue and door names, the applicable age threshold, the retention window, and join or pairing codes. This is operational configuration entered by the venue and is not Guest data.
- Staff roster information. Display names that a venue enters for its own staff, together with role assignments.
- Device and technical data. A device label (for example, “iPhone 14 · iOS 18”), application and operating-system version, and a last-seen heartbeat, used for security, provisioning, and support.
- Diagnostic data. Crash, energy, and performance reports generated by Apple's on-device MetricKit framework. We do not incorporate any third-party analytics or crash-reporting software development kit in the Service.
- Billing data. Subscription status and the associated transaction identifier, as further described in Section 9. Payment card details are collected and processed by Apple and are not received by us.
5. How Guest identification documents are processed
The Service is engineered to minimise the processing of Guest Personal Data by design and by default. When an Operator scans a Guest's identification document, the following applies:
- On-device barcode reading. The App uses the device's rear camera solely to read the PDF417 barcode encoded on the reverse of a United States driver's license or state identification card. That barcode is the entirety of the read.
- No image is captured or retained. The App does not photograph, save, cache, log, or transmit any image of an identification document at any time.
- Transient, on-device parsing. The data fields encoded in the barcode (which may include name, date of birth, document expiry, and document number) are parsed in volatile memory on the device, are used to compute the age verdict, and, subject to a venue setting, may be displayed momentarily to enable the Operator to address the correct individual. Such data is discarded upon dismissal of the verdict and is never written to persistent storage, logged, exported, or transmitted.
- What is retained. The only information retained in respect of a scan is the Scan Record, comprising: the Subject Hash; an age bracket (over or under the applicable threshold); the result (for example, pass, under-age, or expired); the issuing jurisdiction; and the time, door, device, staff member, and threshold in force. No name, date of birth, document number, or image is retained, whether on the device or on our servers.
- No authenticity determination. The App reads the data encoded in a barcode. It does not inspect the physical document, does not authenticate it, and does not determine whether an identification document is genuine, borrowed, or altered.
6. The Subject Hash
The Subject Hash is a salted SHA-256 value derived from the identification document's country, issuing jurisdiction, and document number, computed on the device prior to any transmission. The Subject Hash is one-way and cannot be reversed to recover a document number or to identify a Guest. It is salted on a per-venue basis, such that the same document does not produce a correlatable value across different venues. The Subject Hash is used solely to: (a) recognize that the same document has been presented more than once within a single period at one venue; (b) compare against a venue's own list of flagged records; and (c) compute returning-versus-new counts for that venue. The Subject Hash is not associated with any Apple identifier, device, or account, and is not used to track any individual across applications or businesses.
7. Legal bases for processing (EEA and United Kingdom)
Where the GDPR applies, we rely on the following legal bases under Article 6(1) of the GDPR:
- Performance of a contract (Article 6(1)(b)) — to create and administer Operator accounts, provide the Service, and process subscriptions.
- Legitimate interests (Article 6(1)(f)) — to secure, maintain, and improve the Service, to prevent fraud and abuse, and to provide aggregate reporting to venues, in each case where such interests are not overridden by your interests or fundamental rights.
- Compliance with a legal obligation (Article 6(1)(c)) — where processing is necessary to comply with applicable law or a valid legal request.
- Consent (Article 6(1)(a)) — where we specifically request it; you may withdraw consent at any time as described in Section 14.
8. Purposes of processing
We process Personal Data for the following purposes:
- to compute and display an age verdict at the point of entry;
- to provide venues with scan totals, denial counts, and returning-versus-new trends derived from de-identified counts, and not from Guest identities;
- to operate, secure, troubleshoot, and improve the Service;
- to communicate with account holders regarding the Service, billing, and support; and
- to comply with law and to establish, exercise, or defend legal claims.
We do not use Scan Records or any Guest data for advertising, and we do not sell or rent Personal Data. See Section 10.
9. Disclosure of Personal Data and Sub-processors
We disclose Personal Data only to the limited categories of recipients set out below, and subject to appropriate contractual and security safeguards:
- Supabase — our backend infrastructure provider (managed database, authentication, and server-side functions). Supabase processes Scan Records and Operator configuration data as our Sub-processor. It does not receive Guest identification data.
- Apple Inc. — in connection with Sign in with Apple (authentication) and the Apple App Store and StoreKit (subscription billing and payment processing).
- Legal and governmental authorities — where disclosure is required by law, regulation, legal process, or an enforceable governmental request. Because Guest identification data is not retained, it cannot be produced.
- Successors in interest — in connection with, or during negotiations of, a merger, acquisition, financing, reorganization, or sale of assets, in which case Personal Data may be transferred subject to the commitments in this Policy.
We do not incorporate advertising networks, data brokers, or third-party tracking technologies in the Service.
10. No sale or sharing of Personal Data
We do not, and will not, sell Personal Data, and we do not share Personal Data for cross-context behavioural advertising, as those terms are defined under the CCPA. In the twelve (12) months preceding the effective date of this Policy, we have not sold or shared Personal Data. We do not use or disclose sensitive Personal Information for purposes other than those permitted under the CCPA.
11. International data transfers
We are established in the United States, and our infrastructure processes Personal Data in the United States. Where we transfer Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, we implement appropriate safeguards, such as the European Commission's Standard Contractual Clauses, where and as required by applicable law.
12. Data retention
Scan Records are retained for the retention window configured by each venue and constitute that venue's compliance records. We retain Operator account and configuration data for as long as the relevant account remains active and thereafter for such period as is reasonably necessary to comply with our legal, tax, and accounting obligations and to establish, exercise, or defend legal claims. Because no Guest identity is retained, there is no Guest Personal Data available for us to export, correct, or delete.
13. Information security
We maintain administrative, technical, and organizational measures designed to protect Personal Data, including on-device computation of the Subject Hash (using Apple CryptoKit), encryption of data in transit using Transport Layer Security, per-venue isolation of stored data through row-level security controls, and storage of the per-venue salt in the device Keychain, which is not synchronised to iCloud. No method of transmission or storage is completely secure; however, by design the Service does not retain identification documents, thereby removing the most sensitive category of data from the Service entirely.
14. Your rights (EEA and United Kingdom)
Subject to the conditions and exceptions in applicable law, individuals in the EEA and the United Kingdom have the following rights in respect of their Personal Data:
- Access (Article 15) — to obtain confirmation of whether we process your Personal Data and a copy of that data, together with information about the processing.
- Rectification (Article 16) — to have inaccurate Personal Data corrected and incomplete data completed.
- Erasure (Article 17) — to have your Personal Data deleted where one of the grounds set out in the GDPR applies.
- Restriction (Article 18) — to obtain a restriction of processing in certain circumstances.
- Data portability (Article 20) — to receive Personal Data you have provided to us in a structured, commonly used, and machine-readable format, and to have it transmitted to another controller where technically feasible.
- Objection (Article 21) — to object to processing carried out on the basis of our legitimate interests, on grounds relating to your particular situation.
- Withdrawal of consent (Article 7) — to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
- Complaint — to lodge a complaint with your local supervisory authority.
We will respond to a request without undue delay and in any event within one (1) month of receipt, which period may be extended by up to two (2) further months where necessary, taking into account the complexity and number of requests.
15. Your rights (California)
Subject to the conditions and exceptions in the CCPA, California residents have the right to:
- Know and access the categories and specific pieces of Personal Information we have collected, the sources of that information, the purposes for collecting it, and the categories of recipients;
- Delete Personal Information we have collected from you, subject to statutory exceptions;
- Correct inaccurate Personal Information;
- Opt out of the sale or sharing of Personal Information (note that we do not sell or share Personal Information, as stated in Section 10);
- Limit the use and disclosure of sensitive Personal Information (note that we do not use sensitive Personal Information for purposes requiring such a right); and
- Non-discrimination — to not receive discriminatory treatment for exercising any of these rights.
You may use an authorised agent to submit a request on your behalf, subject to our verification of the agent's authority.
16. Categories of Personal Information (California notice at collection)
In the twelve (12) months preceding the effective date of this Policy, we have collected the following categories of Personal Information, as defined by the CCPA. We collect this information from Operators and from the devices they use, for the business purposes described in Section 8, and we disclose it only to the recipients described in Section 9.
| CCPA category | Examples we process | Collected? |
|---|---|---|
| A. Identifiers | Apple user identifier, contact email address, device label, application identifiers | Yes (Operators) |
| B. Customer records | Contact email and staff display names associated with an account | Yes (Operators) |
| F. Internet or network activity | Diagnostic, crash, and performance data; device heartbeat | Yes (Operators) |
| Commercial information | Subscription status and transaction identifier | Yes (Operators) |
| Biometric information | None — no facial, fingerprint, or other biometric data is collected | No |
| Precise geolocation | None — the Service does not collect location data | No |
| Sensitive Personal Information (Guest identity) | None retained — name, date of birth, document number, and image are processed transiently on-device and discarded | No |
17. How to exercise your rights
To exercise any of the rights described in Sections 14 and 15, please contact us at hello@pagecraftllc.com. For the security of your data, we may request information sufficient to verify your identity before acting on a request. We will not discriminate against you for exercising any of your rights. Because we do not retain Guest identities, requests concerning Guest data generally cannot be actioned, as no such data exists in our records.
18. Children
The Service is intended for use by licensed venues and their authorised personnel and is not directed to children. Indeed, the Service exists to assist venues in preventing entry by under-age individuals. We do not knowingly collect Personal Information from children, and we do not knowingly permit any person under the age of eighteen (18) to hold an Operator account. If we become aware that we have inadvertently collected Personal Information from a child, we will take reasonable steps to delete it.
19. Changes to this Policy
We may amend this Policy from time to time. When we do, we will revise the “Last updated” date above and post the revised Policy at this location. Where changes are material, we will provide additional notice to account holders as appropriate or as required by law. Your continued use of the Service following the effective date of a revised Policy constitutes your acknowledgement of the revised Policy.
20. How to contact us
The data controller responsible for your Personal Data is Page Craft LLC, a North Carolina limited liability company. If you have any question, request, or complaint regarding this Policy or our processing of Personal Data, please contact us at hello@pagecraftllc.com.
See also our Terms of Service.