1. Scope and Current Product Status
This Privacy Policy explains how Netcarda LLC ("Netcarda," "we," "us," or "our") handles information in connection with www.netcarda.com, free.netcarda.com, plus.netcarda.com, Netcarda account and checkout pages, contact forms, learning and editorial pages, browser-based applications, paid subscription features, and other services that link to this Policy (collectively, the "Service").
This Policy describes Netcarda's current data practices as of the Effective Date. Netcarda Free is local-first and may temporarily send relevant tracker information to Netcarda to perform calculations. Netcarda Plus uses account-based cloud storage and synchronization, recovery copies, account authentication, and the other current processing described below. Features labeled planned, preview, beta, experimental, or "coming soon" are not described as current data collection unless and until they are actually launched.
2. Netcarda Free - Information Stored Locally
Netcarda Free does not require a Netcarda account, bank connection, card number, name, email address, or payment to use the tracker itself.
Depending on the features you use, you may enter cards you want to track, benefit and statement-credit usage, values, dates, annual-fee information, custom-card balances and activity, notes, preferences, card-opening dates, and other tracking information.
The current Free tracker keeps the authoritative copy of this application data on your device. To calculate tracker results, Free may temporarily send relevant tracker information to Netcarda. That processing is used to return the requested calculations and is not intended to create an account-based cloud copy of your Free wallet. Ordinary service and security logs may still be generated as described in Section 8.
Because Netcarda does not maintain an account-based server-side Free wallet, we generally cannot retrieve, restore, correct, export, or delete your authoritative Free tracker state for you after it is lost from your device. You can use available in-product controls and export/import tools and your own browser or device controls.
3. Netcarda Plus - Account and Cloud Data
Netcarda Plus is an account-based subscription service. Depending on the Plus features available to you, Netcarda may receive and store information associated with your account so that Plus data can be persisted, synchronized, secured, supported, and made available across supported sessions or devices.
Plus cloud data may include account identifiers and user-entered tracking information such as cards selected or created, benefit and statement-credit usage, dates, annual-fee information, custom-card balances or activity, notes, preferences, card settings, benefit states, selected items, and other information you choose to store in supported Plus features. Netcarda may also maintain service metadata such as storage usage, timestamps, synchronization or recovery status, and identifiers needed to operate, secure, support, or restore the Service.
Plus may temporarily keep unsaved edits on your device so that a failed or conflicting cloud save can be reviewed and retried. These temporary drafts are not the authoritative long-term Plus store and may be cleared, completed, or expire after a limited period.
Netcarda may maintain encrypted recovery copies of Plus cloud tracker data for service continuity and limited recovery. These copies are generally subject to a limited lifecycle of up to approximately 30 days from creation, but they may be deleted sooner. Netcarda does not guarantee that a recovery copy exists for every moment, includes the latest change, remains available for the full period, or can always be restored successfully.
Netcarda uses third-party cloud providers, including Amazon Web Services ("AWS"), to support hosting, account security, authentication, storage, synchronization, and recovery. Netcarda uses access controls and encryption or other security measures appropriate to the Service, while recognizing that no system can be guaranteed completely secure.
Free and Plus also provide user-controlled portable backup files. Current portable .netcarda backups are encrypted in the browser with a password selected by the user. Netcarda does not store that portable-backup password and cannot guarantee recovery if the password or file is lost.
4. Website, Contact, Support, and Feedback Information
If you use a contact form, email us, request support, report a card change, submit feedback, participate in a survey, or otherwise communicate with Netcarda, we may receive information you choose to provide, such as your name, email address, message, attachments, and related correspondence.
We use this information to respond, provide support, investigate reports, improve Netcarda, maintain records, protect the Service, and communicate with you as appropriate.
5. Account and Authentication Information
For account-based features, Netcarda and its service providers may process information such as your email address, account identifier, verification status, subscription or Plus-entitlement status, billing plan, manual or complimentary entitlement status, authentication status, password-reset requests, session or token information, account status, deletion schedule, legal-acceptance version and timestamp, security events, and related account records.
Netcarda uses third-party account and authentication services to create, authenticate, secure, recover, and administer accounts.
Passwords are handled through the authentication system. Netcarda does not need your bank password to provide the current Free tracker or ordinary Plus cloud tracking features. Netcarda support will not ask you to send your Netcarda password, full payment-card number, card security code, bank-login password, or a one-time verification or password-reset code for the purpose of proving your identity. Enter one-time codes only in the official Netcarda authentication flow.
Self-service email changes are not currently part of the account interface. If you request an email change or lose access to the registered email, Netcarda may request information reasonably necessary to verify account ownership before changing or transferring access. Netcarda may be unable to complete a recovery or email-change request when ownership cannot be reasonably verified.
Netcarda may use strictly necessary cookies or similar technologies for sign-in, account security, and requested account functionality.
6. Transactional Email Services
Netcarda uses Resend (Plus Five Five, Inc.) to deliver transactional and service-related emails such as account-verification codes, password-reset messages, password-change notices, security notices, billing or subscription notices, deletion or retention notices, and other account communications. These operational messages are distinct from promotional marketing email.
To provide these services, Netcarda may provide Resend with information necessary to create and deliver the message, including the recipient email address, message subject and content, and delivery-related metadata. When a verification or password-reset code is contained in the email, that code necessarily forms part of the message content processed by Resend for delivery.
Resend may retain and process message content and delivery information under the terms, security practices, and retention periods that apply to Netcarda's account. Those provider practices may change and are governed by Resend's own terms and policies.
Authorized Netcarda personnel may be able to view transactional-email content or delivery information when reasonably necessary for support, security, abuse prevention, troubleshooting, or other legitimate service administration.
Netcarda does not currently use authentication-focused transactional emails for marketing tracking. If that practice changes materially, Netcarda will update its disclosures as appropriate.
7. Checkout, Subscription, and Payment Information
For live paid subscriptions, Netcarda currently uses Stripe as its third-party payment processor. Payment information may be entered directly into Stripe-hosted or Stripe-enabled checkout rather than stored by Netcarda. If Netcarda changes payment processors, Netcarda will update this Policy as appropriate.
Stripe may process information necessary to complete and secure a transaction, which can include payment-method information, name or contact information supplied at checkout, billing information, transaction details, IP address, device or browser information, and fraud-prevention signals under Stripe's own privacy practices.
Netcarda may receive from Stripe information such as the email used for purchase, Stripe customer or transaction identifiers, subscription plan and status, billing interval, payment and refund status, renewal or access-end dates, limited payment-method descriptors made available by Stripe, and records needed for access provisioning, accounting, fraud prevention, billing support, cancellation, refunds, and legal compliance.
Netcarda Free does not require payment information. Netcarda does not intend to store full payment-card numbers or card security codes on Netcarda systems when those details are handled by Stripe.
Stripe may use necessary technologies within its payment functionality to operate and secure its services, subject to Stripe's own privacy policy and applicable terms.
8. Technical and Network Information
Even when tracker data stays local, visiting an online website or using account or checkout infrastructure can generate technical information needed to deliver and secure the Service.
Netcarda and hosting, content-delivery, domain, security, authentication, email, or network providers may process information such as IP address, request date and time, requested page or file, browser and device type, operating system, referring page, approximate network information, error information, and security or server logs.
We use or permit this processing as reasonably necessary to deliver the Service, diagnose problems, prevent abuse, maintain security, understand operational performance, and comply with law.
9. Cookies, Local Storage, and Similar Technologies
Netcarda uses browser or application storage, strictly necessary cookies, and similar technologies for different Service functions.
In Netcarda Free, local browser storage is used to keep tracker information and preferences on your device. Clearing that storage can erase your Netcarda Free history.
For account-based Plus features, strictly necessary technologies may be used for sign-in, account security, temporary unsaved drafts, limited preferences, abuse prevention, and requested account functionality.
Stripe and other service providers may use their own necessary or service-related technologies when their functionality is loaded. Netcarda does not currently use the Service to sell personal data or for cross-site behavioral advertising.
Because Netcarda currently uses these technologies for local storage, sign-in, security, or other necessary Service functions and does not currently use personal data for cross-site behavioral advertising, Netcarda does not currently present an advertising-cookie consent banner solely for those technologies. If our practices change in a way that requires additional notice, consent, or opt-out controls, we will update our disclosures and controls as appropriate.
10. Card Library, Learn, and Editorial Browsing
You can browse Netcarda card pages, Learn content, guides, and articles without providing the tracker data stored in your Netcarda Free wallet.
Normal website technical logs may still be generated when you browse these pages. If you voluntarily use a contact form or another interactive feature, the information described in this Policy may also be processed.
11. Information We Do Not Intentionally Request
Netcarda Free and ordinary Plus tracking features are not designed to require your bank-login password, Social Security number, government-issued identification number, or full payment-card number as tracker inputs.
Do not place passwords, authentication codes, full payment-card numbers, card security codes, bank-login credentials, Social Security numbers, government identification numbers, or other unnecessary highly sensitive information into notes, custom-card fields, contact forms, or support messages. Netcarda support should not ask you to provide those credentials for identity verification.
Payment-card details used to purchase Plus should be entered through the designated Stripe payment interface, not into Netcarda tracker fields or support messages.
12. How We Use Information We Actually Receive
We may use information received by Netcarda or our service providers to operate and improve the Service; return Free tracker calculations; create, secure, recover, and administer accounts; store, synchronize, and recover supported Plus data; manage Plus access and subscriptions; send service-related communications; provide support; investigate errors or card-data reports; monitor storage and service use; prevent fraud, abuse, and security incidents; enforce Service limits and our Terms; maintain administrative, legal, tax, and accounting records; comply with law; and protect Netcarda, users, and others.
Netcarda does not use Free tracker information temporarily submitted for calculations for advertising or machine-learning training. Current Free processing is used to return tracker calculations and operate the Service; it is not intended to create an account-based cloud copy of the Free wallet.
13. How We Disclose Information and Our Service Providers
We may disclose information we actually receive to service providers that perform functions for us, subject to applicable contractual and legal obligations.
Current operational providers include Amazon Web Services ("AWS") for hosting, cloud infrastructure, and authentication-related services; Resend (Plus Five Five, Inc.) for transactional email delivery; and Stripe for payment processing, subscription billing, fraud prevention, and related payment services. These providers may engage their own subprocessors or service providers under their respective terms and privacy programs.
We may disclose information when reasonably necessary to comply with law, legal process, or valid governmental requests; investigate fraud, abuse, or security incidents; enforce agreements; or protect rights, property, and safety.
If Netcarda is involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar corporate transaction, information in Netcarda's possession may be transferred as part of that transaction subject to applicable law.
Netcarda does not sell personal data. Netcarda does not currently share personal data for cross-context behavioral or targeted advertising.
14. Third Parties
The Service refers and links to third-party card issuers, banks, merchants, payment networks, app stores, payment processors, and other services. Their privacy practices are governed by their own policies, not this Policy.
Third-party names, logos, and card products appearing in Netcarda do not mean those companies receive your locally stored Netcarda Free wallet data.
15. Data Retention, Subscription Expiration, and Deletion
Locally stored Free tracker data remains on your device until you delete it, reset Netcarda, clear the relevant browser or application storage, or the data is otherwise removed or lost. Netcarda does not maintain an account-based authoritative server copy of that Free wallet. Temporary evaluation requests are processed as described in Sections 2, 8, and 12, but that processing does not create a server-side recovery copy of your Free wallet.
For Plus, Netcarda retains account and cloud data while reasonably necessary to provide account-based functionality and any applicable paid or complimentary Plus entitlement. If a paid Plus subscription ends and is not renewed, Netcarda may restrict paid Plus access at the end of the prepaid period and retain the associated account and cloud data for a limited period to permit account administration, renewal, support, security review, or orderly deletion.
Under Netcarda's current implementation, active Plus account and cloud data associated with an ended paid subscription are ordinarily scheduled for deletion fourteen (14) days after paid Plus access ends, unless the account has another active entitlement, a different period is disclosed in the Service, retention is reasonably necessary for security, fraud prevention, legal, tax, accounting, dispute, or backup purposes, or applicable law requires otherwise. After the applicable period, Netcarda may delete or de-identify account and cloud records that are no longer reasonably necessary.
Deletion from active systems does not necessarily remove every copy at the same moment. Encrypted Plus recovery copies may remain for a limited period after active account data is removed and are generally retained for no more than approximately 30 days from creation, but they may be deleted sooner. Residual recovery copies are not an active account, are not guaranteed to remain available or recoverable, and are used only for limited recovery, security, continuity, or legal purposes as appropriate.
Administrative and security audit records may be kept longer than active tracker data, generally for up to about 13 months, to support accountability, security investigations, troubleshooting, and compliance. Billing, tax, fraud-prevention, dispute, or legal records may be retained for longer where reasonably necessary or required by law.
Resend, Stripe, AWS, and other providers may retain information under their own contractual, legal, security, backup, or fraud-prevention retention requirements. Netcarda does not control every independent retention obligation of those providers.
If you affirmatively request account deletion through the current account-deletion flow, Netcarda requires confirmation, cancels an active directly billed Stripe subscription, removes the authentication identity and active Plus cloud state, and processes related account records according to the deletion workflow and applicable law. Deletion may be irreversible. Encrypted recovery copies, audit records, billing records, or other limited residual records may remain for the retention periods described in this Policy. Creating a new account later, including with the same email address, does not restore the deleted active cloud state. Export information you want to keep before confirming deletion.
16. Security and Administrative Access
Netcarda uses reasonable administrative, technical, and organizational safeguards appropriate to the nature of information in its possession and the architecture of the Service. No website, device, network, software, storage system, or transmission method can be guaranteed completely secure.
The local-first Free architecture reduces the amount of user-entered Free tracker data Netcarda centrally possesses. Plus cloud functionality necessarily requires Netcarda and its service providers to store and process account-associated data to provide the service.
Authorized Netcarda personnel may access account information and, when reasonably necessary for support, security, abuse investigation, recovery, enforcing Service limits, legal compliance, account administration, or deletion, Plus cloud data or recovery materials. Sensitive access is restricted to authorized purposes and may be recorded in administrative or security audit logs.
Netcarda may investigate suspected misuse, unusually large or abnormal storage use, attempts to abuse the Service, or activity that threatens Netcarda, users, or infrastructure. When practical, Netcarda may use service metadata such as storage usage and update information before accessing customer tracker content. Netcarda may restrict, suspend, or delete accounts or data as permitted by the Terms and applicable law.
Netcarda relies in part on third-party infrastructure and security services, but Netcarda remains responsible for configuring and administering its own Service and access controls appropriately.
Netcarda may maintain administrative and security audit records that document sensitive account or staff actions for accountability, security, troubleshooting, abuse prevention, and compliance. These records are not intended to contain customer passwords or full payment-card numbers.
If Netcarda identifies a security incident, Netcarda may take steps to investigate and contain it, secure affected access, work with relevant service providers, preserve information needed for the response, and provide notices to affected individuals or government authorities when required by applicable law.
Use strong, unique passwords, protect your devices and exported files, and do not enter unnecessary sensitive credentials into Netcarda.
17. Your Choices and Privacy Requests
For locally stored Free tracker data, you can generally review, edit, export where available, or delete the data using Netcarda and your browser or device controls. Because Netcarda may not possess that local data, sending us a privacy request cannot necessarily recover or delete it.
For Plus cloud data and other personal information Netcarda possesses, you may use available account controls or contact us to request information, correction, or deletion where available or required by applicable law. We may need to verify your identity before fulfilling certain requests.
Canceling a paid Plus subscription and deleting a Netcarda account are different actions. Cancellation generally stops future renewal while paid access continues through the applicable paid period. Netcarda provides customer-facing cancellation through the account and billing experience, including Stripe-hosted billing controls where available. Under the current directly billed account-deletion flow, deletion cancels an active Stripe subscription immediately, stops future renewal charges, removes the authentication identity and active Plus cloud data, and does not automatically refund prior payments. Residual recovery copies and limited records may remain under the retention periods described above. Complimentary or administratively granted Plus access may exist independently of Stripe billing and may be changed or revoked by Netcarda.
Privacy requests may be sent to contact@netcarda.com.
18. U.S. State Privacy Laws
Privacy rights differ by state and depend on factors such as where you live, the type and amount of data processed, and whether a particular law applies to Netcarda.
The Texas Data Privacy and Security Act generally exempts qualifying small businesses from most of its controller requirements, while retaining a restriction on the sale of sensitive data without consumer consent. Netcarda does not sell personal data.
Netcarda will evaluate additional state-law obligations as the Service grows or its data practices change. We do not state that every privacy right listed in another company's policy automatically applies to every Netcarda user; where applicable law grants you a right, Netcarda will honor that right as required.
19. Global Privacy Control and Other Browser Signals
Netcarda does not currently sell personal data or use personal data for cross-site behavioral advertising. Accordingly, there is currently no sale or targeted-advertising activity within Netcarda for a Global Privacy Control signal to opt out of.
If Netcarda's practices change in a way that makes Global Privacy Control or another legally recognized opt-out signal relevant, we will update our controls and disclosures as appropriate.
20. Children
The Service is intended for users age 18 and older. It is not directed to children under 13, and Netcarda does not knowingly collect personal information online from children under 13 through the Service.
If we learn that we collected personal information from a child under 13 in circumstances covered by applicable law, we will take appropriate steps to delete it. A parent or guardian may contact us with a concern.
21. United States Focus
Netcarda is operated from the United States and is presently designed primarily for U.S. users and U.S. card products. We do not currently promise that all Netcarda infrastructure or service providers are located exclusively in the United States unless that has been verified for the relevant system.
If Netcarda intentionally expands into jurisdictions that require materially different privacy disclosures or mechanisms, we will update this Policy as appropriate.
22. Changes to This Privacy Policy
We may update this Policy as Netcarda, our vendors, technology, staff administration tools, or law changes. The current Policy will display an effective or last-updated date.
If we materially change how we collect, use, disclose, retain, or provide administrative access to personal information, we will provide additional notice or obtain consent where required by law.
23. Contact
For privacy questions or requests, contact contact@netcarda.com.
Netcarda LLC
Website: www.netcarda.com