This Privacy Policy explains how SocialCards collects, uses, stores, and shares personal data when you visit social.cards, create an account, use the SocialCards application, purchase a subscription, contact us, or otherwise interact with our services.
1. Who we are
SocialCards is operated by:
Vatasoiu Marius-Leonard PFA, trading as SocialCards
CUI: 29255045
Trade Registry number: F2011001190285
Registered office: Beica nr. 15, Salcia, Olt, 237411, Romania
Email: [email protected]
Vatasoiu Marius-Leonard PFA is the data controller for the personal data described in this Privacy Policy, except where another provider acts as an independent controller for its own services.
2. Personal data we collect
2.1 Account and authentication data
When you create or use a SocialCards account, we may process:
- your name;
- your email address;
- your internal account identifier;
- your authentication method;
- your account type and subscription access;
- login, session, and security information;
- the date your account was created or updated.
When you register or sign in using Google or GitHub, we receive information made available by that provider, which may include your name, email address, profile image, and provider-specific account identifier.
SocialCards does not receive your Google or GitHub password.
For email-and-password accounts, passwords are processed through our authentication system and stored only in hashed form. We cannot read or recover your existing password. Password-reset tokens are short-lived and become unusable after they are used or expire.
2.2 Content and service data
When you use SocialCards, we may process:
- images and files you upload;
- images and social preview cards you create;
- text, titles, descriptions, links, templates, and branding settings;
- saved projects;
- branded redirect and preview links;
- custom subdomains;
- API keys, API configuration, and API usage;
- information about actions performed within your account.
You are responsible for ensuring that you have the necessary rights and lawful basis to upload or process any content or personal data belonging to another person.
2.3 Billing and subscription data
When you purchase or manage a SocialCards subscription, we may receive:
- your name and email address;
- your selected plan;
- transaction and subscription identifiers;
- subscription status;
- renewal, expiration, trial, or cancellation dates;
- refund, payment-failure, or dispute status;
- limited order and billing information.
SocialCards does not receive or store your complete payment-card number.
Paid subscriptions are sold and processed through Creem, which acts as merchant of record. Creem processes payments, issues invoices, calculates and collects applicable indirect taxes, and provides the customer billing portal. Creem processes buyer information under its own privacy notice.
2.4 Technical and usage data
When you access SocialCards, we may automatically process:
- IP address;
- browser and device type;
- operating system;
- requested pages and URLs;
- referring page;
- request date and time;
- application activity;
- API requests and usage limits;
- error and diagnostic information;
- security and fraud-prevention events;
- approximate country or region derived from the IP address.
2.5 Communications
When you contact us, we may process:
- your name and email address;
- the content of your request;
- any attachments you send;
- the date and history of our communication;
- our response and any follow-up correspondence.
3. How and why we use personal data
We process personal data for the following purposes:
| Purpose | Legal basis |
|---|---|
| Creating and managing your account | Performance of our contract with you |
| Authenticating you and maintaining secure sessions | Performance of contract and legitimate interests in securing the service |
| Providing image creation, links, custom domains, templates, storage, and API functionality | Performance of contract |
| Processing and managing subscriptions | Performance of contract |
| Sending password-reset, security, billing, and essential service emails | Performance of contract and legitimate interests |
| Providing customer support | Performance of contract and legitimate interests |
| Preventing fraud, abuse, attacks, and unauthorized access | Legitimate interests and, where applicable, legal obligations |
| Monitoring service reliability and diagnosing technical problems | Legitimate interests |
| Enforcing usage limits and our Terms of Service | Performance of contract and legitimate interests |
| Maintaining accounting, tax, and legal records | Compliance with legal obligations |
| Sending optional newsletters or promotional messages | Consent |
| Using non-essential analytics or marketing cookies | Consent, where required |
Where we rely on legitimate interests, we consider whether those interests are overridden by your rights and freedoms.
You may withdraw consent at any time. Withdrawal does not affect processing carried out lawfully before consent was withdrawn.
4. Authentication providers
SocialCards supports authentication through:
- email and password;
- Google;
- GitHub.
When you choose Google or GitHub, that provider also processes your information under its own terms and privacy policy.
SocialCards receives only the information needed to identify you, create or access your account, and provide the requested authentication functionality.
Using an external authentication provider does not give SocialCards access to your password for that provider.
5. Payments through Creem
Creem acts as merchant of record for paid SocialCards subscriptions.
Creem is responsible for:
- processing your payment;
- managing payment methods;
- calculating and collecting applicable taxes;
- issuing invoices and receipts;
- providing its customer billing portal;
- processing payment-related refunds, disputes, and chargebacks.
SocialCards remains responsible for providing, maintaining, and supporting the SocialCards product.
Creem and SocialCards may each act as independent data controllers for the personal data they process for their respective purposes. In some circumstances, Creem may also process data on behalf of SocialCards under its data-processing terms.
6. Service providers and recipients
We may share personal data with service providers that help us operate SocialCards, including:
- Cloudflare, for DNS, security, content delivery, and network protection;
- Google and GitHub, when you use their authentication services;
- Creem, for subscription, payment, tax, invoicing, and billing services;
- transactional email providers used to deliver account, password-reset, security, and service messages;
- monitoring, logging, backup, and security providers;
- professional advisers, including accountants, lawyers, and auditors;
- public authorities where disclosure is required by law.
Service providers may access personal data only to the extent necessary to provide their services or comply with their own legal obligations.
We may also disclose information:
- to investigate fraud, abuse, or security incidents;
- to establish, exercise, or defend legal claims;
- in connection with a merger, restructuring, transfer, or sale of the business;
- where you have instructed or authorized us to do so.
We do not sell your personal data.
7. International data transfers
Some service providers may process personal data outside Romania or the European Economic Area.
Where applicable, transfers are protected using legally recognized mechanisms such as:
- European Commission adequacy decisions;
- Standard Contractual Clauses approved by the European Commission;
- other safeguards permitted under applicable data-protection law.
You may contact us at [email protected] for information about the safeguards relevant to a particular transfer.
8. Data retention
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy.
The following retention periods normally apply.
Account information
Account and profile data is retained while your account remains active.
After an account-deletion request is completed, account data is normally removed from active systems within 30 days, except where continued retention is necessary for security, legal compliance, fraud prevention, disputes, or accounting obligations.
Uploaded and generated content
Uploaded files, generated images, saved projects, links, and custom-domain configurations are retained until:
- you delete them;
- you delete your account;
- the applicable feature or storage period ends;
- deletion is necessary to enforce our Terms of Service.
Following account deletion, this content is normally removed from active systems within 30 days.
Backups
Deleted data may remain in encrypted or access-restricted backups for up to an additional 30 days before being overwritten through the regular backup cycle.
Backups are used for disaster recovery and are not normally restored to recover individual user records.
Application and security logs
Routine application, API, and security logs are normally retained for up to 90 days.
Relevant records may be retained for up to 12 months or for the duration of an investigation where necessary to:
- investigate a security incident;
- prevent fraud or abuse;
- enforce our Terms of Service;
- establish or defend legal claims.
Password-reset and verification information
Password-reset and verification tokens are retained only until they:
- are used;
- expire;
- are replaced by a newer request;
- are no longer required for security purposes.
Support communications
Support requests and related correspondence are normally retained for up to 2 years after the issue is resolved.
They may be kept longer where necessary for an ongoing dispute, legal claim, fraud investigation, or statutory obligation.
Billing and accounting information
SocialCards retains its own subscription, payout, and accounting records for the statutory period applicable under Romanian law.
Accounting records are generally retained for 5 years, calculated from 1 July of the year following the financial year in which they were created.
Creem independently retains buyer, payment, invoice, and transaction data according to its own legal obligations and privacy policy.
Consent and unsubscribe records
Where processing is based on consent, we may retain a limited record of:
- when consent was provided;
- what the user consented to;
- when consent was withdrawn;
- unsubscribe or suppression status.
This information may be kept for as long as reasonably necessary to demonstrate compliance and ensure that withdrawn marketing consent is respected.
9. Account and data deletion
You may request deletion of your SocialCards account and personal data by emailing:
We may request reasonable information to verify that the request relates to your account.
Deleting your SocialCards account does not necessarily delete:
- information that must be retained to comply with legal obligations;
- records required for fraud prevention or security;
- records necessary to establish or defend legal claims;
- information independently retained by Creem for invoicing, payments, tax, or regulatory compliance;
- data temporarily remaining in disaster-recovery backups.
Where only part of the data must be retained, we will restrict its use to the relevant legal or security purpose.
10. Cookies and similar technologies
Essential cookies
SocialCards uses essential cookies and similar storage technologies for:
- authentication;
- session management;
- security;
- user preferences;
- maintaining application state;
- cookie-consent preferences.
These technologies are necessary for SocialCards to function and generally cannot be disabled through our cookie settings.
Analytics and other non-essential cookies
Where analytics or other non-essential technologies are enabled, they are used to understand how SocialCards is used, diagnose problems, and improve the service.
Where required by law, non-essential cookies are activated only after you provide consent.
You may refuse or withdraw consent through the cookie settings available on the website. Refusing non-essential cookies does not prevent you from using core SocialCards functionality.
The cookie-consent interface should provide current information about the cookies in use, including their:
- name;
- provider;
- purpose;
- duration;
- essential or optional status.
11. Email communications
We may send essential messages relating to:
- account authentication;
- password resets;
- security events;
- billing and subscription status;
- service availability;
- important changes affecting your account;
- responses to support requests.
These messages are part of providing and securing the SocialCards service and are not promotional marketing.
Optional promotional emails are sent only where permitted by law. You may unsubscribe from promotional emails using the link included in the message or by contacting [email protected].
Unsubscribing from promotional communication does not prevent us from sending essential account or service messages.
12. Your data-protection rights
Subject to applicable law, you may have the right to:
- receive information about how your personal data is processed;
- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- request deletion of your data;
- request restriction of processing;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- receive certain information in a structured, commonly used, machine-readable format;
- have that information transmitted to another controller where technically feasible;
- withdraw consent at any time;
- lodge a complaint with a data-protection authority;
- request human intervention where a legally significant decision is made solely through automated processing.
These rights may be subject to legal limitations, including where information must be retained to comply with a legal obligation or establish or defend a legal claim.
Requests may be sent to:
We may need to verify your identity before responding. We will respond within the period required by applicable data-protection law.
13. Complaints
You may lodge a complaint with the data-protection authority in the country where you live or work, or where you believe a violation occurred.
In Romania, the competent authority is:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal — ANSPDCP
B-dul General Gheorghe Magheru nr. 28–30
Sector 1, 010336 Bucharest, Romania
Email: [email protected]
Telephone: +40 31 805 92 11
We encourage you to contact us first at [email protected] so that we have an opportunity to address your concern.
14. Security
We use reasonable technical and organizational measures designed to protect personal data against:
- unauthorized access;
- accidental or unlawful disclosure;
- alteration;
- loss;
- destruction;
- misuse.
These measures include, where appropriate:
- encrypted connections;
- password hashing;
- access controls;
- authentication and session-security measures;
- restricted administrative access;
- logging and abuse detection;
- backups and recovery procedures;
- security updates.
No internet service or storage method can guarantee absolute security.
You are responsible for keeping your credentials and API keys confidential and for notifying us promptly if you believe that your account has been compromised.
15. Personal data uploaded by users
SocialCards may be used to upload or process content that contains personal data relating to other people.
Where you upload or process such information, you are responsible for:
- having an appropriate lawful basis;
- providing any notices required by law;
- respecting the rights of the affected individuals;
- avoiding the upload of unnecessary or unlawfully obtained personal data.
SocialCards processes this content only as necessary to provide, secure, and maintain the requested service, subject to our Terms of Service and any applicable data-processing agreement.
16. Automated decision-making
SocialCards does not use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects on users.
Automated systems may be used to:
- detect abuse or suspicious activity;
- enforce technical limits;
- identify fraudulent requests;
- protect the security and availability of the service.
Where an account is restricted automatically, you may contact [email protected] to request a review.
17. Children
SocialCards is not directed to children under the age of 16.
We do not knowingly collect personal data from children under 16 without appropriate authorization. If you believe that a child has provided personal data to SocialCards, contact [email protected] so that we can investigate and take appropriate action.
18. Changes to this Privacy Policy
We may update this Privacy Policy when:
- SocialCards features change;
- we use new service providers;
- our processing activities change;
- legal or regulatory requirements change.
The current version will be published on this page with an updated revision date.
Where a change materially affects users, we may also provide notice through SocialCards or by email.
19. Contact
For questions, requests, or complaints relating to privacy or personal data, contact:
Vatasoiu Marius-Leonard PFA
Trading as SocialCards
CUI: 29255045
Trade Registry number: F2011001190285
Beica 15, Salcia, Olt, 237411
Romania
Email: [email protected]