Privacy Policy

Last updated: 12 July 2026

This Privacy Policy explains the nature, scope, and purpose of the processing of personal data when using the mobile app My Cards (the "App"). My Cards lets you digitally store and manage your own cards and codes (for example loyalty, membership, or barcode/QR cards).


1. Controller

The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is:

NVP Software LLC
2111 Coronet Blvd
Belmont, CA 94002
United States of America (USA)

Email: anton@nvpsoftware.com

Further mandatory information (including authorized representative and phone) can be found in the Legal Notice.

2. Overview of Data Processing

We process personal data only to the extent necessary to provide the App and its features. The App uses Google's Firebase / Google Cloud platform for backend services (authentication, data storage, analytics, crash reporting). Our database (Cloud Firestore) is hosted in a region within the European Union; your account and content data are stored there. Individual services may additionally process data outside the EU (see Section 5).

3. What Data We Process and For What Purpose

a) Account and Authentication

To use the App, a user account is created. This initially happens anonymously; a random user identifier (UID) is generated to associate your cards with your device. Optionally, you can register via:

Purpose: providing a persistent, cross-device account. Legal basis: Art. 6(1)(b) GDPR (performance of a contract / provision of the App's features).

b) Content and Usage Data

To provide the core features, we store the following in our database (Cloud Firestore), in particular:

Purpose: storing and managing your cards. Legal basis: Art. 6(1)(b) GDPR.

c) Analytics and Crash Reports

We use Firebase Analytics and Firebase Crashlytics to understand how the App is used and to fix errors. This may involve processing device and usage information, e.g. device model, operating system version, app version, approximate region (derived from the IP address), event data, and — in the event of an error — crash and diagnostic data.

Purpose: improvement, stability, and security of the App. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a functional, error-free App). Where required by applicable law, we obtain your consent before using non-essential analytics technologies (Art. 6(1)(a) GDPR).

d) Abuse Protection

To protect against abuse, we use Firebase App Check (using Apple DeviceCheck or Google Play Integrity). This verifies whether requests originate from a genuine, unmodified instance of the App.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security and abuse prevention).

4. Disclosure of Data

Your data is only disclosed within the scope of the services mentioned above (Google/Firebase as processors) and where legally required. We do not sell your personal data.

5. Storage Location and Transfers to Third Countries

Our database (Cloud Firestore), where your account and card data are stored, is hosted in a region within the European Union. This data is therefore stored within the EU.

However, certain other services — in particular Firebase Analytics and Firebase Crashlytics — as well as the controller's location (USA) may result in personal data being processed outside the EU, in particular in the USA, or being accessible from there. Appropriate safeguards exist for such transfers, in particular the Standard Contractual Clauses (SCC) approved by the European Commission and — where applicable — certification under the EU-U.S. Data Privacy Framework.

6. Retention Period

We store personal data only for as long as necessary for the stated purposes or as required by statutory retention obligations. Account and content data are stored for the duration of your use of the App and are removed when you delete your account (see Section 8).

7. Your Rights

Under the GDPR, you have the right to:

To exercise your rights, simply send a message to anton@nvpsoftware.com.

8. Deleting Your Account

You can delete your account directly in the App under "Settings → Delete account". This deletes your associated data (including your saved cards, your profile, and your authentication account).

9. Children

The App is not directed at children. We do not knowingly collect personal data from children below the age relevant under applicable law. If we become aware of such data, we will delete it.

10. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in the law or in the App's features. The current version is available in the App or at this address.

11. Contact

If you have any questions about data protection, you can reach us at: anton@nvpsoftware.com