Privacy

Last updated September 22, 2026

The short version

  • We collect only what it takes to make and deliver your card: the names and note you write, a photograph or voice note if you add one, your email address, and a record of your payment.
  • We don’t sell your information, and we don’t run ads. We count how the shop is used, in our own database and with one analytics service, without names, email addresses or anything you write. Nothing is measured on a card’s page.
  • Your card can only be opened by someone who has its link.
  • Stripe handles your payment, so we never see your card number.
  • Email kindnotesapp@gmail.com for a copy of your information, or to have a card deleted.

This summary is here to help. The full text below is what counts.

Who we are

This policy explains how Kindnotes (“we”, “us”, “our”) handles personal information when you make, buy or open a card. It covers the Kindnotes website and the cards it serves. We’re responsible for that information; under European and UK law, we’re its “controller”. Our privacy contact, and the way to reach us about anything here, is kindnotesapp@gmail.com.

What we collect

When you make a card

  • the recipient’s name, how you know them, and whether the card refers to them as “her” or “him”
  • your name
  • your note, greeting and sign-off, and any details you add to the design, such as seal initials, an inscription, a caption or a date
  • a photograph, if you add one to a polaroid or locket card, and a voice note of up to a minute, if you record one; both are part of the card the recipient opens
  • your email address, which we use for your receipt, your links and any notifications you ask for
  • whether you’d like an email when the card is first opened

When you pay

Stripe collects your payment details directly, under its own privacy policy. Stripe may also collect device information to prevent fraud. Stripe tells us whether the payment succeeded and the email address used at checkout. We keep a record of each order: the design, amount, currency, time of payment, that email address and Stripe’s reference number. The payment description Stripe records includes the card design and the recipient’s name.

When a card is used

  • when the card was bought and last changed
  • when it was first opened, and how many times it has been opened

When anyone visits

Like any website, our hosting provider automatically processes technical information to deliver pages and keep the site secure. This includes your IP address, browser and device type, and the pages you request. We don’t use it to build a profile of you.

How the site is used

To see where people get stuck, we keep simple usage records in our own database: which steps of making a card were seen and for how long, which design, look and handwriting were picked, the kind of relationship chosen and whether the card says “her” or “him”, how long a note is (never its words), whether a link was shared, and whether a checkout started, finished (with the amount and any promo code) or was left. Each record carries a random number your browser keeps for that tab (it’s gone when the tab closes), the page’s address with any card or draft id replaced, and the id of the draft or card it belongs to. These records never contain names, email addresses or anything you write, and we delete them after 90 days.

On the shop’s pages we also use DataFast, an analytics service, to learn which video, post or website brought people who went on to buy a card. It receives the pages you visit, where you came from, your browser and device type, and a few milestones (a card started, names added, a checkout started, a card bought, a link shared) with the same kinds of details as above: the design, a count, never a name or a word. When you pay, Stripe passes DataFast the random visitor number from the cookie described under “Cookies and tracking”, so the sale is counted against the visit it came from; DataFast never gets your card number, and nothing you wrote. DataFast doesn’t run on a card’s page, on your edit page or on the demo.

What we don’t collect

We don’t ask for your phone number, mailing address or date of birth. There are no accounts or passwords. There are no advertising or social media trackers on the site.

If someone sent you a card

If you received a Kindnotes card, the sender gave us your name and wrote the note. We use it only to make and show you that card. When you open the card, we record that it was opened and how many times. If the sender asked to be told, we email them once, the first time you open it, with the day and time. We don’t collect anything else about you, and you never need to give us anything.

If you’d like a card addressed to you taken down, email kindnotesapp@gmail.com and we’ll look into it.

If you’re sending a card, please include only what the person you’re writing to would be comfortable with.

How we use it

  • to make, save and show your card, and to let you edit it
  • to take payment and keep records of orders
  • to email your receipt and links, and the opened notice if you asked for it
  • to answer your messages and fix problems
  • to keep Kindnotes secure, prevent fraud and abuse, and enforce our Terms
  • to meet legal obligations, such as tax and accounting rules

We don’t send marketing emails. We don’t sell your information or share it for advertising, and we don’t use what you write to train AI models. We only look at what’s in a card when you ask us for help, when someone reports it, or when we need to fix a problem or comply with the law.

Our legal bases (EU and UK)

  • Contract: to make and deliver the card you bought, take payment, and send your receipt and links.
  • Consent: to email you when your card is opened. You can withdraw consent at any time.
  • Legitimate interests: to show a card to the person it was written for, keep Kindnotes secure, and prevent fraud and abuse.
  • Legal obligation: to keep payment and accounting records.

Who we share it with

We share personal information only with the companies that help us run Kindnotes, and only what each one needs:

  • Vercel hosts the website, handles the technical data of each visit, and counts page views on the shop’s pages without cookies.
  • Convex stores cards, drafts, orders, uploaded photographs and voice notes, and usage records.
  • Stripe processes payments and screens them for fraud.
  • Resend sends our emails.
  • DataFast counts visits to the shop and which video or post brought them, and matches a sale to that visit.

These companies handle information on our behalf, under their own contracts and security commitments.

We may also disclose information when the law requires it, to protect someone’s safety or our rights, or as part of a sale or reorganization of Kindnotes. In a sale, the new owner would have to honour this policy.

A card itself shows the names and words you put in it to anyone with its link. Your email address isn’t part of the card.

Where it’s stored

Our providers store and process information mainly in the United States, and sometimes in other countries. Data protection laws there may differ from those where you live. When information moves from the EU, the UK or Canada, we rely on our providers’ safeguards, such as the European Commission’s Standard Contractual Clauses.

How long we keep it

  • Cards you’ve bought: for as long as the card is live, because its link is meant to last. We delete a card when you ask us to.
  • Drafts you never bought: deleted after 60 days without activity, along with any photograph or voice note uploaded for them. An upload you replaced is deleted within a day.
  • Order and payment records: for as long as tax and accounting law requires. In Canada, that’s generally six years.
  • Technical data from visits: kept briefly by our hosting provider for security and troubleshooting.
  • Your emails to us: for as long as we need them to help you.

After information is deleted, copies can remain in backups for a limited time before they’re overwritten.

Your choices and rights

You can change your card at any time with your edit link. You can also ask us to:

  • give you a copy of the information we hold about you, including in a portable format
  • correct it, or delete it, including deleting a card you bought. A deleted card’s link stops working for good, and deletion isn’t a refund.
  • stop the opened notice
  • limit or stop certain uses of your information

To make a request, email kindnotesapp@gmail.com, ideally from the address you used to buy the card. Because there are no accounts, we’ll need to confirm the card is yours before we act, usually by asking for your edit link. We’ll reply within 30 days. We won’t charge you for making a request, or treat you differently because you made one.

If you’re unhappy with how we’ve handled your information, please tell us. You can also complain to a data protection authority: in Canada, the Office of the Privacy Commissioner; in the UK, the ICO; in the EU, your country’s authority.

California residents

California law gives you the right to know what personal information we collect, and to have it deleted or corrected. We don’t sell or share personal information, as California law defines those terms. We don’t use sensitive personal information to draw conclusions about you.

In the past 12 months, we have collected these categories:

  • identifiers (names, email address, IP address)
  • commercial information (order records)
  • internet activity (technical data from visits and card opens, and the usage records described above)
  • the content of the notes you write

This information comes from you, from the person who sent a card, from Stripe and from your device. We use it for the purposes listed above, and share it for those purposes only with the providers named above. You can make a request yourself or through an authorized agent by emailing kindnotesapp@gmail.com.

Cookies and tracking

Kindnotes doesn’t use advertising cookies. On the shop’s pages, DataFast sets two of its own: a random visitor number kept for a year, so a return visit counts as the same person and a sale can be matched to the visit it came from, and a session number that expires after thirty minutes. Neither holds a name or an email address, and neither is set on a card’s page. We use your browser’s storage only for things the site needs to work: your light or dark display setting, a copy of a card you’re still writing until it’s safely saved (so an edit is never lost), and the random number for the tab described under “How the site is used”. If you add a card to your Home Screen, your device saves a shortcut to that card’s link.

We don’t track you across other websites, and we don’t sell or share your information. That leaves nothing for a Do Not Track or Global Privacy Control signal to switch off.

Security

Cards live at long, random links that can’t practically be guessed. Everything is sent over an encrypted connection, and payments go through Stripe, so card numbers never reach our servers. No system is perfectly secure, so treat your edit link like a password. If a security breach affects your information, we’ll tell you as the law requires.

Children

Kindnotes isn’t meant for children under 13, and we don’t knowingly collect personal information from them. If you think a child under 13 has given us information, email kindnotesapp@gmail.com and we’ll delete it.

Changes to this policy

When we update this policy, we’ll change the date at the top. If a change is significant, we’ll also point it out on the site, or by email if it affects a card you’ve bought.

Contact

For questions about your information or this policy, email kindnotesapp@gmail.com.

TermsPrivacyContact

Copyright ©2026 Kindnotes