Privacy Policy
Table of contents
1. Information we collect
GoodCard collects only what is needed to operate accounts, issue virtual cards and record spending:
- Account details: name, email address and phone number.
- Security data: password (stored only as a one-way hash), two-factor authentication settings, one-time codes, and login session records including IP address, device and browser.
- Card and spending data: card name, expiry, the last four digits, spending limits, wallet balance and budget movements.
- Transaction data synchronized from our card issuing partner: merchant name and category, amount, currency, status, decline reason and timestamps.
2. What we never store
We do not store full card numbers (PAN) or card security codes (CVV) anywhere in our database, cache or logs. When card details are revealed, they are retrieved from the card issuing partner for that single view over an encrypted connection and are discarded immediately afterwards.
3. How we use your information
- To create and manage your account, wallet and card group.
- To issue, pause, resume and close virtual cards, and to enforce spending limits.
- To record budget allocations and reconcile transactions against the card issuing partner.
- To send security notifications (one-time codes, password resets) and operational notifications about your cards and budget.
- To detect and prevent fraud, unauthorized access and misuse of the platform.
4. How we protect your information
- All traffic is encrypted in transit using TLS.
- Passwords are hashed one way; API credentials are encrypted at rest.
- Access is restricted by role-based permissions, and sensitive actions require re-authentication and are written to an activity log.
- Sensitive values are scrubbed from application logs.
5. Sharing your information
We do not sell, rent or trade personal information. Information is shared only:
- With our regulated card issuing partner, to the extent required to issue cards and process payments;
- With administrators of your organization, who can see the wallets, cards and transactions they manage;
- With email delivery and notification providers, limited to what is needed to deliver a message;
- Where required by law or by a valid request from a competent authority.
6. Data retention
Account, card and transaction records are retained while the account is active and afterwards for as long as required for accounting, audit and legal obligations. Login session records are retained for a limited period for security review.
7. Your choices
You can review and update your profile details, manage two-factor authentication, and sign out active sessions from your profile page. To request access to, correction of, or deletion of your personal data, contact an administrator of your organization.
8. Cookies
We use cookies strictly to keep you signed in, protect forms against cross-site request forgery, and remember interface preferences such as language and theme. We do not use cookies for advertising. Blocking cookies in your browser will prevent you from signing in.
9. Changes to this policy
We may update this policy as the service evolves. Changes take effect when published on this page.
Questions about these terms? Contact us at support@goodcard.io.