Last updated: July 26, 2026 · ICO Registration: ZB[XXXXXX]
This Privacy Policy is our mandatory transparency notice under UK GDPR Articles 13 & 14 and the Data Protection Act 2018. CardStack (“we”, “our”, “us”) is the data controller. We are committed to handling your personal data lawfully, fairly, and transparently. By using the CardStack platform, you acknowledge you have read this notice. Please read it carefully.
CardStack Technologies Ltd ("CardStack", "we", "our", "us") is the data controller of personal data processed through this platform.
Company Name: CardStack Technologies Ltd Registered Address: 1 Platform Street, London, EC2V 8RF, United Kingdom Company Registration: England & Wales, No. 12345678 ICO Registration Number: ZB[XXXXXX] Email: privacy@cardstack.app
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing our compliance with UK data protection law. You can contact our DPO at:
DPO Email: dpo@cardstack.app DPO Post: FAO Data Protection Officer, CardStack Technologies Ltd, 1 Platform Street, London, EC2V 8RF
For EU/EEA data subjects, our EU Representative (required by UK GDPR Art 27 / EU GDPR Art 27) can be contacted at eu-privacy@cardstack.app.
We collect the following categories of personal data:
Account & Identity Data: Full name, email address, username, date of birth, nationality, and profile photograph. Collected when you register.
Contact Data: Email address, postal address, and phone number. Used for account communications and legal notices.
Financial Data: Wallet addresses, transaction history, token balances, payment method details (processed via PCI-DSS-compliant processors — we do not store full card numbers, only tokenised references). Bank account details where fiat on/off-ramp services are used.
Identity Verification (KYC) Data: Government-issued photo ID (passport, driving licence), proof of address (utility bill, bank statement), biometric data where facial recognition is used for liveness checks. Collected under the legal obligation lawful basis (MLRs 2017). This is special category data under UK GDPR Art 9 — biometric data used for unique identification — and is processed under DPA 2018 Schedule 1 para 8 (employment, social security, and social protection law) as applied to our legal AML obligations.
Usage & Technical Data: IP addresses, browser type and version, operating system, device identifiers, pages visited, click-stream data, session duration, and referral URLs. Collected automatically via cookies and server logs.
Communications Data: Support tickets, chat messages, feedback, and any other correspondence you send to us.
Marketing Preferences: Your consent choices for marketing communications and cookie categories.
We process your personal data for the following purposes and on the following lawful bases:
Providing the platform and services — Lawful basis: Contract (Art 6(1)(b)). Processing is necessary to perform our contract with you (Terms of Service).
Identity verification (KYC/AML) — Lawful basis: Legal obligation (Art 6(1)(c)). Required by MLRs 2017 Reg 27 and the Reporting Cryptoasset Service Providers Regulations 2025.
Fraud prevention and security — Lawful basis: Legitimate interests (Art 6(1)(f)). Our legitimate interest in protecting our platform and users from fraud, abuse, and security threats. Balancing test: the processing does not outweigh your interests and fundamental rights given that it directly protects you.
HMRC Reporting (CARF) — Lawful basis: Legal obligation (Art 6(1)(c)). Required by the Reporting Cryptoasset Service Providers Regulations 2025 — we must report account and transaction data to HMRC annually.
Regulatory compliance and law enforcement — Lawful basis: Legal obligation (Art 6(1)(c)). Includes POCA 2002 SAR reporting, SAMLA sanctions screening, FATF Travel Rule compliance.
Improving our services and analytics — Lawful basis: Legitimate interests (Art 6(1)(f)). Our legitimate interest in understanding how users interact with the platform to improve it. Only anonymised or pseudonymised data is used where possible.
Marketing communications — Lawful basis: Consent (Art 6(1)(a)). Only where you have given explicit consent. You may withdraw consent at any time via the unsubscribe link in any marketing email or by emailing privacy@cardstack.app.
Resolving disputes and enforcing our Terms — Lawful basis: Legitimate interests (Art 6(1)(f)).
We retain personal data for the minimum period necessary, consistent with our legal obligations:
Account Data: For the duration of your account, plus 7 years after account closure (UK HMRC record-keeping requirements under the Taxes Management Act 1970 s.12B and the Companies Act 2006 s.386).
Transaction Records: Minimum 5 years, or 7 years where required by HMRC for tax purposes. Financial record-keeping is mandated by MLRs 2017 Reg 40(1).
KYC/AML Records: Minimum 5 years after the end of the business relationship (MLRs 2017 Reg 40(1)(b)), or longer if directed by the NCA or FCA.
CARF Reporting Data: Minimum 5 years from the date of report submission (Reporting Cryptoasset Service Providers Regulations 2025, Reg 10).
Usage/Analytics Data: 26 months (Google Analytics default) or anonymised after 13 months.
Marketing Preferences and Consent Records: Until you withdraw consent plus 3 years (to evidence compliance with the consent requirement).
Support Communications: 3 years from last contact.
You may request deletion of your data under Art 17 (Right to Erasure). However, we may decline or partially fulfil such requests where retention is required by law (e.g., AML records cannot be deleted before the statutory minimum period has elapsed).
Under UK GDPR, you have the following rights. You can exercise any of these by contacting privacy@cardstack.app. We will respond within 30 days (extendable to 90 days for complex requests, with notice).
Right of Access (Art 15): Obtain a copy of the personal data we hold about you, along with information about how we process it.
Right to Rectification (Art 16): Request correction of inaccurate or incomplete data.
Right to Erasure / Right to Be Forgotten (Art 17): Request deletion of your data. This right is not absolute — we may retain data where legally required (e.g., AML records).
Right to Restriction of Processing (Art 18): Request that we limit processing of your data in certain circumstances (e.g., while you contest accuracy).
Right to Data Portability (Art 20): Receive a structured, commonly used, machine-readable copy of data you provided to us, processed by automated means on the basis of contract or consent.
Right to Object (Art 21): Object to processing based on legitimate interests or for direct marketing purposes. We must cease direct marketing immediately upon objection — no exceptions.
Rights Related to Automated Decision-Making (Art 22): If we use solely automated processing (including profiling) that produces legal or similarly significant effects on you, you have the right to request human review.
Right to Withdraw Consent (Art 7(3)): Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.
Right to Lodge a Complaint: If you are unhappy with our response, you may lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk, 0303 123 1113.
Identity Verification: To protect your data, we may ask you to verify your identity before fulfilling a request.
We use automated processing in the following contexts:
Sanctions Screening: Your name, date of birth, and country of residence are automatically screened against OFAC, UN, EU, and OFSI sanctions lists upon account registration and periodically thereafter. A positive match may result in immediate account restriction. You have the right to request human review of any automated sanctions decision.
Transaction Monitoring (AML): Automated systems analyse transaction patterns to detect suspicious activity consistent with money laundering or terrorist financing. Automated flags may trigger enhanced due diligence or account restrictions. Reviewed by a human compliance officer before action is taken.
Risk Scoring: We may calculate a risk score for your account based on your transaction history, verification level, and behavioural patterns. This score is used internally to prioritise compliance reviews. We do not use risk scores to make fully automated credit or investment decisions.
If you believe an automated decision has been made about you incorrectly, you may request human review by contacting compliance@cardstack.app.
We implement the following technical and organisational measures (TOMs) to protect your personal data, consistent with UK GDPR Art 32:
- Encryption at rest: AES-256 encryption for all personal data stored in our databases and object storage. - Encryption in transit: TLS 1.2+ for all data transmitted between your device and our servers. TLS 1.3 where supported. - Access controls: Role-based access control (RBAC) limiting employee access to personal data to those with a need-to-know. All access is logged and audited. - Multi-factor authentication: MFA enforced for all employee access to production systems. - Penetration testing: Annual third-party penetration testing of all internet-facing systems. - Data minimisation: We collect only the minimum data necessary for each processing purpose. - Pseudonymisation: Where feasible, we pseudonymise personal data used in analytics and development environments.
Despite these measures, no internet service is completely secure. You are responsible for maintaining the confidentiality of your account credentials. Contact security@cardstack.app immediately if you suspect unauthorised access to your account.
The CardStack platform is not directed at individuals under the age of 18. We do not knowingly collect personal data from persons under 18 years of age. If we become aware that we have inadvertently collected personal data from a minor, we will delete it promptly.
Under UK GDPR Art 8, processing of personal data relating to under-13s on the basis of consent requires parental authorisation. We implement age verification as part of our KYC process to prevent under-18s from registering.
If you believe a minor has provided personal data through our platform, contact us immediately at privacy@cardstack.app with the subject line "Minor Data — Urgent".
We may update this Privacy Policy from time to time to reflect changes in our data practices, legal obligations, or regulatory guidance. The "Last Updated" date at the top of this page indicates when the current version was published.
For material changes (e.g., new processing purposes, new data sharing recipients, or changes that affect your rights), we will provide advance notice by email (to the address on your account) at least 30 days before the changes take effect. Continued use of the platform after the effective date constitutes acceptance of the updated policy.
We recommend reviewing this policy periodically. Previous versions are available on request from privacy@cardstack.app.
For questions, requests, or complaints about this Privacy Policy or our data practices:
Data Protection Officer: dpo@cardstack.app Privacy Team: privacy@cardstack.app Post: CardStack Technologies Ltd, Data Protection Officer, 1 Platform Street, London, EC2V 8RF
If you are not satisfied with our response to a complaint, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
ICO Website: ico.org.uk ICO Helpline: 0303 123 1113 ICO Address: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
For EU/EEA residents, complaints may also be lodged with your local supervisory authority. Our EU Representative can direct you to the appropriate authority: eu-privacy@cardstack.app.
Supervisory Authority — Information Commissioner's Office (ICO)
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the ICO, the UK's independent data protection authority. You can contact the ICO at ico.org.uk or by calling 0303 123 1113.