Introduction
eCards Photos ("we," "our," or "us") is a personal project operated by an individual sole proprietor based in Ontario, Canada. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our digital greeting card service at ecardsphotos.com (the "Service").
By using our Service, you agree to the collection and use of information in accordance with this policy. We are committed to protecting your privacy and complying with applicable privacy laws including Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).
Information We Collect
Account Information
When you create an account, we collect:
Card Content
When you create cards, we collect:
Business Information (Business Subscribers)
If you subscribe to the Business tier, we additionally collect:
Technical Data
We automatically collect:
Payment Information
Payment processing is handled entirely by Stripe. We do not store your credit card numbers or banking information. Stripe may collect information necessary to process your payments in accordance with their Privacy Policy.
legal.privacy.collect.usage.title
legal.privacy.collect.usage.content
How We Use Your Information
We use your information to:
- Provide, maintain, and improve our card creation and sharing service
- Process your subscription payments through Stripe
- Authenticate your account and keep it secure
- Enforce usage limits and prevent abuse (rate limiting)
- Analyze usage patterns to improve the Service (via Google Analytics)
- Respond to your requests or questions
- Send important service updates (we do not send marketing emails)
- Display your business branding (logo, name, email, phone, website) on cards you create with a Business subscription, visible to all card recipients
- Track view counts on Business tier cards to provide engagement data to the card creator
Data Retention
We retain your data according to these policies:
When cards expire, all associated photos, content, and embedded business branding are permanently deleted from our servers. Downloaded cards remain on your device and may continue to display business branding that was embedded at creation time.
Data Sharing
We share your information only with:
- Sell your personal information
- Share your data with advertisers
- Use your photos for any purpose other than delivering your cards
Important: If you use a Business subscription, the business contact information you provide (company name, email, phone, website) and your business logo are intentionally displayed on your cards and visible to anyone who views or downloads them. This is a core feature of the Business tier, not an incidental data disclosure.
Your Privacy Rights
Canadian Residents (PIPEDA)
Under Canadian privacy law, you have the right to:
- Access your personal information we hold
- Request correction of inaccurate information
- Withdraw consent for data processing
- Request deletion of your account and associated data
European Residents (GDPR)
If you are in the European Economic Area, you have additional rights to:
- Data portability
- Object to processing
- Restrict processing
- Lodge a complaint with your supervisory authority
California Residents (CCPA)
California residents have the right to:
- Know what personal information we collect
- Request deletion of personal information
- Opt-out of the sale of personal information (note: we do not sell personal information)
- Non-discrimination for exercising your rights
Data Security
We implement appropriate security measures to protect your information, including:
- Encryption in transit (HTTPS/TLS)
- Secure password hashing
- IP address hashing for anonymization
- Regular security updates
- Firebase Security Rules to control data access
- End-to-end encryption for Sealed Cards (AES-256-GCM β your content is encrypted on your device before upload; we never have access to the decryption key)
International Data Transfers
Your information may be processed on servers located outside your country of residence, including in the United States where Google Cloud/Firebase operates data centers. We rely on standard contractual clauses and other appropriate safeguards for such transfers.
Children's Privacy
Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us at:
Email: support@ecardsphotos.com
Location: Ontario, Canada