Unboring Card

Last updated: 2 August 2026

Privacy Policy

This privacy policy describes how Unboring Card processes personal data. It is a draft for the described service and should be legally reviewed before publication.

1. Controller

The controller responsible for data processing on this website is Oliver Lauckner, Am Stichkanal 45, 14167 Berlin, Germany.

Contact: info@unboringcard.com

2. What Unboring Card does

Unboring Card lets registered users create a personal Hero Page, add images, contact details, highlights, projects, and other profile content, and publish or unpublish it with a switch.

Users can also design a personal business card and order it through the shop. Payments are processed via Stripe; cards are shipped to the delivery address provided by the user.

3. Data we process

During registration and use, we process in particular names, email addresses, password hashes, verification status, session and security data, cookie settings, and the contents of the Hero Page and card design.

For card orders, we process order data, product and pricing information, invoice and payment status, Stripe references, delivery address, email address, optional customer notes, and the card design snapshot required for production.

For a mockup or contact request, we process the name, email address, message, and optionally company and phone number. Where available, we also store the campaign parameters utm_source, utm_medium, utm_campaign, utm_content, and utm_term, together with the time and version of the privacy acknowledgement.

To protect the request form against abuse, we use a daily rotating hash created with a server secret from technical request characteristics. The raw IP address is not stored in the lead database; older hash values are removed from request records.

If a Hero Page is published, the profile content released by the user is available at the public URL. If the Hero Page is set to private, it is no longer publicly reachable through the profile route.

4. Purposes and legal bases

We process data to provide the account, editor, publishable Hero Page, card designer, shop, payment processing, order fulfillment, communication, and technical security.

Request data is processed to handle the requested contact and to take pre-contractual steps. The required form confirmation records that the privacy notice was acknowledged; optional campaign parameters are used to attribute the request source.

Processing takes place, where required, for contract performance or pre-contractual steps, to comply with legal obligations, on the basis of legitimate interests in secure and stable operation, or on the basis of consent, for example for optional analytics and insight features.

5. Hosting, database, and payments

The website is hosted by Vercel. Technically necessary access data may be processed, for example IP address, access time, requested resources, browser and device information, and technical logs.

Application data is stored in a Supabase Postgres database. This includes account data, Hero Page content, card designs, orders, contact requests, and cookie settings.

Payments are processed via Stripe. The data required for payment, fraud prevention, invoicing, and payment confirmation is transmitted to or processed by Stripe. Payment data such as complete credit card numbers is not stored by us.

6. Card production and shipping

For producing and delivering ordered business cards, the necessary data may be shared with print, production, or shipping providers. This includes name, delivery address, order details, and the final card design.

This data is processed only as far as necessary for production, delivery, support, invoicing, and statutory retention.

7. Cookies, local storage, and optional insights

We use technically necessary cookies and comparable technologies so that login, security, language settings, and cookie choices work. Where access to device information is strictly necessary, it is used for the service requested by the user.

Optional analytics data is collected only after opt-in. On the public landing page, we record the landing-page view, visibility of the clearly fictional demo, and the request-CTA click at most once per 30-minute analytics session. We store the time, coarse page context, a source reduced to a small set of categories, and only an HMAC of the random session; the raw UTM value, raw IP address, user agent, referrer, account data, and contact data are not stored in the analytics record.

Consent can be changed at any time with future effect via the cookie settings or account settings.

8. Recipients and international transfers

Recipients of personal data may include hosting, database, payment, production, shipping, and technical service providers. Where required, these providers are engaged as processors or independent controllers.

For providers based outside the EU or EEA, we seek appropriate safeguards, such as adequacy decisions, standard contractual clauses, or comparable protection mechanisms.

9. Retention period

We store personal data only for as long as it is required for the purposes described above. Account, Hero Page, and card design data is generally stored until the account is deleted or changed by the user.

Contact and mockup requests are reviewed regularly and deleted no later than twelve months after the last substantive contact, unless an ongoing business relationship, consent, or legal obligation requires longer storage.

Optional raw funnel events are deleted no later than 90 days after collection. Order, payment, and invoice data may be stored longer due to commercial and tax retention obligations. Security and server logs are retained only for a limited period unless needed to investigate abuse or disruptions.

10. Rights of data subjects

Data subjects have the right, within the statutory requirements, to access, rectification, erasure, restriction of processing, data portability, and objection to certain processing.

Where processing is based on consent, consent can be withdrawn at any time with future effect. There is also a right to lodge a complaint with a data protection supervisory authority.

11. Security and changes

We use technical and organizational measures to protect data against loss, misuse, and unauthorized access. These include encrypted connections, access-restricted systems, and password hashing.

This privacy policy may be updated if features, service providers, or legal requirements change.