Privacy Policy

Last updated: [TO BE COMPLETED: effective date]

Who we are

BrandEra lets you design a bilingual business card without creating an account. This policy explains what we collect when you do, why, and what control you have over it.

The organisation responsible for your data is [TO BE COMPLETED: registered company name, legal form and registration number], at [TO BE COMPLETED: registered address and country].

What we collect

When you create a card we store the details you type into the form: your name, job title, company, phone number, email address and website. These are printed on the card and kept as a record of your enquiry. Your name, phone number and email address are required; the rest are optional.

We also store any logo you upload and the card design itself, so you can reopen and edit it later.

Separately, we record a one-way hash of your IP address and browser identity — never the address itself — to prevent abuse and enforce rate limits, along with the marketing source that brought you here and basic usage events that tell us which parts of the product work.

Why we are allowed to hold it

The card details, your uploaded logo and the design are held on the basis of your consent, given by the checkbox on the form. Nothing personal is stored before that consent is recorded.

The hashed IP and browser identity, the referral source and the usage events are held on the basis of our legitimate interest in keeping the service available and working — these are collected as you browse, before any form exists to ask you.

Consent

There are two separate checkboxes on the card form, and neither is ticked for you.

  • Required: “I agree to BrandEra storing my details to create and save my card.” Without this, nothing is stored and no card is created.
  • Optional: “Send me occasional emails about BrandEra.” This is never required in order to make a card, and never bundled with the checkbox above.

We record which version of this policy you agreed to and when, so it is always clear what you were shown.

If you did not tick the optional box, we will not send you marketing email. The email containing your finished card is not marketing and is sent regardless.

How long we keep it

  • Designs you never submitted a form for: 7 days.
  • Designs with a submission: 12 months from your last activity, then anonymised.
  • Your submitted details: 24 months, or until you ask us to delete them.
  • Exported files: 30 days. You can regenerate an export from the design at any time before it expires.
  • Uploaded logos: deleted together with the design they belong to.
  • Abuse and rate-limit records: 90 days.
  • Our internal audit logs: 24 months.

Deletion is automatic and removes the stored files as well as the database records.

Your rights

You can ask us to:

  • tell you what we hold about you;
  • correct it;
  • delete it, including your designs and exported files;
  • stop sending you marketing email — every email also has a one-click unsubscribe link.

Contact us at [TO BE COMPLETED: privacy contact email address]. We respond within [TO BE COMPLETED: response deadline, e.g. 30 days].

A deletion request made by email has to be confirmed from that address before we act on it. This protects you: without it, anyone could delete someone else’s card by guessing their email.

You can also edit any detail on your card directly in the editor at any time, which updates what we hold.

[TO BE COMPLETED: rights not currently offered — objection, restriction and portability — confirm with counsel which are required in each market]

Cookies

We set one cookie that matters to you: cm_design, which remembers the card you are working on so a refresh does not lose it. It cannot be read by scripts and is not used for advertising.

[TO BE COMPLETED: full cookie table — name, purpose, duration and provider for every cookie including analytics]

Who else sees your data

We use Cloudflare Turnstile to tell people from bots when you submit the form.

[TO BE COMPLETED: complete sub-processor list — hosting, database, object storage, CDN, email delivery, analytics and error tracking, each with its purpose, location and data-processing agreement]

We do not sell your data.

How we protect it

Uploaded images are limited to PNG and JPG, checked by their actual content rather than their filename, and re-encoded on our side — which strips the location data that photographs routinely carry. Files are stored privately and served through short-lived signed links.

The link to your card is a long random token and is the only credential that opens it. It is never listed in a sitemap, a log, or an analytics event, and the pages are marked so search engines do not index them.

Anyone holding that link can open and edit your card. Treat it like a password, and do not share it with anyone you would not want editing the card.

Where your data is held

[TO BE COMPLETED: hosting region and country, whether any data leaves it, and the safeguard relied on for transfers]

Children

[TO BE COMPLETED: minimum age to use the service and what happens if a child’s data is discovered]

Which law applies

We handle personal data in line with Egypt’s Personal Data Protection Law (Law 151/2018).

[TO BE COMPLETED: the other laws that apply in each market served, the governing law and jurisdiction, and the authority a complaint can be made to]

Changes to this policy

When this policy changes, its version changes with it, and we keep a record of which version you agreed to.

[TO BE COMPLETED: how people are told about changes, and whether consent is asked for again]