Privacy Policy

As of June 2024

Introduction

Your privacy is extremely important to us and we are committed to fair practices that protect your information. This Privacy Policy explains our data practices and tells you about your privacy rights and how the law protects you.

This Policy applies to everyone whose personal data we handle — whether you visit our site, sign up on your own, or use CardBoard as part of an organization. By accessing or using CardBoard’s Site and Service, you acknowledge the practices described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our Site or Service.

Who we are

CardBoard is provided by CARDBOARDit, Inc. (“CardBoard”, “we”, “us”, or “our”), located at 16080 Westfield Blvd., Carmel, IN 46033, USA. For most personal data we process about our account holders and site visitors, CardBoard is the data controller. Where we process personal data on behalf of an organization that uses CardBoard (for example, content and end-user data inside that organization’s boards), we act as a processor on that organization’s behalf, and that organization is the controller — see our Terms of Service and any data processing addendum with that organization.

How to reach us about privacy: email [email protected] or write to the address above. For security matters or to report a vulnerability, email [email protected]. We have not appointed a separate Data Protection Officer; please direct privacy questions to [email protected].

Sources of personal data

CardBoard obtains information about individuals in these main ways:

  • Account Information: When you register for an account, we collect your name, email, and other information you provide to create and manage your account.
  • User Content: We collect the content, materials, and information you provide when you use CardBoard, including comments, feedback, and any other data you submit.
  • Log Data: When you visit CardBoard’s site, our servers automatically record information, including your IP address, browser type, referring URLs, and other data.
  • Cookies and Similar Technologies: We use cookies and similar technologies to operate the Service and understand how it is used. See “Cookies and tracking technologies” below.
  • Third-Party Integration: If you choose to connect your account with third-party services or platforms — such as an issue tracker (e.g., Jira, Azure DevOps), a single sign-on provider, or your own AI assistant — we may collect or exchange information with those services as authorized by you. See “AI features and your data” below.

Children’s and teens’ privacy

The CardBoard Service is not intended for children under the age of 13, and we do not knowingly collect personal information from any person we actually know is under 13. We also do not knowingly sell or share the personal information of anyone under the age of 16, and we do not sell or share personal information for advertising at all (see “Cookies and tracking technologies”). If you believe a child under 13 has provided us personal information, please contact us so we can delete it.

How your data is used

In general, we use the information collected to provide you with a great overall experience interacting with us and when using the CardBoard website.

Providing, maintaining, and improving the Service

We use the information collected to help us understand who uses our offerings, for internal operations such as operating and improving the CardBoard website and our services, and to contact you for customer service and billing purposes.

Communicating with you

We use your information to send you a welcome e-mail after you create an account, when you are invited to CardBoard, or when you sign up for a demo, webinar or to receive our newsletter. We also use your information to send other e-mail communication related to the CardBoard website. We always give you the option to unsubscribe from marketing email; service and account notices (such as changes to these terms or billing) are not optional, as they contain information essential to your use of the Service.

Responding to your inquiries and providing customer support

If you identify yourself to us by sending us an e-mail with questions or comments, we may use your information (including personal information) to respond to your questions or comments, and we may retain your questions or comments (with your information) for future reference.

We may also use the information gathered to perform statistical analysis of user behavior or to evaluate and improve the CardBoard services. We may link some of this information to personal information for internal purposes or to improve your experience with the CardBoard website and our services.

If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data on these legal bases: performance of a contract (to provide the Service you or your organization have signed up for); legitimate interests (to secure, operate, and improve the Service, and to communicate with you, balanced against your rights); consent (for example, optional marketing or non-essential cookies, which you can withdraw at any time); and compliance with a legal obligation. Where we rely on consent, you may withdraw it at any time without affecting prior processing.

Data sharing and disclosure

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We may share your information in the following ways:

Service Providers and sub-processors

We use service providers (“sub-processors”) to run the Service. They may access personal data only to perform services for us, under contractual confidentiality and data-protection obligations, and not for their own purposes. Current categories include:

  • Cloud hosting and storage: Heroku (application hosting) and Amazon Web Services / S3 (file storage), with data hosted in the United States.
  • Authentication: Google and Microsoft (for social and enterprise sign-in you choose to use).
  • Payment processing: Stripe (we do not store full payment card numbers; card data is handled by Stripe).
  • Email and communications: Loops (transactional and product/marketing email).
  • Analytics: PostHog (first-party product analytics to understand and improve usage).
  • Customer support: Help Scout (to manage and respond to your support conversations).

A current list of sub-processors is available on request at [email protected].

Outside Contractors and Third-Party Processors

We may employ independent contractors, vendors and suppliers to provide specific services and products related to the CardBoard website and our services. We require that these Outside Contractors agree to (1) protect the privacy of your personal information consistent with this Privacy Policy, and (2) not use or disclose your personal information for any purpose other than providing us with the products or services for which we contracted or as required by law.

We may disclose your information (including personal information) if we believe in good faith that we are required to do so in order to comply with an applicable statute, regulation, rule or law, a subpoena, a search warrant, a court or regulatory order, or other valid legal process. We may disclose personal information in special circumstances when we have reason to believe that disclosing this information is necessary to identify, contact or bring legal action against someone who may be violating the CardBoard Terms of Service, to detect fraud, or to protect the safety and/or security of our users, the CardBoard website, or the general public. We also may be required to disclose an individual’s personal information in response to a lawful request by public authorities, including to meet national security or law enforcement requirements.

Affiliates and business transfers

We may disclose information about you to our Corporate Affiliates, who will treat it in accordance with this Privacy Policy. If CardBoard is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction; we will notify you of any such change in ownership or control of your personal information.

AI features and your data

CardBoard is built to work with AI assistants. Today, CardBoard operates on a bring-your-own-LLM model: when you connect your own AI assistant (for example, over our MCP endpoint or API), that assistant can read and propose changes to the boards you authorize, and the board content involved is sent to and processed by that third-party AI service under your direction and that provider’s own terms and privacy policy. We encourage you to review the terms and privacy practices of any AI service you connect.

  • We do not send your board content to large language model providers on our own initiative, and we do not use your content to train AI/ML models.
  • Access by an AI assistant is authorized through your account credentials and scoped permissions, and every change an assistant proposes is attributed to the member who authorized it.
  • If we introduce first-party AI features that process your content with an LLM provider on our behalf, we will update this Policy, add that provider to our sub-processor list, and notify you as required by law.

International data transfers

CardBoard is operated from the United States, and personal data we process is stored and processed in the United States. If you are located in the EEA, the UK, or Switzerland, transferring your data to the U.S. means it is processed outside your home country. Where required, we rely on appropriate safeguards for these transfers, including the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum). You may request a copy of the safeguards we use by contacting [email protected].

Cookies and tracking technologies

We use strictly necessary cookies to operate the Service (for example, to keep you signed in) and limited first-party analytics (via PostHog) to understand and improve usage. We do not use advertising or cross-site tracking cookies, and we do not sell or share personal information for advertising. Where required by law (for example, in the EU/UK), we ask for your consent before setting non-essential cookies. We honor recognized opt-out preference signals, including Global Privacy Control (GPC), where applicable.

Data retention

We keep personal data only as long as necessary for the purposes described in this Policy, to provide the Service, and to comply with our legal obligations, resolve disputes, and enforce our agreements. In general, account data is retained for the life of the account and deleted within 30 days of account closure; backups are purged within 90 days; and server logs are retained for about 12 months. When data is no longer needed, we delete or de-identify it; note that residual copies may persist in backups for a limited period (see “User rights”).

Data security

We take precautions to protect the security of your information, including TLS encryption in transit, encryption of stored files, server-side access controls on a least-privilege model, and audit logging of changes. However, neither people nor security systems are foolproof, including encryption systems, and we cannot guarantee absolute security. If applicable law imposes any non-disclaimable duty to protect your personal information, you agree that intentional misconduct will be the standard used to measure our compliance with that duty.

Breach notification

If we become aware of a breach of security leading to the unlawful destruction, loss, alteration, or unauthorized disclosure of your personal data, we will notify you and the relevant authorities without undue delay where required by applicable law, and will provide information about the incident and the steps we are taking in response.

Your privacy rights

Depending on where you live, you may have some or all of the following rights regarding your personal data: to access it; to correct inaccuracies; to delete it; to obtain a portable copy; to restrict or object to certain processing; to withdraw consent; and to opt out of the sale or sharing of personal information or of profiling that produces legal or similarly significant effects. We do not sell or share personal information for advertising, and we do not discriminate against anyone for exercising these rights.

How to exercise your rights. Email [email protected] or use the controls in your account. To protect your privacy, we will take reasonable steps to verify your identity before acting on a request, and we may decline requests permitted to be denied by law. You may use an authorized agent to submit a request on your behalf, subject to verification. If you are an end user of an organization’s CardBoard workspace, you may also exercise rights by contacting that organization, and we will assist them as their processor.

Appeals. If we decline your request, you may appeal by replying to our decision or emailing [email protected] with “Appeal” in the subject line. We will respond within the time required by applicable law; in some states you may also contact your state Attorney General.

EEA / UK / Swiss residents

In addition to the rights above, you have the right to lodge a complaint with your local data protection authority (in the UK, the Information Commissioner’s Office). We respond to verified requests within the timeframes set by the GDPR/UK GDPR.

California residents

The California Consumer Privacy Act, as amended by the CPRA, provides California consumers with rights to know/access, correct, delete, and opt out of the sale or sharing of their personal information, and to limit the use of sensitive personal information. CardBoard does not sell or share personal information and does not use sensitive personal information for purposes that require a “limit” option. You will not be discriminated against for exercising any CCPA/CPRA right, and you may submit requests as described under “How to exercise your rights.”

Note on deletion

It is not technologically possible to remove every record of information you have provided from our systems immediately, because we back up our systems to protect against inadvertent loss. Promptly after a verified request, we will update, correct, change, or delete personal information in the databases we actively use and other readily searchable media as soon as, and to the extent, reasonably and technically practicable, and residual backup copies will be purged on our standard backup cycle.

Updates to this Privacy Policy

We may revise this Privacy Policy from time to time. If we make material changes, we will provide notice as required by law — for example, by posting a prominent notice on our website or emailing you — before the changes take effect. We encourage you to review this page periodically. Your continued use of the Service after an update takes effect constitutes your acceptance of the updated Policy to the extent permitted by law.

Contact information

If you have any questions, comments, or concerns about this Privacy Policy or our data practices, please contact us at [email protected] or 16080 Westfield Blvd., Carmel, IN 46033, USA.