Carded ("Carded," "we," "us") builds a browser-based tool that helps retailers verify a customer's age from the barcode on a government-issued ID. This policy explains what happens to data when you use Carded. In plain terms: the actual ID scanning happens on your own device, and we do not collect, upload, or sell the personal information on your customers' IDs.
1. Information processed on your device
When you scan an ID, Carded reads the data encoded in the barcode (such as name, date of birth, address, ID number, and expiration date) to calculate age and check the expiration date. This processing happens entirely within your browser. This information is displayed to you and, if you choose, added to a local scan log.
The scan log, the unique device identifier, and any device name you set are stored only in your browser's local storage on that device. They remain there until you clear them, clear your browser data, or export them. We cannot see this information.
Carded also keeps two optional records on the device to power its watchlist and compliance features. The watchlist (IDs you mark as "86'd" or VIP) and the re-scan check do not store the raw ID number: each ID is saved as a one-way cryptographic hash (a fingerprint that cannot be turned back into the original number), alongside any note, name label, and timestamp you add. The compliance report stores only the outcome of each scan, pass, decline, expired, the device and staff name, and that same hashed fingerprint, with no customer names, dates of birth, or ID numbers. Both live only on the device, are never uploaded to us, and can be exported or cleared by you at any time.
If you use the optional DeliveryPro add-on, Carded also creates a delivery record when you complete a delivery. Because a delivery is a documented hand-off, this record can include more than a normal scan: the recipient's name (pre-filled from the scanned ID, which you can edit), their on-screen signature as an acknowledgment of receipt, a not-visibly-intoxicated confirmation, an optional photo you choose to take at the hand-off, the delivery address (from your device's location, which you can edit or enter by hand), an order number you enter, the time, and the same outcome and hashed fingerprint described above. It does not store the recipient's date of birth or ID number. These delivery records, including the name, signature, and any photo, are stored only on your device. They are never uploaded to us, and you can export them (for your own compliance records) or clear them at any time. You are responsible for handling any records you export in line with the laws that apply to your business.
Carded also runs integrity checks to help your staff spot fake or altered IDs. Carded IntegrityEngine analyzes the barcode's structure and internal consistency entirely on your device. With IntegrityEngine 360, if your staff choose to scan the front of the ID, Carded captures an image of the front and reads its printed text on the device to compare it against the barcode. This capture and comparison happen entirely within your browser. The front image is used only for that on-device comparison; it is not uploaded to us and is not saved to your scan log.
If you use the optional Festival Mode (currently in beta), Carded stores event information on the device: the event name and gate you set, an on-device tally of scans by gate and staff, and any ejection or "cut-off" you record (saved with the hashed ID fingerprint, a reason, and an optional note). If you also turn on Wristband mode, Carded stores a link on the device between the wristband number your staff scan, photograph, or enter and limited details from the scanned ID (the person's name, date of birth or age, expiration date, and the hashed fingerprint), so staff can look that band up during the event. All of this is stored only on the device, is scoped to the event, is never uploaded to us, and can be cleared by you at any time.
To power your account dashboard and to keep your plan's device count accurate, each authorized device sends de-identified scan outcomes to us when it is online. For each scan this is limited to the result (pass, decline, or unclear), the age as a plain number, the issuing state, the reason a scan did not pass, the ID type, the age threshold that was checked, the device name you set, and the optional location label you set for that device (a station name or address you type in Settings, never read from GPS). It never includes any customer's name, date of birth, ID number, address, photo, GPS coordinates, or the raw barcode, and it is not the on-device scan log itself. The device name and location label are free-text fields you control, so you should not enter customer information in them. This data lets you, the account owner, see your scanning activity and compliance trends across all of your devices in one place, from the dashboard on our website. We call it de-identified rather than anonymous because it is linked to a device and your business, though not to any customer. It exists so you can manage your account and understand your own usage, not to profile anyone, and we do not sell it.
2. Information we do not collect
- We do not upload, transmit, or store your customers' ID data on our servers.
- We do not sell or share customer data with advertisers or data brokers.
- We do not build profiles of the people whose IDs you scan.
3. Location data
Ordinary counter scans do not use your device's GPS. No GPS coordinates are read, stored, or transmitted when you scan an ID at the counter. A counter scan is tagged only with the device name and the optional location label you type in Settings (both are your own words, never read from GPS); that label is included in the de-identified outcomes described in section 1 and shown on your dashboard. Actual device GPS is used only in the optional DeliveryPro add-on, to record the delivery address as part of the delivery hand-off record. In that case Carded reads your device's approximate GPS coordinates and, to convert them into a readable address, sends the coordinates (and only the coordinates, never any ID data) to the OpenStreetMap Nominatim service; you can also edit the address or enter it by hand. That delivery record, including the address, is stored only on your device and is never uploaded to us. You can decline or revoke location permission at any time in your browser or device settings.
4. Information you provide to us
If you submit your email address through a form on our website (for example, to receive product updates or contact us), we collect that email address so we can respond or send you the updates you requested. We use it only for that purpose and you can ask us to remove it at any time.
When you start a subscription or free trial, our payment processor Stripe collects the information needed to set up billing. This may include your name, your venue or business name, your billing address and (optionally) your venue's street address, a phone number, and your payment-card details. Your full card details are handled directly by Stripe and are never seen or stored by us. We receive and retain limited account information, such as your email, venue name, address, plan, and subscription status, so we can provide the Service, manage your plan and the devices on it, and support you.
To use your online account dashboard on our website, you create a login with your email address. You can sign in with a password you set or by requesting a one-time sign-in link sent to your email. Our authentication and database provider, Supabase, securely stores your email, your encrypted password if you set one, and the de-identified scan outcomes described in section 1 so we can display them back to you. Your dashboard is matched to your subscription by the email address on file, so please use the same email you used to subscribe. We use your email to operate your account, send you sign-in links and important service notices, and, only if you have opted in, occasional product updates you can unsubscribe from at any time.
5. Automatically collected technical data
Our website is hosted on Netlify. Like most websites, our host may automatically log standard technical information such as IP address, browser type, and pages requested for security and to keep the service running. We use privacy-respecting hosting and do not use this data to identify individual visitors.
6. Cookies and local storage
Carded does not use advertising, analytics, or cross-site tracking cookies. It uses a small number of strictly necessary cookies, together with your browser's local storage, only to make the app work:
- A secure, signed sign-in cookie that keeps your device authorized on your subscription, so you don't have to re-verify every time you open the app.
- Cookies and local storage that remember your device's ID, the device name you set, and the staff member currently signed in, so a phone you add to your home screen keeps its settings.
- A login session token, stored in your browser's local storage by our authentication provider (Supabase), that keeps you signed in to your online account dashboard if you use it. The dashboard also loads that provider's software library from a public code CDN (jsDelivr). Clearing your browser storage signs you out.
- Local storage that holds your scan log, your watchlist, and your compliance record on the device, as described in section 1.
- Local storage that holds any Festival Mode event data, wristband links, and ejection records you create, on the device only, as described in section 1.
- An on-device text engine (Tesseract.js), used by IntegrityEngine 360 and Wristband mode to read printed text from the front of an ID or a wristband. The engine's software is downloaded from a public code CDN (cdnjs) the first time it is used; the ID image and the text read from it are processed entirely on your device and are never sent to the CDN or to us.
These are all functional and necessary for the Service; we do not use them to track you across other websites. Clearing your browser's cookies or storage removes them and will sign the device out.
7. Third-party services
We rely on a small number of trusted service providers to run Carded. Our current providers, each processing only the limited data described and under its own privacy terms, are:
- Stripe, payment processing and subscription billing. Stripe collects and processes your billing details and card information under its own privacy terms; we never receive your full card number.
- Supabase, provides our database, account sign-in and authentication, and the secure storage of your account information and the de-identified scan outcomes shown in your dashboard. No customer ID data is stored there.
- Resend, sends account and product emails on our behalf, such as sign-in links, email confirmations, and any updates you subscribe to.
- Netlify, website and app hosting.
- OpenStreetMap (Nominatim), converts GPS coordinates to an address, only when you use DeliveryPro with location enabled.
- Google Fonts, web fonts used on our marketing pages.
We keep this list current; if our providers change, we will update this page and the date above.
8. Your responsibilities as a retailer
You control any records you choose to export from Carded (such as a CSV of your scan log). Once exported, that file is yours and its handling is your responsibility. Some jurisdictions place limits on scanning, recording, or retaining information from customers' IDs. You are responsible for complying with the laws that apply to your business and location.
9. Data retention
Because scan data lives on your device, its retention is controlled by you. Emails you submit to us are kept only as long as needed to provide updates or support, or until you ask us to delete them.
10. Children's privacy
Carded is a tool for businesses and is not directed to children. We do not knowingly collect personal information from children through our website.
11. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
12. Contact us
Questions about privacy? Email support@trycarded.app.