Legal
Privacy policy
Last updated: July 15, 2026
GG² Cards is committed to protecting your privacy. We collect only what we need to operate the service, we never sell your data, and we never use your card content to train AI models. Below is a plain-language explanation of our practices.
01Who we are
GG² Cards ("we", "us", "our") is a digital group greeting card platform operated in Canada. We are subject to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws. This policy explains what personal information we collect, how we use it, and your rights under Canadian law.
02Information we collect
When you create a card, we collect: your name or display name, your email address (required to deliver the card and receive management links), and the occasion and recipient details you provide. When contributors sign a card, we collect: their name, optional email address, and the message, photo, or GIF they add. For payment processing, we collect the minimum information required by Stripe (our payment processor) — we never receive or store raw credit card numbers. When you set a reminder, we collect your email address and the date and occasion type you specify — used only to send the reminder and a confirmation. We also collect standard usage data (IP address, browser type, pages visited) to operate and improve the service.
03How we use your information
We use your information to: deliver cards to recipients on the date and time you choose; send you management links so you can track signatures; process payments through Stripe; send reminder emails you have explicitly requested; respond to support requests; and improve the platform. We do not sell your data to third parties. We do not use your card content — messages, photos, or artwork — to train AI models. AI-generated card artwork is created using your text prompt through Ideogram's API; Ideogram's own privacy policy governs how they handle that data.
04Card content and retention
Card content (messages, signatures, photos, GIFs) is stored securely on Supabase infrastructure in Canada or the United States. Cards remain accessible to the recipient via their delivery link for 1 year after delivery. After that period, links expire and personal card content (messages, signatures, photos) is deleted by an automated daily process. Card content is never indexed publicly or shared outside the card's delivery link. Contributors who sign a card can request removal of their specific contribution at any time by contacting [email protected] with the card link.
05Cookies and tracking
We use only essential cookies to operate the service (session management, security, payment flow). For analytics we use a privacy-first, cookieless tool (Cloudflare Web Analytics) that measures aggregate traffic without storing any identifier on your device — so there is no tracking cookie and nothing to consent to. We do not use advertising cookies, cross-site trackers, or sell any data.
06Third-party services and data processors
We use the following third-party services to operate GG² Cards. Each is a data processor acting on our behalf under a data processing agreement: • Supabase (supabase.com) — database and file storage. Data may be stored in the US. • Stripe (stripe.com) — payment processing. Stripe is PCI-DSS certified. • Resend (resend.com) — transactional email delivery (card delivery, reminders, notifications). • Ideogram (ideogram.ai) — AI image generation. Your text prompt is sent to their API to generate card artwork. • Anthropic (anthropic.com) — AI text assistance for card message rewriting. Your message text is sent to their API. • GIPHY (giphy.com) — GIF search for contributors. GIF searches are sent to GIPHY's public API. • Cloudflare (cloudflare.com) — CDN, DDoS protection, and network security layer. Traffic passes through Cloudflare's network. • Self-hosted server infrastructure located in Canada — application and logs are hosted on our own hardware. We share only the minimum data necessary with each provider.
07International data transfers
GG² Cards is operated in Canada. Some of our third-party processors store or process data in the United States. Where data is transferred outside Canada, we ensure appropriate safeguards are in place in accordance with PIPEDA. By using our service, you consent to the transfer of your information to these processors in accordance with this policy.
08Your rights (PIPEDA)
Under Canadian privacy law, you have the right to: access the personal information we hold about you; request correction of inaccurate information; withdraw consent for certain uses of your data; and request deletion of your personal information. To exercise any of these rights, email [email protected]. We will acknowledge your request within 5 business days and respond fully within 30 days. If you are unsatisfied with our response, you may contact the Office of the Privacy Commissioner of Canada (priv.gc.ca).
09Privacy Officer (Quebec Law 25)
In accordance with Quebec's Act respecting the protection of personal information in the private sector (Law 25) and PIPEDA, our designated Privacy Officer can be reached at [email protected]. The Privacy Officer is responsible for handling access, correction, and deletion requests, privacy complaints, and questions about our retention practices (card content is retained for 1 year after delivery, then deleted automatically). You may also unsubscribe from all marketing emails at any time at gg2cards.com/unsubscribe.
10Children's privacy
GG² Cards is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us immediately and we will delete it promptly.
11Security
We use industry-standard security measures including TLS encryption in transit, encrypted storage at rest via Supabase, and access controls that limit who within our team can view card content. No system is 100% secure. If you believe there has been a security incident affecting your data, please contact [email protected] immediately.
12Changes to this policy
We may update this policy as the product evolves. We will notify registered users by email of material changes at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the service after that date constitutes acceptance of the updated policy.
Questions about your data?
Email us at [email protected] or visit our contact page. Privacy complaints may also be directed to the Office of the Privacy Commissioner of Canada.