Privacy Policy
This policy explains how personal data is handled when you use PaymentCardDesign.com. The controller is Impera Manufacture GmbH, Albulastrasse 57, 8048 Zürich, Switzerland, which operates this website under the brand PaymentCardDesign.com. It applies under the Swiss Federal Act on Data Protection, and under the GDPR where you are in the European Economic Area.
Data we collect
- Design brief details you provide about your card project.
- Uploaded brand assets and reference materials.
- Contact and organisation details (name, email, company).
- Payment information, which is handled by Stripe. We do not store your card data on our systems.
- Consent-aware analytics data, collected only where you have agreed.
Who we share data with
We use a small number of service providers to run the service. Each processes personal data only on our instructions, under a data processing agreement.
| Provider | What for | Where | Transfer basis |
|---|---|---|---|
| Stripe | Payment processing and invoicing. | Ireland and the United States | EU Standard Contractual Clauses with the Swiss addendum |
| Resend | Order confirmations, project links and other transactional email. | Message processing and delivery in Ireland (EU). Resend is a company established in the United States. | EU Standard Contractual Clauses with the Swiss addendum, covering administrative and support access from the United States. The messages themselves are processed in the EEA. |
| Google Ireland Limited | Website analytics. Loaded only where you have accepted analytics cookies. | Ireland and the United States | EU Standard Contractual Clauses with the Swiss addendum |
| Vercel | Running the website and its application servers. | Application servers and request processing in Frankfurt, Germany (EU). Vercel Inc. is a company established in the United States. | EU Standard Contractual Clauses with the Swiss addendum, covering administrative and support access from the United States. The processing of your requests itself stays in the EEA. |
| Neon | Storing orders, briefs, portal accounts and the project activity log. | Germany (EU) | None required: the data stays in the EEA, which Switzerland recognises as offering adequate protection. |
| Cloudflare R2 | Private storage of uploaded brand assets and delivered artwork. | European Union | None required: the bucket is created under Cloudflare's EU jurisdiction, so the data stays in the EEA. |
Some of these providers process data outside Switzerland and the European Economic Area, including in the United States. Where the destination country is not recognised as offering adequate protection, the transfer is covered by the safeguard named above, and you can ask us for a copy of it.
File storage and access
Files you upload and designs we deliver are stored privately. Access is granted through short-lived signed links rather than public URLs.
No live card or cardholder data
You must not submit live card numbers, cardholder data or any other production payment credentials through our brief forms, uploads or messages. Our services are for design only.
Why we process it, and on what basis
- Delivering your project: brief, assets, correspondence and portal account. To perform our contract with you.
- Taking payment and invoicing: order and payment records. To perform our contract, and to meet our accounting and tax obligations.
- Keeping the record of approvals: who approved what, and when. Our legitimate interest in being able to show what was agreed and to defend a claim.
- Security and preventing abuse: sign-in attempts and rate limiting. Our legitimate interest in keeping accounts and artwork secure.
- Analytics: how the site is used. Your consent, which you can withdraw at any time without affecting anything done before you withdrew it.
We do not make decisions about you by automated means alone, and we do not profile you. We do not sell personal data, and we do not use it for advertising.
How long we keep it
- Orders, invoices and payment records: 10 years. Swiss accounting law requires business records to be kept for ten years (Art. 958f CO).
- Design briefs, uploaded assets and delivered artwork: 24 months after final delivery. So we can reissue files and answer questions about work we did for you.
- Client portal accounts: Until you ask us to close the account. The account is how you reach your projects.
- Project activity log: 10 years, alongside the order. It records who approved what and when, which is part of the order record.
- Analytics data: 14 months. The retention window configured in Google Analytics.
- Enquiries that never became an order: 12 months. Long enough to pick a conversation back up, no longer.
Where a longer statutory period applies, it takes precedence. Once a period ends we delete the data or anonymise it so it can no longer be linked to you.
Your rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal data, object to or restrict certain processing, withdraw consent, and request data portability. We answer within 30 days, and we do not charge for it.
Complaints
Please raise anything with us first, which is usually the quickest fix. You also have the right to complain to a supervisory authority:
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC) (www.edoeb.admin.ch)
- European Economic Area: Your local data protection authority (edpb.europa.eu/about-edpb/about-edpb/members_en)
Representative in the EU
We are established in Switzerland and have not appointed a representative in the European Union. If you are in the EEA, contact us directly at the address below and we will handle your request.
Contact
To exercise your rights or ask about this policy, contact hello@paymentcarddesign.com.