Privacy Policy
Last updated: August 3, 2026
This Privacy Policy explains how Connex ("Connex," "we," "us," or "our") collects, uses, discloses, and protects your personal information when you visit connex.cards (the "Site"), purchase a Connex card, or otherwise interact with us. By using the Site or purchasing from us, you agree to the practices described here. If you do not agree, please do not use the Site.
This policy is written to align with the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), Canada's PIPEDA, and other applicable data-protection laws. Your rights depend on where you live, and the sections below explain them.
1. Who We Are
Connex sells a physical smart card that, when tapped to a phone, opens a web address ("destination link") that you provide to us at the time of purchase. We are the data controller for the personal information described in this policy.
For any privacy question or to exercise your rights, contact us at admin@connex.cards. We aim to respond to all privacy requests within the timeframes required by law (generally 30 days under GDPR and 45 days under CCPA/CPRA, each extendable where permitted).
2. Information We Collect
We collect the following categories of personal information:
Information you give us directly:
- Order and contact details: your name, email address, shipping address, billing address, and phone number (if provided).
- Card personalization data: the name or text you ask us to print on each card and the destination link (URL) you ask us to program onto each card. Because you may order multiple cards, we collect a separate name and link for each card in your order.
- Communications: information you provide when you email us or contact support, including the contents of your messages.
Information collected automatically:
- Device and usage data: IP address, browser type, device information, pages viewed, session activity, and referring URLs, collected through cookies and similar technologies.
- Transaction metadata: order numbers, purchase history, and approximate location derived from your IP or shipping address.
Information from third parties: our payment processors and platform provider (see Section 5) provide us with transaction confirmations, fulfillment status, and fraud-prevention signals.
Payment information: when you pay, your card details are collected and processed directly by our payment processor. We do not receive or store your full payment card number.
We do not knowingly collect special categories of sensitive data (such as health, biometric, precise geolocation, or government-ID data), and we ask that you not include such information in the name or link fields you submit. Any sensitive information you choose to submit in those fields is provided at your own risk.
3. How We Use Your Information and Our Legal Bases
We use your personal information for the following purposes. Where GDPR applies, the applicable legal basis is noted in brackets.
- To manufacture, personalize, and program your cards with the name and destination link you provide, and to fulfill and ship your order [performance of a contract].
- To process payments, verify orders, and prevent fraud and abuse [performance of a contract; legitimate interests; legal obligation].
- To provide customer support and respond to your inquiries [performance of a contract; legitimate interests].
- To send you transactional messages such as order confirmations and shipping updates [performance of a contract].
- To send marketing communications, where you have opted in or where permitted by law [consent; legitimate interests]. You can opt out at any time.
- To operate, secure, monitor, and improve the Site and analyze usage [legitimate interests; consent for non-essential cookies].
- To maintain business, accounting, and production records [legal obligation; legitimate interests].
- To comply with legal obligations, enforce our Terms of Service, and establish, exercise, or defend legal claims [legal obligation; legitimate interests].
4. A Note About Your Destination Link
The destination link you provide is programmed onto your card and becomes accessible to anyone who taps that card. Do not use a destination link that exposes information you consider private or sensitive. You are solely responsible for the content located at your destination link and for ensuring you have the right to share it. We are not responsible for the privacy practices, security, availability, or content of any third-party site your link points to (for example, a link-in-bio service, social profile, or payment page).
Because your card is permanently programmed at production, we cannot change, disable, or revoke a destination link after your card is made. If you no longer wish your card to direct people to a given destination, you should change or remove the content at that destination through the third-party service that hosts it.
5. How We Share Your Information
We do not sell your personal information for money. We share personal information only with the following categories of recipients, and only as needed:
- Platform provider: Shopify Inc., which hosts our Site and processes orders.
- Payment processors: such as Shopify Payments, Stripe, and/or PayPal, which process your payment.
- Shipping and fulfillment partners: carriers and print/fulfillment vendors who manufacture, personalize, and deliver your cards using your name, link, and shipping address.
- Analytics and infrastructure providers: who help us operate, host, and secure the Site.
- Professional advisors: accountants, auditors, insurers, and legal counsel, bound by confidentiality obligations.
- Legal and safety recipients: law enforcement, regulators, courts, or others where required by law, in response to lawful process, or where necessary to protect rights, safety, and property.
- Business transfers: a successor entity in the event of a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets.
Regarding "sharing" for targeted advertising: if we use advertising or analytics cookies (for example, from advertising platforms), this may be considered "sharing" or a "sale" of personal information under certain U.S. state laws, even though no money changes hands. You can opt out as described in Section 8.
We require service providers to process personal information only on our instructions and to protect it appropriately.
6. International Data Transfers
We are based in the United States, and your information may be processed in the United States and other countries whose data-protection laws may differ from yours. Where we transfer personal data out of the EU/EEA or the UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum. You may request a copy of the safeguards we use by contacting us.
7. Data Retention
We keep personal information only as long as necessary for the purposes described in this policy:
- Order, personalization, and transaction records: retained for the duration of our relationship and for up to seven (7) years afterward to meet tax, accounting, warranty, and legal obligations, and to establish or defend legal claims.
- Card name and destination link: retained as long as needed to fulfill and support your order, to maintain production records, and to handle warranty or replacement requests, then deleted or anonymized in accordance with the retention period above.
- Marketing data: retained until you unsubscribe or object, then suppressed as needed to honor your choice.
- Website analytics data: retained for up to 26 months.
- Support communications: retained for up to three (3) years after resolution.
When retention periods expire, we delete or irreversibly anonymize the data.
8. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights:
For EU/EEA and UK residents (GDPR): the right to access, rectify, erase, restrict, or object to processing; the right to data portability; the right to withdraw consent at any time; and the right to lodge a complaint with your local data-protection authority.
For California residents (CCPA/CPRA): the right to know what personal information we collect and how we use and disclose it; the right to access and delete your personal information; the right to correct inaccurate information; the right to opt out of the "sale" or "sharing" of personal information for targeted advertising; the right to limit use of sensitive personal information; and the right not to receive discriminatory treatment for exercising your rights.
For residents of other U.S. states and jurisdictions with comparable laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and Arkansas, and Canada under PIPEDA), you may have similar rights to access, correct, delete, and opt out, and where applicable to appeal a denied request.
To exercise any right, email admin@connex.cards with your request. We will verify your identity before acting and will not discriminate against you for exercising your rights. You may use an authorized agent where the law permits. We honor recognized opt-out preference signals, including Global Privacy Control (GPC), where required.
Do Not Sell or Share My Personal Information: to opt out of any "sale" or "sharing" of your personal information for targeted advertising, email admin@connex.cards or use the opt-out link provided in our Site footer where available.
9. Data Deletion
You may request that we delete the personal information we hold about you at any time. To make a request, email admin@connex.cards with the subject line "Data Deletion Request."
Upon verifying your identity, we will delete your personal information from our active records within the timeframes required by law, except where we are required or permitted to retain it — for example, to complete a transaction you requested, comply with a legal, tax, or accounting obligation, resolve disputes, detect or prevent fraud, honor a warranty claim, or establish, exercise, or defend legal claims.
Please note: because each Connex card is made to order and permanently printed and programmed with the name and destination link you provide, information associated with completed orders — including the personalization details printed and encoded on your card — may be retained for production, accounting, tax, warranty, and legal-compliance purposes even after a deletion request, for the retention periods described in Section 7. Deleting your information from our records does not alter, disable, or erase a card that has already been manufactured.
We will confirm completion of your request by email. Where we deny a request in whole or in part, we will explain why, and where the law provides an appeal process, we will tell you how to appeal.
10. Cookies and Tracking Technologies
We use cookies and similar technologies to operate the Site, remember your preferences, analyze traffic, and, where applicable, support advertising. Strictly necessary cookies are required for the Site to function. Non-essential cookies (analytics and advertising) are used only with your consent where the law requires it, and you can accept or decline them through our cookie banner or your browser settings. Withdrawing consent will not affect the lawfulness of processing carried out before withdrawal.
11. How We Protect Your Information
We use administrative, technical, and organizational safeguards designed to protect personal information, including encryption of data in transit (HTTPS/TLS), access controls, and reliance on vetted providers such as Shopify for secure checkout and payment handling.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping any account credentials confidential. We will notify you and the relevant regulators of a data breach where and as the law requires.
12. Children's Privacy
The Site and our products are not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact us at admin@connex.cards and we will delete it promptly.
13. Third-Party Links
The Site and the cards may link to third-party websites and services that we do not control. This policy does not apply to those third parties, and we encourage you to review their privacy policies before providing them with information.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, where required, provide additional notice. Your continued use of the Site after changes take effect constitutes acceptance of the updated policy.
15. Contact Us
If you have questions, requests, or complaints about this Privacy Policy or our data practices, contact us at:
Connex Email: admin@connex.cards