Privacy
What we collect, who else sees it, and how long we keep it.
Last updated 3 October 2026
The short version
SnapACard turns a photo and a message into a real postcard and posts it. To do that we need your address and the address of the person you are sending to, and we hand both to the company that prints and mails the card.
That second part is the unusual bit, so it comes first: we hold the name and home address of people who have never used this site. If you are one of them, there is a section for you at the bottom.
What we collect from you
- Your email address, name and full postal address — the return address printed on the card.
- The photo you upload, and how you framed it.
- The message and any caption text you write.
- Payment identifiers from Stripe. Your card details never touch our servers — you type them into Stripe.
- A one-way hash of your IP address when you share a card or sign in, used only to stop abuse. We do not store the address itself.
- Your browser's user-agent string while you are signed in, so a session can be recognized.
We do not collect phone numbers anywhere, and Stripe is not configured to ask for one.
What we collect about the person you are sending to
Their name and full postal address, because that is what goes on the card. Their email address if you give us one, so they can be told a card is coming. Any greeting you write, and — if you write each person their own note — that note.
A message written to one named person and kept is a different thing from a shared one, so it is worth saying plainly: we keep it, and a person you wrote to can ask us what we hold about them and to delete it.
Your photo
The photo you upload is the only copy of it we hold. If you adjust it — brightness, contrast and the rest — those are five numbers stored alongside your card and applied in your own browser. They never produce a second photo and they are never sent anywhere.
What we do keep beside it is the finished card, front and back, as printed. Those images sit at web addresses that are public but unguessable: there is no listing and no way to find one from a name, but anyone given the link can open it.
If you have an account
An account is an email address you proved you can read. There is no password and no profile — we store the address, when it was created, and when it was last used. It exists so your past orders and saved cards can be found again.
A saved card holds everything a real order does, including every recipient's full address, for as long as you keep it. You can delete your account from your account page; see “How long we keep things” below.
Content screening — please read this one
Every photo and every message is sent to Google and analysed automatically, and every order is read by a person before it is printed. This is how we keep the press away from material we will not print. People do not expect it, so we are saying it here rather than burying it.
The writing helper
If you tap “Help with my message”, the text you have written — or the occasion and tone you picked — is sent to Anthropic to get a suggestion back. That only happens when you tap it.
No name, address, email or photo is ever sent, including the name of the person you are writing to, even though the app knows it. The reply is offered as a suggestion and never replaces your message without a tap, and we keep none of it.
Who else sees your information
- Stripe — payment. Receives your email and your card details directly. We deliberately send Stripe no names and no addresses.
- Lob — printing and mailing. Receives both addresses and the finished card. No email addresses.
- Resend — email, including sign-in links.
- Vercel — hosting, the database, and storage for photos and cards.
- Google Cloud — the content screening described above.
- Google Places — address autocomplete. What you type into an address box is sent to Google as you type it, before you submit anything.
- Anthropic — the writing helper, only when you tap it.
- Google Analytics — how people find this site and move around it. It sets cookies in your browser. It is not loaded at all on a page whose address contains a tracking link, a sign-in link or a card preview link, because those addresses are themselves the key to the page, and a key does not belong in somebody else's analytics.
We do not sell your information, and we do not share it for anyone else's advertising.
Each name above links to that company's own privacy policy.
How long we keep things
These are the rules the software actually applies today:
- Checkouts you did not finish — 7 days, then deleted. This includes the addresses you had typed in.
- Saved cards you have not sent — 60 days after you last edited one, then the card and its photo are deleted.
- Sign-in links — they stop working after 15 minutes, and the record is deleted a day later.
- Signed-in sessions — 60 days, refreshed while you keep using the site.
- Abuse-prevention hashes — 24 hours.
- A shared card page you never paid for — 7 days.
- A deleted account — you are signed out everywhere immediately, and the account and its saved cards are erased 7 days later.
A paid card's share page is kept indefinitely, on purpose. The QR code printed on the card opens it, and a card on someone's fridge should not stop working. That page shows the photo and the message, never any address. Ask us and we will take one down.
Order records, including the addresses we printed, are kept for 3 years after the order, then deleted. That takes the order with its recipients and their addresses, the delivery tracking, any replacement-card record, and the photo and printed card images in storage. Three years covers the tax year the order falls in and every chargeback window several times over. We do not keep them longer, because the people whose addresses those are mostly never used this site.
A paid card's share page outlives the order record behind it, on purpose and as described above: it holds the photo and the message and never an address, so the QR code on a fridge still works years later.
Our database keeps point-in-time backups, so a deleted row can survive in a backup for a while after it is gone from the live data.
Your rights
You can ask us what we hold about you, ask for it to be corrected, and ask for it to be deleted. If you have an account you can delete it yourself from your account page. Write to support@snapacard.com for anything else.
Depending on where you live — California, Florida and a growing list of other states — you may have a legal right to those things rather than just our word for it. We will not treat you differently for asking.
One limit, said plainly. If you ask us to delete an order we have already printed and accounted for, we delete what we can and keep the payment record until its 3 years are up — we are not allowed to lose a receipt. The photo, the message and the share page can go straight away, and we will tell you what we have kept and why.
If someone sent you a card
You did not agree to anything and you cannot sign in, so this is the part that matters: write to support@snapacard.com and we will tell you what we hold about you and delete it. Say roughly when the card arrived and what name it was addressed to — that is enough to find it.
Children
SnapACard is not for children under 13, and we do not knowingly collect anything from them.
Changes
If this page changes in a way that matters, we will change the date at the top. Carry on using the site and you are agreeing to the version that is up.
Contact
support@snapacard.com reaches a person.
By post: SnapACard, 7050 W Palmetto Park Rd, Suite 15-534, Boca Raton, FL 33433.