Privacy policy
Last updated:
This policy describes how we handle personal data when you use Gruppkort at www.gruppkort.se – whether you create a card, write a greeting in someone else's card or receive one.
We only collect what the service needs to work, and we never sell personal data.
Data controller
Laguna Creations AB (reg. no. 559443-2667), Storgatan 32, 931 31 Skellefteå, Sweden, is the controller for the processing described here.
Send questions about personal data to support@gruppkort.se.
What data we process
What we hold depends on how you use the service:
- If you create a card: your name and email address. We create an account for you with those details and a password, which is only stored in hashed form. We also store the card's title, the sender name (for example "Your colleagues in finance"), the chosen theme and any scheduled delivery time.
- If the card has a recipient: the recipient's name and email address, as you enter them, and whether the recipient has opened the card.
- If you write a greeting: your name as a signature, your text, the chosen font and any images, GIFs or videos you add. You don't need an account to write. If you are signed in, or choose to give an email address, it is stored with the greeting.
- If you pay for a card: we store a reference to the payment. Card details are handled only by Stripe and never reach us.
- Technical data: your IP address when you sign in or reset your password, to protect against break-in attempts, and records of the emails we send and whether they were delivered.
- Usage statistics, if you have allowed them: which pages and buttons are used, for example when a card is created or opened. See the section on cookies.
Why we process the data and on what legal basis
- To provide the service – creating and showing cards, collecting greetings, delivering the card to its recipient and managing your account and payments. Legal basis: contract (Article 6(1)(b) GDPR).
- To show greetings and recipient details that someone else has added to a card. Legal basis: legitimate interest (Article 6(1)(f)) – that the person who creates a card can collect greetings and send it.
- To protect the service against abuse, for example by limiting repeated sign-in attempts. Legal basis: legitimate interest.
- To understand how the service is used and improve it, using usage statistics. Legal basis: consent (Article 6(1)(a)), which you give or refuse in our cookie notice and can withdraw at any time. See the section on cookies.
- To meet legal requirements, such as bookkeeping rules for payments. Legal basis: legal obligation (Article 6(1)(c)).
Who can see the data
A card and its greetings can be seen by anyone who has the card's link – the person who created it, the people invited to write and the recipient. Only share the link with people who should contribute.
We use the following providers, which process data on our behalf or deliver content directly to your browser:
- Vercel – hosts the website.
- Supabase – hosts our database.
- Amazon Web Services (S3) – stores uploaded images.
- Mux – stores and plays videos and measures playback quality, for example whether a video loads slowly. Mux only stores a cookie in your browser if you have allowed statistics.
- Mailgun – sends email, such as sign-in details, password resets and the card itself to its recipient. We use Mailgun's EU region.
- Stripe – handles payments. Stripe receives the card's sender name and the recipient's name and email address with the payment.
- Google (Firebase Analytics) – usage statistics, only if you have allowed them.
- Google Fonts – serves the fonts you can choose for a greeting. When such a font is shown, your browser fetches it from Google, which then sees your IP address.
- Giphy and Unsplash – GIFs and images you choose are shown directly from their servers, which then see your IP address.
Transfers outside the EU/EEA
Several of the providers above are based in the United States. Where personal data is transferred outside the EU/EEA, this relies on the EU–US Data Privacy Framework or the European Commission's standard contractual clauses.
How long we keep the data
A card and its greetings are kept until the person who created it deletes it, so that the recipient can keep opening it. Your account is kept until you ask us to delete it.
If you delete a greeting or a whole card, its images and videos are also removed from our storage providers within about an hour. If you want your whole account deleted, with all your cards – contact us and we will do it.
Payment references are kept for as long as Swedish bookkeeping law requires, currently seven years.
Your rights
You have the right to know what data we hold about you and get a copy of it, to have inaccurate data corrected, to have data deleted, to restrict processing, to object to processing based on legitimate interest, and to receive data you provided in a machine-readable format.
Contact support@gruppkort.se to exercise your rights. We reply within one month.
If you are unhappy with how we handle your data, you can complain to the Swedish Authority for Privacy Protection (IMY), https://www.imy.se.
Changes
We update this policy when the service or the law changes. The date at the top shows when it last changed.
Contact
Laguna Creations AB, Storgatan 32, 931 31 Skellefteå, Sweden. Email: support@gruppkort.se.