cardperGet the app

Privacy Policy

Effective date: 20 July 2026Last updated: 20 July 2026

Cardper ("the App") is operated by WEBYAP YAZILIM LİMİTED ŞİRKETİ ("we", "us"), a company registered in İzmir, Republic of Türkiye. This policy explains what the App collects, why, and what control you have. Cardper is a local first application: by default, the card information you enter stays on your device.

1. Information We Collect

Information you enter

You may add card nicknames, issuing bank names, the last four digits of a card, statement dates, due dates, limits, balances, payments and notes. This information is stored locally on your device. We do not ask for full card numbers, CVV codes, PINs or online banking credentials, and the App never connects to your bank.

Optional account for Cloud Sync

If you choose to enable Cloud Sync, you sign in with Apple or Google. We receive a user identifier and, depending on your choice, an email address. Sign in is optional and the App is fully usable without it.

Anonymized analytics and diagnostics

We may collect aggregated, anonymized usage events (for example, screens opened, features used, crash reports) to understand stability and improve the App. These events are not linked to your card records.

Device and advertising data

Free users see ads. Ad networks may process device identifiers, coarse location derived from IP address, and interaction data as described in section 3.

2. How We Use the Information

We use information to:

We do not sell your personal information and we do not use your financial records for advertising or profiling.

3. Advertising and AdMob

The free tier of the App is supported by advertising delivered through Google AdMob and its partners. Ad networks may use device identifiers and interaction data to select and measure ads. Where consent is required, including in the European Economic Area, the United Kingdom and Switzerland, we present a consent request before personalized advertising is enabled, and you may withdraw consent at any time in the App settings or your device settings.

Your card records, balances and payment history are never shared with ad networks. Pro subscribers see no ads.

Google's advertising practices are described at policies.google.com/technologies/ads.

4. Cloud Sync and Data Storage

Cloud Sync is optional and off by default. When you enable it, your Cardper records are encrypted in transit using TLS and stored on secured, access-controlled infrastructure operated by our hosting provider. Sync exists so that you can restore your data on a new device or use several devices with one account.

You can disable Cloud Sync at any time. Disabling it stops further uploads, and you may request deletion of the stored copy as described in section 10. If you never enable Cloud Sync, no card data leaves your device.

5. Data Retention

Local data remains on your device until you delete a record or uninstall the App. Synced data is retained while your account is active. If you delete your account, synced content is removed from our active systems within 30 days and from routine backups within 90 days. Anonymized analytics may be retained in aggregate form, since it cannot be traced back to you. Records we must keep for tax or legal reasons are retained for the period required by law.

6. Data Security

We apply appropriate technical and organizational measures: TLS encryption in transit for synced data, optional Face ID, Touch ID or PIN app lock on device, access control on our systems, and regular dependency updates. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Keeping your device passcode and your Apple or Google account secure is an important part of protecting your data.

7. Children's Privacy

The App is intended for users aged 13 and over, and where local law requires a higher age for consent to data processing, for users who meet that age. We do not knowingly collect personal information from children below that age. If you believe a child has provided us with personal information, contact us at contact@cardper.com and we will delete it.

8. Third Party Services

We rely on a small number of processors and platforms:

Each provider processes data under its own privacy policy and under our instructions.

9. International Data Transfers

We are based in Türkiye and our providers may process data in the European Union, the United Kingdom, the United States or other countries. Where personal data is transferred out of the European Economic Area or the United Kingdom, we rely on adequacy decisions or Standard Contractual Clauses, together with technical safeguards such as encryption.

10. Your Rights

Subject to applicable law, including the GDPR and the CCPA, you have the right to:

Most data lives only on your device, so deleting a record or the App removes it directly. For anything held under Cloud Sync, write to contact@cardper.com and we will respond within 30 days.

11. Subscriptions and Payments

Cardper Pro is sold as an auto renewing subscription through the Apple App Store and Google Play. Payments are processed by those stores. We never receive or store your card or payment details. The stores share limited transaction information with us so we can validate your entitlement and restore purchases. Manage or cancel your subscription in your App Store or Google Play account settings.

12. Changes to This Policy

We may update this policy as the App changes or the law requires. When we make a material change we will update the effective date above and, where appropriate, notify you inside the App. Continued use after an update means you accept the revised policy.

13. Contact Us

Questions, requests or complaints about this policy can be sent to:

WEBYAP YAZILIM LİMİTED ŞİRKETİ
İzmir, Republic of Türkiye
contact@cardper.com