CardimSign in

Privacy Policy

Last updated: 24 August 2026

This English text is a translation provided for convenience only. Only the Portuguese version is binding and it prevails in the event of any discrepancy: read the Portuguese version.

1. Who this policy applies to

This policy applies to two groups: Merchants, who create an account to manage bookings, and customers, who make a booking through a Merchant’s public page without creating any account of their own. As regards customers’ data, the Merchant whose page was used is the data controller and Cardim is their data processor — see our Terms of Service for that relationship.

2. What we collect

If you are a Merchant: your business name, your name, your email address, your password (always stored as a hash, never in plain text) and your time zone, and the address and telephone number of your establishment. If you connect Google Calendar and/or the Outlook/Office 365 calendar, we store the OAuth tokens needed to read your availability and to write the events for your bookings. When reading, we take only the free and busy periods from your calendar, not the titles or the details of the events. When writing, the event goes — with Google — into a separate calendar that Cardim creates in your account, which is the only calendar Cardim is able to see or change, and — with Outlook/Office 365 — into the calendar you authorise. Each booking we create for you as an event includes the customer’s name and telephone number, so it is visible to anyone else with access to that calendar. The notes the customer wrote are not copied there — the event states only that a note exists, and its content stays in Cardim.

If you are making a booking as a customer: the name, telephone number and email address you enter, the date, the time and the service you chose, and whatever you decide to add in the notes field, which is optional. The email address is needed because that is how we send you the confirmation, the reminder and the link to change or cancel — without it you would receive nothing. For a restaurant booking we also ask for the number of people and, if you wish to give them, the part of the room you prefer and the occasion. We do not ask for identity documents, payment details or any other personal information, and there is no customer account or password — a booking is identified by a link that cannot be guessed, not by a login.

If the Merchant you booked with has Google Calendar and/or the Outlook calendar connected, your name, telephone number and time are also written into the event that Cardim creates for them in that calendar — see the previous paragraph. Any notes you write are not copied into that calendar: the event states only that a note exists. They are, however, included in the new-booking notification we send the Merchant by email, delivered by our email sending provider — see section 5. If we delete your data, we also delete the event Cardim created; if we can no longer reach it — because the Merchant has since disconnected that calendar, for instance — we tell the Merchant so, so that they can delete it themselves.

As happens with web applications generally, our hosting providers automatically record routine technical information (IP address, date and time, addresses requested) for security and reliability reasons.

3. What we use it for

  • To operate the booking system itself — showing real availability, preventing overlapping bookings and creating the booking.
  • To send confirmations, reminders and cancellation notices by email and, if the Merchant has set it up, a review request after the visit.
  • To enable the Merchant to manage their calendar, their staff, their services and their customer list.
  • To notify customers on the waiting list when a slot they wanted becomes free.
  • To keep the Service secure and to diagnose problems.
  • To calculate what the Merchant pays us: each month, we count the bookings made for that month and the number of people on each one. Cancelled bookings, those the Merchant marks as no-shows and those the Merchant enters themselves do not count. For this count we use only the date, the time, the status and the number of people — never the name, telephone number, email address or notes of the person who booked.

We do not use booking data for advertising and we do not sell personal data to third parties.

4. Legal basis (UK and EU GDPR)

We process the Merchant’s account data in order to perform our contract with them (the provision of the Service). We process customers’ booking data on the Merchant’s behalf and in accordance with the Merchant’s instructions, for the performance of the Merchant’s own contract with that customer (the booking in question) — see section 1. Where applicable, we also rely on legitimate interests (for example, to prevent misuse of the waiting list or of cancellations).

The count described in the last point of section 3 is the only processing of booking data that we carry out on our own account and not on the Merchant’s behalf. In that part — date, time, status and number of people, with no identification of who made the booking — the data controller is Cardim, on the basis of the performance of the contract we have with the Merchant and of compliance with our legal obligations relating to invoicing and accounting.

Health information. If you write information about your health in the notes field — a food allergy, for example, which is precisely what that field asks for at a restaurant — that information is a special category of personal data (Article 9 of the GDPR). We process it, and pass it on to the Merchant, only with your explicit consent, which you give us by choosing to write it in that field after this notice. You may withdraw it at any time by asking for the note to be deleted. If you would rather not record it here, tell the establishment directly.

5. Who we share it with

Personal data is shared only where it is necessary for the Service to work:

  • The Merchant whose booking page the customer used — they need the customer’s contact details in order actually to provide the service booked.
  • Resend, our email sending provider, to send the confirmation, reminder and cancellation emails.
  • Google, only for Merchants who choose to connect Google Calendar — the free and busy periods read from the calendar and, on each booking made through Cardim, an event written into a separate calendar that Cardim creates in that account, with the customer’s name, telephone number, service and time. The notes written by the customer are not sent to Google: the event states only that a note exists.
  • Microsoft, only for Merchants who choose to connect the Outlook/Office 365 calendar — the same reading of availability and the same writing of an event described above, likewise without the customer’s notes, in the Microsoft calendar you authorise.
  • Neon and Vercel, our database and application hosting providers, which store and run the Service’s infrastructure on our behalf.
  • Sentry, our error detection service, which receives technical reports when something fails in the application. From the messages we send, we remove email addresses and the links that give access to a booking or to a password reset, so that those reports cannot be used to access your booking.

We never sell personal data and we never share it for third-party advertising.

6. How long we keep it

Booking records are kept for as long as the Merchant’s account is active, so that they can manage their booking history and the related statistics. Cancelling a booking does not delete its history; the booking is marked as cancelled so that the record remains faithful to what happened.

A customer may ask the Merchant they booked with — or us, at the address given in section 7 — to have their data deleted. When that happens, we permanently delete the name, the email address and the notes, and replace the telephone number with a meaningless marker — the record has to continue to exist so that the bookings are not left orphaned, but it is no longer associated with any person. We also delete any event we have created in the Merchant’s Google Calendar or Outlook, which is the only copy of that data outside Cardim; if for some reason we cannot, we tell the Merchant so that they can delete it themselves. The bookings themselves remain, with nobody associated with them, because they are the Merchant’s accounting and tax record — a separate obligation that the right to erasure does not override.

Not everything is kept in this way. Waiting list entries — which hold the name, the telephone number and the email address of someone who never actually booked — are deleted 30 days after the date they related to. Logged-in sessions expire after 30 days and are then deleted. The technical records we use to block abusive access attempts hold only an irreversible code derived from the IP address, never the address itself, and are deleted after 24 hours.

7. Your rights

Under the GDPR you have the right to access your personal data, to rectify it, to erase it and to export it, and also to object to certain processing or to ask for it to be restricted. Customers may address their request directly to the Merchant they booked with, or contact us at support@usecardim.com and we will forward the request to whoever is responsible for it.

You also have the right to lodge a complaint with the competent supervisory authority. In Portugal, this is the Comissão Nacional de Proteção de Dados (CNPD) — www.cnpd.pt.

Merchants can export all of their account data at any time, under Settings → Your data. To correct the account name or email address, or to close the account and delete everything, write to us at support@usecardim.com: we reply and complete the request within 30 days.

8. Security

Passwords are stored as hashes, never in plain text. All data in transit is encrypted (HTTPS/TLS). Access to production data is limited to what is necessary to operate and support the Service. No system is completely secure and we cannot guarantee absolute security, but we take reasonable, industry-standard measures to protect the data we hold.

9. Cookies

We use exactly one cookie: a strictly necessary session cookie (cardim_session) that keeps the Merchant signed in to the admin dashboard. It is an opaque identifier, with no readable information inside it, marked httpOnly and secure, so that page scripts cannot read it and so that it is only sent over an encrypted connection (HTTPS). It is not used for tracking or for advertising. We do not currently use any third-party analytics or advertising cookies. Customers making a booking receive no cookie at all — the booking is reached through its unguessable link, not through a session.

10. Children’s privacy

The Service is not directed at children and Merchant accounts are intended for businesses only. We do not knowingly collect children’s personal data through the booking process, beyond what a parent or guardian may provide on the child’s behalf (for example, when booking a haircut for their child).

11. International data transfers

Your bookings and your customers’ data are stored in a database hosted in London, in the United Kingdom (Neon, on AWS infrastructure in the eu-west-2 region). The other providers listed in section 5 — email sending, application hosting and calendars — may process data in other countries.

We choose providers that offer appropriate safeguards for international transfers (such as the standard contractual clauses) wherever the law requires it.

12. Changes to this policy

If we make substantial changes to this policy, we will update the “Last updated” date above and, wherever practicable, notify Merchants directly.

13. Contact

Questions about this policy, or any request concerning your data, may be sent to support@usecardim.com.