Privacy notice
Version 1.0 · In force from 28 September 2026 · Last updated 28 September 2026
This notice explains what personal data we collect when you use Simplecard Business, why we use it, who we share it with, how long we keep it and the rights you have.
Who we are
Simplecard Business is run by Valesta Group LTD, registered in England and Wales under company number 14468408, registered office 60 Tottenham Court Road, Suite 5062a, Fitzrovia, London, W1T 2EW, United Kingdom. We are registered with the Information Commissioner's Office (ICO) under number ZC235270.
For anything about your personal data, email our data protection contact at data-officer@simplecard.io.
Our two roles
The law gives us a different role depending on whose data it is and why we have it.
- We are the controller for your account, your organisation's account, orders, payments, delivery, messages you send us, marketing choices and website security. This notice covers that data.
- We are a processor for the staff, member and other people's details that organisations put on cards: names, job titles, ID numbers, photos and similar details. The organisation that ordered the cards decides how those details are used and is the controller. We handle them only on its instructions, under our data processing agreement.
If your details are on a card your employer, club or school ordered, please contact them first with questions about your data. If you contact us, we will pass your request to them and help them answer it.
What we collect
- Account details: your name, email address, the organisation you design and order for, and whether you have confirmed your email. If you set a password we store it only in scrambled (hashed) form, so we cannot read it. If you turn on two-step sign-in, we store the settings for it.
- Google sign-in: if you choose to sign in with Google, Google tells us your name, email address and an identifier for your Google account. We never see your Google password.
- Organisation details: the organisation's name, billing email, delivery addresses, logos and colours, and the colleagues invited to it with their roles.
- Designs: the cards you design, the files you upload and the details you add to cards (see “Our two roles” above).
- Orders: what you ordered, prices, the delivery address, the recipient's name and phone number, the contact name, email and phone for the order, proof approvals, the order's progress, tracking details and messages about corrections.
- Payments: you pay on the secure payment page of Stripe, our payment provider. Stripe tells us whether the payment worked and gives us a payment reference. We never see or store your full card number.
- Messages: what you send us through the contact form or by email, such as your name, email address, organisation and message.
- Marketing choices: whether you have agreed to receive offers and news by email, when and where you agreed or unsubscribed, and the wording you were shown.
- Technical and security data: your IP address, browser and device type, the pages you request and when, and a record of important actions such as signing in, approving a proof, placing an order or changing settings. See our cookie policy for the cookies we use.
We do not ask for special categories of personal data, such as health information, and we ask you not to add them to cards unless we have agreed it with you in writing.
Do you have to give us your data?
- Your name, email address and organisation name are needed to create an account, save your designs and send you proofs. Without them we cannot keep your designs for you or take an order.
- Order, delivery and payment details are needed to enter into and carry out the contract: without a delivery address, a recipient and payment we cannot print or deliver your cards. We also have to keep invoice and payment records by law.
- The details on cards are up to you and your organisation: we print what you add.
- Marketing consent is entirely optional. Saying no, or not ticking the box, never affects your order.
- Contact form messages: we need your name and email address to reply to you.
How we use it and our lawful bases
- To provide the service you asked for: running your account, saving your designs, making proofs, taking payment, printing and delivering your order, and emailing you about it (order confirmations, proof questions, dispatch and tracking, set-password links and invitations). Lawful basis: contract (UK GDPR Article 6(1)(b)). For colleagues invited to an organisation, it is our and the organisation's legitimate interest in providing the service the organisation asked for (Article 6(1)(f)).
- To keep accounting and tax records, such as invoices and VAT records. Lawful basis: legal obligation (Article 6(1)(c)).
- To keep the service secure and prevent misuse, for example stopping fraud, checking cards we will not print and keeping an audit trail. Lawful basis: legitimate interests in protecting our customers, the people on cards and our business (Article 6(1)(f)).
- To answer your messages and handle complaints. Lawful basis: legitimate interests in helping you, or contract where it concerns an order.
- To fix problems and improve the website. Lawful basis: legitimate interests in running a reliable service.
- To send offers and news by email, only if you agreed. Lawful basis: consent (Article 6(1)(a)) and the Privacy and Electronic Communications Regulations.
- To establish, exercise or defend legal claims. Lawful basis: legitimate interests.
Where we rely on legitimate interests, we have balanced them against your rights. You can ask us for details and you can object (see “Your rights”).
We do not make decisions about you based only on automated processing, and we do not profile you.
Offers and news by email
We only send marketing emails if you have said yes, for example by ticking the box at checkout. That box is never ticked for you, and you do not need to tick it to buy. If you tick it before you have confirmed your email address, we first ask you, in your order confirmation email, to confirm that the address is yours and that you want offers, and we send none until you do. Our marketing emails are about Simplecard Business products and services only.
You can change your mind at any time, free of charge:
- use the unsubscribe link at the bottom of every marketing email;
- change your email preferences in your account; or
- email data-officer@simplecard.io.
Unsubscribing does not stop the emails we must send about your account and orders. We keep a record that you unsubscribed so that we do not email you offers again.
Who we share it with
- Service providers who help us run the service, such as hosting, payments, email delivery and sign-in. They may only use the data to provide their service to us. Our sub-processors page lists them.
- Stripe processes your payment. For some purposes, such as preventing fraud and meeting financial regulations, Stripe is a controller in its own right, under its own privacy policy.
- Google, if you choose to sign in with Google. Google handles your Google account under its own privacy policy.
- Delivery companies receive the recipient's name, address and, where they need it to deliver, phone number or email.
- Your organisation: owners of an organisation account can see the colleagues on it, their roles and the designs and orders made for the organisation.
- Professional advisers, such as accountants, lawyers and insurers, under a duty of confidentiality.
- Authorities, such as HM Revenue & Customs, the police or a court, when the law requires it or to prevent fraud or crime.
- A buyer of our business, if we sell or reorganise it. They would have to use your data in the same way.
We do not sell personal data, and we do not share it with other companies or with our sister brands for their own marketing.
International transfers
Some of our service providers, such as Stripe and Google, are based in the United States or process data there. When personal data leaves the United Kingdom we make sure it is protected, either because the UK government has decided the destination or the recipient gives adequate protection (for example the UK–US “data bridge” for certified companies), or by using the ICO's International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses. Email us if you would like more details.
How long we keep it
- Your account: while it is open. If you ask us to close it we delete your account details, except what we must keep for the reasons below.
- Accounts that were never set up: an account created when you continued from the editor is deleted automatically, with its organisation's designs, people and photos, once it has not been used for 30 days, if no password or Google sign-in was set up, the email address was never confirmed and nothing was ordered.
- Orders, receipts and payment records, including what was printed: six years after the end of the financial year of the order, because tax and company law require it.
- Designs saved in an organisation account, and the people's details on them: while the organisation's account is open, so you can reorder. Owners can delete designs at any time.
- Designs started without an account and never saved to one: deleted after 14 days.
- Earlier saved versions of a design: removed after 30 days (the latest 50 are always kept).
- Uploaded photos and logos that are not used in any design, card, saved branding or order: deleted after 90 days.
- Proofs that were never approved: deleted after 60 days. Approved proofs are kept with the order.
- Uploaded spreadsheets and photo ZIP files: deleted 30 days after the import finishes. The people added from them stay in the design.
- Print production files: deleted 120 days after they are made.
- Messages to us and complaints: for as long as we need them to deal with the matter and any follow-up.
- Marketing consent records: while you receive our emails, and afterwards for as long as we may need to show that you agreed. We keep a record that you unsubscribed so we never email you offers again.
- Security and audit records: for as long as they are needed to keep the service secure, and with the order records where they relate to an order.
Your rights
You have the right to:
- ask for a copy of your personal data (access);
- ask us to correct data that is wrong or incomplete;
- ask us to delete your data;
- ask us to limit how we use your data;
- receive data you gave us in a common digital format, or have it sent to another organisation (portability);
- object to our use of your data based on legitimate interests, and at any time to direct marketing, which we will then stop;
- withdraw your consent at any time, where we rely on it. This does not affect what we did before.
Some rights depend on our reason for using the data, and we may need to keep some data by law. To use any of these rights, email data-officer@simplecard.io. It is free. We may ask you to confirm your identity. We will reply within one month. If your request is complex, we may need up to two more months, and we will tell you if so.
Complaints about your data
Please tell us first if you are unhappy with how we have used your data, at data-officer@simplecard.io. We will acknowledge your complaint within 30 days and tell you what we are doing about it.
You also have the right to complain to the Information Commissioner's Office, the UK regulator for data protection: ico.org.uk/make-a-complaint, telephone 0303 123 1113.
How we protect your data
- All connections to the website are encrypted (HTTPS).
- Passwords are stored only in hashed form, and session data is encrypted.
- Uploaded files, proofs and print files are kept in private storage. They are never publicly available and are only shown to people with permission.
- Our staff's access to the admin area needs two-step sign-in, and staff only see what their role needs.
- Download links for print files stop working after a short time.
- Data we no longer need is deleted automatically on the schedule above.
No system is perfectly secure. If a breach puts your rights at high risk, we will tell you without undue delay.
Children
Our website is for adults ordering for themselves or for an organisation. We do not knowingly create accounts for children. Clubs and schools may order cards for members or pupils under 18. In that case the organisation is the controller for the details on the cards and must make sure it is allowed to use them.
Changes to this notice
We will update this notice when the way we use personal data changes. The version and date at the top show when it last changed. If a change affects you significantly, we will tell you by email or on the website before it takes effect.