Privacy Policy
Last updated 2 August 2026
mycarrd is a free link-in-bio builder. This policy explains what we collect when you use it, why we collect it, and what you can do about it. We do not sell your data, we do not run advertising, and we do not track you across other websites.
Who we are
mycarrd ("we", "us") operates mycarrd.link. We are the data controller for the information described below.
What we collect
Only what the product needs to work. There is no hidden collection beyond this list.
- Account details. When you sign up with email and password, we store your email address and an authentication record. Passwords are hashed by our authentication provider — we never see or store your password.
- Google account details, if you choose Google sign-in. We receive your email address, name and profile picture from Google. We do not receive your Google password and we request no access to any other Google service.
- Your page content. Everything you type into the editor: display name, bio, chosen avatar, theme, optional company name and logo, your username, and the label and destination URL of each link.
- Publication state. Whether your page is published, and when it was last saved.
- Technical logs. Our hosting and database providers keep short-lived operational logs (IP address, browser user-agent, timestamps, request paths) to serve traffic, prevent abuse and debug failures.
We do not collect payment details — mycarrd is free — and we do not ask for a phone number, a physical address or a date of birth.
Why we use it
- To sign you in and keep you signed in.
- To save your page and serve it to visitors at your public address.
- To keep usernames unique and to enforce the reserved-name list.
- To keep the service running: fix errors, prevent abuse, and protect accounts.
Where the GDPR applies, our legal bases are performance of a contract (running the service you asked for) and legitimate interests (security and abuse prevention).
What is public
A published page is public by design. Anyone with the address can read your username, display name, bio, avatar, theme, optional company details and every link you added — no account required, and search engines may index it.
Your email address is never shown on your public page. Treat the editor as a publishing tool: do not put anything in it you would not put on a public website.
Unpublishing removes the page from public view. Copies already made by other people, caches or search-engine indexes are outside our control.
Cookies and local storage
- Strictly necessary cookies. Set by our authentication provider to keep you signed in and to protect the session. The service cannot work without them, so they are not optional.
- Your cookie choice. Stored in your browser's local storage so we do not ask again on every visit. It never leaves your device as part of a profile.
- Editor state. Your work-in-progress card may be kept in your browser's local storage so a refresh does not lose it.
We run no advertising cookies and no cross-site trackers. The analytics and marketing categories in the cookie panel are off by default and remain unused until this policy says otherwise.
Who we share it with
We do not sell personal data and we do not share it for advertising. We use a small number of processors to run the service:
- Supabase — database and authentication. Stores your account record and your page content.
- Vercel — hosting and content delivery. Serves the site and keeps operational logs.
- Google — only if you choose Google sign-in, and only to authenticate you.
- Cloudflare — the anti-bot check on the sign-in form (Turnstile). It receives your IP address and signals about your browser in order to tell a person from a script. It does not identify you, and we do not use it to track you across sites.
We may also disclose information where the law requires it, or where it is necessary to investigate abuse or protect the rights and safety of users.
Where data is stored
Our providers operate globally, so your data may be processed outside your country, including in the United States. Transfers rely on the safeguards our providers offer, such as Standard Contractual Clauses.
How long we keep it
Your account and page content are kept until you delete them. Deleting your account deletes your profile and every link attached to it. Operational logs held by our providers are short-lived and expire on their own schedule.
Your rights
Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, and to object to certain processing.
- Access and correction. Sign in and open the editor — your page content is all there and editable at any time.
- Deletion. Email us from the address on your account and we will delete your account and content.
- Complaints. If you are in the EEA or the UK you may complain to your local data protection authority.
Security
Traffic is served over HTTPS. Access to your rows in the database is enforced by row-level security policies, so one account cannot read or write another account's private data. No service can promise perfect security, but we treat a breach of your account data as a serious failure and will notify affected users where the law requires it.
Children
mycarrd is not intended for children under 13 (or under 16 where local law sets that age). We do not knowingly collect data from them. If you believe a child has created an account, contact us and we will remove it.
Changes to this policy
If we change what we collect or why, we will update this page and move the date at the top. Material changes will be signalled in the product before they take effect.
Contact
Questions about this policy, or a request about your data: