Back to home

Privacy Policy

Last updated: July 23, 2026

Carded ("Carded," "we," "us") builds a browser-based tool that helps retailers verify a customer's age from the barcode on a government-issued ID. This policy explains what happens to data when you use Carded. In plain terms: the actual ID scanning happens on your own device, and we do not collect, upload, or sell the personal information on your customers' IDs.

Carded is privacy-first by design. When you scan an ID, the barcode is decoded locally in your browser. The name, date of birth, and other details never leave the device and are never sent to our servers.

1. Information processed on your device

When you scan an ID, Carded reads the data encoded in the barcode (such as name, date of birth, address, ID number, and expiration date) to calculate age and check the expiration date. This processing happens entirely within your browser. This information is displayed to you and, if you choose, added to a local scan log.

The scan log, the unique device identifier, and any device name you set are stored only in your browser's local storage on that device. They remain there until you clear them, clear your browser data, or export them. We cannot see this information.

Carded also keeps two optional records on the device to power its watchlist and compliance features. The watchlist (IDs you mark as "86'd" or VIP) and the re-scan check do not store the raw ID number: each ID is saved as a one-way cryptographic hash (a fingerprint that cannot be turned back into the original number), alongside any note, name label, and timestamp you add. The compliance report stores only the outcome of each scan, pass, decline, expired, the device and staff name, and that same hashed fingerprint, with no customer names, dates of birth, or ID numbers. Both live only on the device, are never uploaded to us, and can be exported or cleared by you at any time.

If you use the optional DeliveryPro add-on, Carded also creates a delivery record when you complete a delivery. Because a delivery is a documented hand-off, this record can include more than a normal scan: the recipient's name (pre-filled from the scanned ID, which you can edit), their on-screen signature as an acknowledgment of receipt, a not-visibly-intoxicated confirmation, an optional photo you choose to take at the hand-off, the delivery address (from your device's location, which you can edit or enter by hand), an order number you enter, the time, and the same outcome and hashed fingerprint described above. It does not store the recipient's date of birth or ID number. These delivery records, including the name, signature, and any photo, are stored only on your device. They are never uploaded to us, and you can export them (for your own compliance records) or clear them at any time. You are responsible for handling any records you export in line with the laws that apply to your business.

To keep your plan's device count accurate and to give you, the account owner, a usage overview, each authorized device sends a small check-in to us when it is online. This check-in contains only anonymized numbers, such as how many scans, declines, and expired IDs a device has recorded, along with the device name you set and the device's approximate location. It never includes any customer's name, date of birth, or ID number, or the ID data itself. You can view this usage information in the app, and it exists so you can manage your own devices, not to profile anyone.

2. Information we do not collect

3. Location data

If you enable location, Carded reads your device's approximate GPS coordinates at the time of a scan so it can tag the scan with a location. To convert those coordinates into a readable address, the coordinates (and only the coordinates, never any ID data) are sent to the OpenStreetMap Nominatim service. We do not store your location on our servers. You can decline or revoke location permission at any time in your browser or device settings.

4. Information you provide to us

If you submit your email address through a form on our website (for example, to receive product updates or contact us), we collect that email address so we can respond or send you the updates you requested. We use it only for that purpose and you can ask us to remove it at any time.

When you start a subscription or free trial, our payment processor Stripe collects the information needed to set up billing. This may include your name, your venue or business name, your billing address and (optionally) your venue's street address, a phone number, and your payment-card details. Your full card details are handled directly by Stripe and are never seen or stored by us. We receive and retain limited account information, such as your email, venue name, address, plan, and subscription status, so we can provide the Service, manage your plan and the devices on it, and support you.

5. Automatically collected technical data

Our website is hosted on Netlify. Like most websites, our host may automatically log standard technical information such as IP address, browser type, and pages requested for security and to keep the service running. We use privacy-respecting hosting and do not use this data to identify individual visitors.

6. Cookies and local storage

Carded does not use advertising, analytics, or cross-site tracking cookies. It uses a small number of strictly necessary cookies, together with your browser's local storage, only to make the app work:

These are all functional and necessary for the Service; we do not use them to track you across other websites. Clearing your browser's cookies or storage removes them and will sign the device out.

7. Third-party services

Each provider processes only the limited data described above and under its own privacy terms.

8. Your responsibilities as a retailer

You control any records you choose to export from Carded (such as a CSV of your scan log). Once exported, that file is yours and its handling is your responsibility. Some jurisdictions place limits on scanning, recording, or retaining information from customers' IDs. You are responsible for complying with the laws that apply to your business and location.

9. Data retention

Because scan data lives on your device, its retention is controlled by you. Emails you submit to us are kept only as long as needed to provide updates or support, or until you ask us to delete them.

10. Children's privacy

Carded is a tool for businesses and is not directed to children. We do not knowingly collect personal information from children through our website.

11. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.

12. Contact us

Questions about privacy? Email support@trycarded.app.