Effective Date: November 08, 2025
At Big Day Card (bigdaycard.com), we are committed to protecting your privacy and ensuring the security of your personal information. Our contact details are provided at the end of this policy. We are committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679, as well as other applicable data protection laws worldwide, including but not limited to the California Consumer Privacy Act (CCPA) for users in California, USA.
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website https://bigdaycard.com/ (the “Site”) or use our services to generate AI-powered birthday invitations (the “Service”). By using the Site or Service, you consent to the practices described in this policy. If you do not agree, please do not use our Site or Service.
1. Data Controller
Email: privacy@bigdaycard.com
We act as the data controller for personal data processed through the Site and Service.
2. Personal Data We Collect
We collect the following types of personal data:
a. Data You Provide Directly
- User-Uploaded Content: When generating invitations, you may upload photos (e.g., child’s photo), provide names, ages, themes, designs, and additional text. Photos may contain personal identifiers such as faces.
- Contact Information: Email address (provided for payment confirmation, download links, free generations limit, and inquiries).
- Payment Information: Billing details processed via payment processors (we do not store card details; see Section 5 for details).
b. Automatically Collected Data
- Device and Usage Information: IP address, browser type, device identifiers, operating system, pages visited, time spent, and referral sources.
- Cookies and Similar Technologies: See our separate Cookie Policy for details. We use essential cookies for functionality (e.g., session management) and may use analytics cookies if enabled.
c. Data from Third Parties
- Information from payment processors or AI providers related to your transactions or generations.
We do not intentionally collect sensitive personal data (e.g., racial or ethnic origin, health data) unless inherent in uploaded photos. We do not collect data from children under 16 without verifiable parental consent; if you believe we have such data, contact us immediately.
3. How We Use Your Personal Data
We process your personal data for the following purposes:
- Providing the Service: To generate, preview, and deliver AI-created invitations based on your inputs.
- Payments and Transactions: To process payments and track usage limits.
- Site Functionality: To maintain security, prevent abuse, and improve user experience.
- Analytics and Improvements: To analyze usage patterns (anonymized where possible) and enhance the Service.
- Legal Compliance: To comply with laws, respond to authorities, or enforce our terms.
- Marketing: With your consent, to send updates or promotions (you can opt out anytime).
Legal Bases under GDPR:
- Consent: For photo uploads, AI text generation, and optional marketing.
- Contract: To fulfill your request for invitation generation and delivery.
- Legitimate Interests: For security, analytics, and site maintenance (balanced against your rights).
- Legal Obligation: For payment records or regulatory compliance.
4. Data Retention
- Invitation Files: Stored for up to 24 hours after creation, then automatically deleted (including thumbnails and previews). Database entries (e.g., metadata like theme/design) may be retained longer for auditing but anonymized where possible.
- Payment Data: Retained as required by law (e.g., 7 years for tax purposes) but minimized.
- Email, IP, Device ID and Usage Data: Retained for up to 12 months for security and limit enforcement.
- We delete data upon request unless legally required to retain it.
5. Sharing Your Personal Data
We share data only as necessary:
- Service Providers:
- AI and machine learning service provider in the technology sector, located in the United States, used for generating invitation content.
- Financial technology providers specializing in payment processing, located in the United States and Ireland.
- Legal Requirements: To comply with laws, court orders, or government requests.
- Business Transfers: In case of merger or sale (with notice to you). We do not sell your personal data. Transfers outside the EU/EEA use Standard Contractual Clauses or other GDPR-approved mechanisms.
6. Your Rights
Under GDPR and similar laws (e.g., CCPA):
- Access: Request a copy of your data.
- Rectification: Correct inaccurate data.
- Erasure (“Right to be Forgotten”): Delete your data (subject to exceptions).
- Restriction/Objection: Limit processing or object to it.
- Portability: Receive your data in a structured format.
- Withdraw Consent: Where processing relies on consent.
- Do Not Sell (CCPA): We do not sell data, but you can opt out of any future sales.
- Complaints: Lodge with your local data protection authority (e.g., in the EU) or contact us first.
To exercise rights, email privacy@bigdaycard.com. We respond within 30 days (extendable under GDPR).
7. Security
We use industry-standard measures (e.g., encryption, access controls) to protect data. However, no system is 100% secure. Report vulnerabilities to privacy@bigdaycard.com.
8. Children’s Privacy
The Service is not for children under 13 (or 16 in some jurisdictions). We do not knowingly collect data from them without consent.
9. International Users
If you’re outside the EU, your data may be transferred to the EU for processing. We comply with applicable laws, but protections may differ.
10. Changes to This Policy
We may update this policy. Changes are posted here with the effective date. Continued use constitutes acceptance.
11. Contact Us
For questions: privacy@bigdaycard.com