Back to home
Legal · Privacy

Privacy Policy

A clear account of what Cardrine collects, why we use it, who receives it, and the choices available to you.

Plain-language policy
Built for transparency
Last updated
August 27, 2026
Product status
Early access
01

Who we are and what this policy covers

Merchant Processor Limited operates the Cardrine brand (“Cardrine”, “we”, “us”). Unless we identify another organisation when information is collected, Merchant Processor Limited is responsible for the personal data described in this policy.

This policy applies when you visit the Cardrine website, join the waitlist, contact us, or use a Cardrine account or early-access gift card service that is made available to you (together, the “Service”). It does not govern an independent third-party service that has its own privacy notice.

Current product status. The public website and waitlist are available today. Trading screens and product examples may be previews. Provisions about identity verification, trades, and payouts apply only when those features are offered and used.
02

Personal data we collect

The information we collect depends on how you use Cardrine:

  • Website and waitlist data. Your email address, trading intent, gift card brand interests, and any preferences you submit when requesting access.
  • Account and identity data. If account or trading features are offered, this may include your name, contact details, date of birth, address, login credentials, authentication factors, government-issued identification, selfie, and verification results. We collect biometric data only where necessary, legally permitted, and explained before collection.
  • Gift card and transaction data. Gift card brand, value, region, card details or credentials submitted for review, proof of ownership, quoted and accepted offers, order history, status, disputes, and support records.
  • Payout data. Details needed to arrange an available payout, such as account-holder information, destination account details, payout status, and provider references. The information required varies by method and location.
  • Technical and security data. IP address, browser and device information, user agent, request timestamps, pages or features used, session and authentication events, diagnostic records, and fraud or security signals.
  • Communications and preferences. Messages, support requests, feedback, survey responses, and records of your notification or marketing choices.
  • Derived information. Risk indicators, account or transaction links, and verification outcomes produced from the information above to help identify fraud, misuse, or security concerns.

Please do not send Gift Card credentials, identity documents, or payment information through ordinary email unless we specifically provide a secure method and ask you to do so.

03

Where personal data comes from

We collect personal data:

  • directly from you and the devices you use;
  • from identity, fraud-prevention, payment, payout, hosting, and communications providers used to support the Service;
  • from counterparties or partners involved in a transaction, where relevant and permitted; and
  • from public or legally accessible sources when needed for verification, fraud prevention, sanctions, or legal compliance.

If you provide information about another person, you must be authorised to do so and should ensure they understand how their information will be used.

04

Why we use personal data

We use personal data only where we have a lawful reason. Depending on the activity and your location, those reasons may include:

Provide the Service

To manage the waitlist, create and secure accounts, process instructions, review trades, arrange payouts, and provide support. This is generally necessary for a contract with you or steps you request before a contract.

Keep Cardrine safe

To authenticate users, verify cards and identities, investigate suspicious activity, prevent fraud, protect systems, and enforce our rules. We generally rely on legitimate interests, contract, or legal obligations.

Meet legal obligations

To complete required identity or sanctions checks, keep records, respond to lawful requests, manage complaints, and make required reports where applicable.

Improve and communicate

To troubleshoot, measure reliability, improve product flows, respond to feedback, and send requested updates. We rely on legitimate interests or consent, depending on the activity.

Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect processing that was lawful before withdrawal. Where we rely on legitimate interests, we assess whether those interests are proportionate and compatible with your rights.

05

Verification, fraud review, and automation

Cardrine may use rules, risk indicators, and automated tools to help verify account or Gift Card information, detect duplicate or unusual activity, protect payouts, and prioritise transactions for review. These tools may produce a risk score or recommendation.

We do not intend to make a decision that has a legal or similarly significant effect on you based solely on automated processing without the safeguards required by applicable law. Where you have a right to request human review, explain your position, or challenge a decision, you may contact us using the details below.

06

When we share personal data

We do not sell personal data. We disclose only what is reasonably necessary for the relevant purpose, including to:

  • Technology and operations providers supporting hosting, communications, authentication, customer support, analytics, security, or other platform functions.
  • Verification and risk providers supporting identity, Gift Card, fraud, sanctions, or transaction review.
  • Payment and payout providers involved in an available transaction or payout method.
  • Professional advisers and auditors where they need information to provide legal, compliance, accounting, or assurance services.
  • Authorities and affected parties when disclosure is required by law, valid legal process, or reasonably necessary to protect people, rights, property, transactions, or the Service.
  • A successor organisation in a proposed or completed financing, reorganisation, merger, acquisition, or sale, subject to appropriate confidentiality and legal requirements.
  • Other recipients you direct or approve.

Providers may use personal data only for agreed purposes and under applicable contractual and security requirements. Some recipients, such as a bank or identity provider, may also act independently under their own privacy notice.

07

How long we keep personal data

We retain personal data only for as long as reasonably necessary for the purpose collected, including to provide the Service, preserve transaction integrity, comply with legal, accounting, tax, fraud, or reporting obligations, resolve disputes, and enforce agreements.

Retention depends on the type and sensitivity of the data, the associated risk, the status of your relationship with us, and any mandatory period. Gift Card credentials and identity information receive restricted access and are not kept merely because they might be useful later. Information may remain in protected backups for a limited period after deletion from active systems.

When retention is no longer justified, we delete, anonymise, or securely dispose of the information, subject to any legal hold.

08

How we protect personal data

We use administrative, technical, and organisational safeguards designed for the sensitivity of the information and the risks of the Service. Depending on the system, these may include encryption, access controls, multi-factor authentication, session controls, logging, monitoring, vulnerability management, backups, and provider reviews.

No service can guarantee absolute security. Use a strong, unique password, enable available authentication features, protect Gift Card credentials, and contact us promptly if you suspect unauthorised access or an information-security incident.

09

Your rights and choices

Your rights depend on the law that applies to you. They may include the right to:

  • be informed about how your personal data is used;
  • request access to or a copy of your personal data;
  • correct inaccurate or incomplete data;
  • request deletion or restriction in appropriate circumstances;
  • object to processing, including certain direct marketing;
  • receive portable data where the right applies;
  • withdraw consent where processing relies on consent; and
  • request safeguards concerning certain solely automated decisions.

Email privacy@cardrine.com to exercise a right. Describe your request and the email or account it concerns. We may need to verify your identity and may retain a record of the request. We respond within the period required by applicable law and ordinarily do not charge a fee.

You may also complain to the data-protection authority in your location. In Nigeria, this is the Nigeria Data Protection Commission. We would appreciate the opportunity to address your concern first, but contacting us does not limit your right to complain.

10

Cookies, analytics, and product updates

Cardrine does not currently use advertising cookies on this public website. Our hosting and security infrastructure may process essential technical information needed to deliver pages, prevent abuse, and maintain logs. Early-access account features may use strictly necessary cookies or similar storage for authentication, security, and preferences.

If we introduce optional analytics, advertising technologies, or materially different cookie use, we will update this policy and provide choices where required. You can also use browser controls to delete or block stored data, although essential account features may then stop working.

When you join the waitlist, you ask us to send Cardrine product and early-access updates. You can opt out using an unsubscribe method in the message or by emailing us. We may still send non-marketing service or security messages where appropriate.

11

International processing and transfers

Cardrine and its providers may process personal data in countries other than where you live. Before making a transfer that requires protection under applicable law, we assess the recipient and use an appropriate legal mechanism and safeguards, such as contractual, organisational, and technical protections. You may contact us for more information about safeguards relevant to your data.

12

Children's privacy

Cardrine is intended for people aged 18 or older. We do not knowingly offer accounts or Gift Card trading services to children. If you believe a child has provided personal data to Cardrine, contact us so we can investigate and take appropriate action.

13

Changes and contact details

We may update this policy as the Service, our practices, or legal requirements change. We will post the revised version here and update the date above. If a change materially affects how we use personal data, we will provide additional notice where appropriate.

Questions, privacy requests, or concerns can be sent to Merchant Processor Limited / Cardrine at privacy@cardrine.com. Security concerns may also be sent to security@cardrine.com.

This notice describes current website and waitlist processing and conditionally covers early-access features when they are made available. Email privacy@cardrine.com with privacy questions or requests.