Privacy Policy

Last updated: 28 September 2026

This policy explains how the Cardashian app (“the app”) and this website handle personal data: what we collect, why, on what legal basis, who else receives it, how long we keep it, and what rights you have. It is written for the EU General Data Protection Regulation (“GDPR”) and Latvian law.

1. Who we are

The controller of your personal data is SIA “Limedot” (reg. No. 50203718151), Miera iela 61 k-1 - 1, Rīga, LV-1013, Latvia (“we”, “us”). For anything about your data, email hello@limedot.io. We have not appointed a data protection officer, because the law does not require one for a company and service like ours; that email address reaches the people responsible for privacy.

The short version

2. What we collect, why, and on what legal basis

“Contract” means we need the data to provide the app you asked for (GDPR Art. 6(1)(b)). “Legitimate interest” means we use it for a reasonable purpose of ours that does not override your rights (Art. 6(1)(f)); you can object to these uses (see section 10). We do not rely on your consent as the legal basis for any processing.

PurposeDataLegal basisHow long
Your account (Sign in with Apple) A random account ID, your email address (or Apple’s private relay address if you hide it), your name if you choose to share it, sign-in dates Contract Until you delete your account
Keeping and backing up your cards Each card’s store name, card number and barcode type, category, expiry date, balance, colour or background, card photos, favourite flag, dates Contract Until you delete the card or your account
Keeping your settings App settings such as theme, notification choices, nearby radius and country Contract Until you delete your account
Finding where a store is (see section 3) The store name you search for and your location at that moment (as a small area around you), your IP address Contract We do not store it. OpenStreetMap’s own retention applies (section 5)
Sharing a card (section 4) A copy of the shared card including its photos, your account ID, dates Contract At most 14 days (section 9)
The Lock Screen card when the app is in the background (section 6) Device push token; the nearby cards’ name, initials, colour and distance; your account ID; a counter Contract (sending the card); legitimate interest (the counter, to prevent abuse) The card data is not stored. The counter: see section 9
Community store map (section 7) Store pins and confirmations you add, with your account ID and the time Legitimate interest: a shared, accurate store map for all users, with one vote per account so it cannot be manipulated Your answers: until you delete your account. Unconfirmed pins: 30 days. Confirmed pins stay on the map; your account ID is removed from them when you delete your account (section 9)
Store name catalogue When you save a card, its store name, category and country are added to a shared list of store names. No account ID is stored with it Legitimate interest: suggesting store names to all users Kept as long as the service runs
App updates On each start, the app asks Expo’s update server whether there is a newer version: your IP address, iOS version, app version and a random update token Legitimate interest: delivering bug and security fixes quickly Expo’s retention applies (section 5)
Running and securing our servers Technical request logs kept by Google Cloud when the app calls our functions (for example IP address, time, and device type) Legitimate interest: keeping the service working and secure About 30 days (Google Cloud’s standard log retention)
Sign-up statistics We count how many accounts were created per day from account creation dates. Only totals are shown to us, never names or emails Legitimate interest: understanding how the app grows Totals are computed on request and not stored
Answering your emails and privacy requests Your email address and what you write to us Legitimate interest (support); legal obligation for privacy requests (Art. 6(1)(c)) As long as needed to deal with your message, and up to 3 years to show how we handled a privacy request

Stored only on your phone. The app also keeps some data only on your device: a list of store locations for your cards, the last time you were reminded about each store, your country code, which store checks you have already answered, the Lock Screen card’s push token, and the store areas iOS watches for reminders. Your sign-in token is kept in the iPhone Keychain. This data is needed for features you turned on and is not sent to us, except where this policy says so.

Camera and photos. The camera is used to scan a barcode or photograph a card, and your photo library only when you pick a picture. Scanning happens on your phone. Card photos you save are part of the card, so they are backed up to your account and included if you share that card.

3. Location

Location is optional. If you do not allow it, everything except nearby reminders, the nearby list and map features still works. You can change this at any time in iOS Settings → Cardashian → Location.

Our app code can also send store searches with your location to our own resolveStores function (which asks OpenStreetMap’s Overpass service) or to Google Places. Neither is switched on in the current version of the app. We will update this policy before switching either on.

4. Sharing a card

If you share a card, a copy of it (including its photos and your account ID) is uploaded to our database, and the app gives you a link. Anyone who has the link can open that copy, so only send it to people you trust. The copy is deleted when the recipient adds the card or when you revoke the link in Settings → Shared cards. Otherwise the link stops working after 14 days — the app refuses to serve an expired copy from that moment, even if the underlying record has not been purged yet — and the record itself is deleted automatically afterwards, which may take a little longer.

5. Who receives your data

We do not sell your data and we do not share it with advertisers. Only these companies receive it:

RecipientWhat forRoleWhere
Google Ireland Ltd / Google LLC (Firebase, Google Cloud) Sign-in accounts, the database (cards, settings, shared cards, store map), our server functions, hosting this website Our processor, under the Firebase Data Processing Terms Database: EU (Firestore eur3 region). Sign-in and server functions: United States
650 Industries, Inc. (Expo) Delivering app updates Our processor United States
Apple (Apple Distribution International Ltd and Apple Inc.) Sign in with Apple; delivering the Lock Screen card (Apple Push Notification service); Apple Maps; country lookup Independent controller for its own services (Apple’s privacy policy) Ireland and United States
OpenStreetMap Foundation (Nominatim) Finding store locations Independent controller (OSMF privacy policy) United Kingdom and EU
Other app users The community store map (section 7) and cards you share by link (section 4) Recipients of what you choose to share Anywhere

We may also disclose data if the law requires it, for example to a court or the police with a valid legal request.

6. The Lock Screen card (Live Activity)

While you are near stores you have a card for, the app can show a card on your Lock Screen and in the Dynamic Island. If the app is open, your phone shows it without contacting us. If the app is in the background, iOS only lets it start by a push, so the app sends our server (a Google Firebase function) the device push token Apple gave the app, and each nearby card’s name, initials, colour and distance to the store. This tells our server which of your saved stores you are near at that moment. Your exact location is not sent. Our server passes this straight to Apple’s push service and does not store it. It stores only a small counter under your account ID (the start of the current hour and how many requests your account made in it), so no one can send too many pushes; the limit is 10 per hour. Updating and removing the card happen on your phone. Apart from this card, the app does not use push notifications; expiry and nearby reminders are scheduled on your phone.

7. Community store map

Store locations in the app are added and checked by users. If you pin a store or answer “is this store here?”, we save the store’s name, address and coordinates, and your answer, together with your random account ID and the time. The store entries, including the account ID of the person who added them and when, are publicly readable, so a pin can show that the account that added it was at that store around that time. Your answers are stored separately and only you and we can read them; other users see only the total number of confirmations. We never publish your name or email. If you would rather not share this, don’t add pins; the rest of the app works the same.

An unconfirmed pin stops being shown after 30 days and is deleted automatically after that, which may take a little longer to run. Once three users confirm a pin, it stays as part of the map.

8. Transfers outside the EU

Some recipients process data outside the European Economic Area:

Email us for a copy of these safeguards.

9. How long we keep data, and deleting it

Store pins you added stay on the community map after you delete your account, because other users rely on them, but your account ID is removed from them, so they are no longer linked to you.

10. Your rights

Under the GDPR you have the right to:

To use any of these rights, email hello@limedot.io. We may ask you to confirm the request from the email linked to your account, so we know it is you. We answer within one month; if a request is complex we may take up to two more months and will tell you why. It is free.

Permissions. We do not rely on consent, but you control every iOS permission (camera, photos, location, notifications) and can turn it off at any time in iOS Settings → Cardashian.

11. Complaints

If you think we have handled your data wrongly, please tell us first so we can fix it. You also have the right to complain to a data protection authority: in Latvia this is the Datu valsts inspekcija (Data State Inspectorate), Elijas iela 17, Rīga, LV-1050, Latvia, phone +371 67223131, email pasts@dvi.gov.lv, www.dvi.gov.lv. You can also complain to the supervisory authority of the EU country where you live, work, or where the alleged infringement took place.

12. Do you have to give us your data?

The app needs an account, so you must sign in with Apple to use it; you can hide your real email address when you do. The data in your cards is what you choose to add. Location, camera, photos and notifications are optional; without them, only the features that need them stop working.

13. Automated decisions

We do not make decisions about you by automated means that have legal or similarly significant effects, and we do not profile you.

14. Security

Data travels between the app and our servers over encrypted connections (HTTPS). Your backed-up cards and settings can be read only by your own signed-in account; our database rules enforce this. Google encrypts the stored data. Your sign-in token is kept in the iPhone Keychain, and the rest of the app’s data on your phone is protected by iOS’s standard device encryption. Only a small number of people at Limedot can access the servers. No system is perfectly secure; if a breach puts you at high risk, we will tell you without undue delay.

15. Children

The app is not directed at children under 13. In Latvia, children aged 13 and over can use online services like this on their own (Section 33 of the Personal Data Processing Law); in some other EU countries the age is higher, up to 16. If you are below the age that applies where you live, please use the app only with the permission of a parent or guardian. If we learn that we hold data about a child without that permission, we will delete it. Parents can contact us at hello@limedot.io.

16. This website

This website is hosted on Google Firebase Hosting. It sets no cookies and uses no analytics. The pages, fonts and images, including the App Store badge, are all served from this website, so when you visit it your browser contacts only Google Firebase Hosting, which receives your IP address to deliver the pages. We use this only to show you the website (legitimate interest). Opening a shared-card link on the website only passes the link on to the app.

17. Changes to this policy

If we change how we handle your data, we will update this page and the date at the top. If the change is significant, we will also let you know before it takes effect, for example by email to the address linked to your account.

18. Contact

SIA “Limedot” (reg. No. 50203718151), Miera iela 61 k-1 - 1, Rīga, LV-1013, Latvia — hello@limedot.io — limedot.io.