Privacy Policy

Last updated: August 2026

This policy covers TeamRally Cards (cards.teamrally.app) — the free group e-card tool. It is a separate product from the TeamRally workspace app, with separate data: no accounts, no organisations, and nothing here is shared into a TeamRally workspace. If you're looking for the app's policy, it's over here.

What we collect

Three kinds of people touch a card, and we hold different things for each.

  • If you create a card — your email address (that's the whole sign-in; we email a short code rather than storing a password), an optional display name, and, if you use Google sign-in, the account identifier Google returns. We never receive or store your Google password, and we don't keep a Google access token.
  • If you sign a card — the email address the creator invited you at, or an optional unverified address you enter through a shared link; the name you sign with, your message, any sticker or GIF you attach, and whether you mark your note private. The creator sees invited signers' open and signed status.
  • If a card is for you — your name, the delivery date if one is set, and timezone, and your email address if the creator chose to have us deliver it (they can also skip that and hand you the link themselves).
  • Abuse signals — a one-way hash of the IP address behind a message or a report. We can tell that two messages came from the same source; we cannot read the address back out of the hash.

Email addresses you give us for other people

When you create a card you type in other people's email addresses — the signers you invite and, optionally, the recipient. We use those addresses only to send that card's invitation, delivery notice and any recipient reply, on your instruction. We don't add them to a mailing list, we don't market to them, and we don't use them to build a profile. By entering them you're confirming it's reasonable for you to share them with us for this purpose. Anyone we email can ask us to delete their data using the contact address below, whether or not they created the card.

If you enter your own email while signing through a shared link, we use it to send a delivery notice and any reply from the recipient. That address is not verified. Private notes are available when the card is emailed directly to the recipient. A private note is shown to its author and, after email verification, to the recipient; other signers and the card creator do not see its text.

How we use it

  • To build the card, collect messages, and deliver it on the right day.
  • To send the emails the card needs: your sign-in code, signer invitations, the delivery notice, and any reply from the recipient. These are transactional — there is no newsletter to unsubscribe from because we don't send one.
  • To keep the tool usable: rate limits, profanity filtering, and abuse reports.
  • To fix things when you write to us about them.

We do not sell personal data, we do not run ads, and we do not share anything with ad networks or data brokers.

Cookies, analytics, and why there's no cookie banner

You won't see a consent pop-up here, and that's a deliberate design decision rather than an oversight — we don't set anything that requires consent.

  • Analytics is cookieless. We use Umami, which we host ourselves on our own EU infrastructure. It counts page views and referrers in aggregate. It sets no cookies, assigns no persistent visitor ID, doesn't fingerprint your browser, and never sends anything to a third party — because there is no third party; the data lands on our own server.
  • One strictly necessary cookie, and only if you choose Google sign-in: a short-lived, HttpOnly token that ensures the sign-in that comes back is the one you started. It carries no identity, it's scoped to the sign-in endpoint, and it's deleted the moment sign-in completes. Cookies this narrow are exempt from consent requirements under the ePrivacy Directive and the German TDDDG.
  • Local storage, which stays on your device. Your card draft while you're writing it, your session token once you've signed in, and whether you muted the reveal sound. None of it is transmitted anywhere by us. Clearing your browser data clears it.

Stickers and GIFs

GIF search is powered by a third-party provider. Your search terms reach that provider so it can return results, and an attached GIF is displayed from the provider's servers — which means the provider can see the IP address of anyone viewing that card, the same way any embedded image works. Text messages and stickers involve no third party.

Who else touches the data

Only the services needed to run the tool: our hosting provider, our transactional email provider (for the sign-in code, invitations, and delivery), and the GIF provider described above. Each gets only what its job needs. We may also disclose information where the law actually requires it.

How long we keep it

A delivered card, its messages and the email addresses attached to it are deleted about thirteen months after delivery. Until then it stays at its link, because a card is meant to be re-openable — that is the point of it. A little over a year, rather than exactly a year, so that a card is still there on its own anniversary and for a while after. Once the window passes, it and everything written on it are removed automatically; we do not keep a copy. Cards that were never delivered are kept while they are being made.

Sign-in codes expire shortly after they're issued. You do not have to wait for the twelve months: you can ask us to delete a card and everything attached to it at any time by emailing hello@teamrally.app from the address that created it. If you signed a card or received one, you can ask us to remove your message or your details the same way.

Who else processes this data

We use a small number of providers to run the service. Each one only ever sees what it needs to do its job, and each is bound by a data processing agreement.

  • Hetzner (Germany) — hosting and the database.
  • Cloudflare (R2, EU) — storage for uploaded images and the files a purchased digital copy produces, plus the Turnstile check that keeps bots off the create form.
  • Resend and ZeptoMail — sending the emails: sign-in codes, signer invites, delivery, and the occasional occasion nudge.
  • Creem — payments for the optional extras. Creem is the seller of record and handles the transaction; we receive confirmation that it happened, not your card details.
  • Klipy — GIF search. Your search terms reach them; the card does not.
  • Sentry — error reports, so we find out when something breaks.
  • Umami — privacy-friendly, cookie-free analytics. No cross-site tracking, no advertising profiles.
  • Google — only if you choose to sign in with a Google account.

We do not sell personal data, and we do not use it to train anything.

Our own feedback tool

The feedback, roadmap and changelog pages — and the small launcher in the corner of the home page — are FeatureWish, which runs at app.featurewish.com. Despite the different domain it is not a third party: it is another service operated by the same person named in the Impressum, so nothing is handed to anyone else. Loading it sends the usual request data — your IP address and the page you are on. It stores nothing on your device: no cookie, no local storage, nothing to consent to under § 25 TDDDG.

Your rights and where the data lives

TeamRally Cards is hosted in the European Union and operated under the GDPR. You can ask for access to your data, correction of it, a copy of it, or its deletion, and you can object to how we're using it — write to hello@teamrally.app and we'll act on it. You also have the right to complain to a data protection authority — ours is Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (HmbBfDI), and your own local authority is equally open to you. Data is encrypted in transit (TLS). No system is perfectly secure, but we don't hold much: there are no passwords here, and no card numbers — if you buy one of the optional extras, the payment is taken by Creem and we never see or store your payment details.

Children

TeamRally Cards is built for workplaces and isn't directed at children under 16.

Changes

If this policy changes materially, the "last updated" date above changes with it.

Contact

Questions, or a deletion request? Email hello@teamrally.app. The controller for this processing, with full contact details, is named in the Impressum.