Privacy notice
Last updated 14 September 2026. Cards.pad has no accounts and sets no cookies. This page explains what it processes anyway, and why.
- 1. Controller
- 2. Wallet addresses and transactions
- 3. What the site processes
- 4. Storage in your browser
- 5. Service providers
- 6. Retention
- 7. Your rights
- 8. Changes
1. Controller
The controller under the General Data Protection Regulation (GDPR) is the operator of Cards.pad. There is no contact form on this site; the controller is reached by email at runnexadam2545@gmail.com, the same address named for legal notices in the terms.
2. Wallet addresses and transactions
When you connect MetaMask, the site sees your wallet address and the chain it is on. When you launch or trade a coin, the transaction, your address, the amounts and the coin data you entered are written to Robinhood Chain by your wallet. Chain data is public by design, replicated by every node, and cannot be changed or deleted by Cards.pad or by anyone else.
Cards.pad stores in its own database the launches prepared through the site (transaction hash, launcher address, coin name, symbol, description, image link, the chosen card and a snapshot of it) and the market data it reads about each coin (price, market cap, holders, volume). It also reads the public launch events of the Pons factory to list coins that carry its card marker. Legal basis: Article 6(1)(b) GDPR (performing the service you asked for: showing and confirming your launch) and Article 6(1)(f) GDPR (the legitimate interest in keeping an accurate public listing of card coins).
3. What the site processes
- Server logs. The hosting provider records the IP address, time, requested page, browser and referrer of each request for security and error diagnosis, for a short period. Legal basis: Article 6(1)(f) GDPR.
- Search and page views. Card searches and page requests are handled by the site's own API routes and are not tied to a wallet or profile. No analytics service is loaded.
- Wallet connection. Your address is used in the browser to prepare transactions and to filter “my launches”. It is sent to the site's server only when you record a launch or open your own launches page.
- Optional fields. Links you enter on the launch form (X, Telegram) are written on chain by your transaction and shown on the coin page. Enter only what you want to be public forever.
- Card requests. The request page sends nothing and stores nothing; what you type there stays in your browser until you post it yourself on X, under X's own privacy notice.
4. Storage in your browser
Cards.pad sets no cookies. Your browser keeps two small local settings: the theme preference, and the flag your wallet library uses to reconnect MetaMask on your next visit. Both stay on your device, are never sent to a server, and can be cleared through your browser at any time. MetaMask itself is separate software with its own privacy notice.
5. Service providers
Cards.pad runs on infrastructure from the following providers, each bound by a data processing agreement or acting as an independent public service:
- Vercel Inc. (hosting and server logs, edge locations in the EU and worldwide).
- Supabase Inc. (database and image storage, region eu-central-1 in Frankfurt).
- The public Robinhood Chain RPC endpoint and Blockscout explorer, which receive read requests with your IP address when the site or your wallet reads chain data.
- Public market data services (Dexscreener) queried by the server, not by your browser, for pool-phase coins.
- The public card databases named on each card page are queried by the server during imports only; your browser never contacts them.
Where a provider processes data outside the European Economic Area, the transfer rests on the EU standard contractual clauses or an adequacy decision.
6. Retention
- Server logs: deleted by the hosting provider after a short period (normally a few days to a few weeks).
- Launch and market rows: kept as long as the coin exists on chain and the listing is offered, because they mirror public chain data.
- Card catalogue: kept and refreshed as long as the site runs; individual cards are hidden on request through the takedown process.
7. Your rights
Under the GDPR you have the right to access the personal data held about you, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable format, and to lodge a complaint with the supervisory authority competent for you or for the operator. Because chain data cannot be erased, requests concerning it can only be met by removing the data from what the site displays. Use the channel in section 1.
8. Changes
This notice is updated when the site changes what it processes; the date at the top tells you when. The terms of use and how it works describe the service itself.