Last updated: 8 July 2026. This policy explains what we collect, why we collect it, and the choices you have.
cardtory (“we”, “us”, “our”) provides a cloud-based stock movement and audit platform (“the Service”) accessible through this website. This policy applies to visitors of this website and to registered users of the Service.
Account information. When you register we collect your name, email address, company name and a password (stored only as a secure hash, we can never see your password).
Business data you enter. Products, stock movements, warehouse names, supplier names, uploaded images and documents. This data belongs to you. We process it solely to provide the Service.
Billing information. Payments are processed by Paystack. We never see or store your full card number, CVV or bank credentials. We keep only payment references, amounts, dates and subscription status for accounting and support.
Technical information. Standard server logs (IP address, browser type, pages visited) used for security and to keep the Service running reliably.
Contact messages. If you use our contact form we keep your name, email and message so we can reply.
We use your information to: provide and secure the Service; process subscription payments and send billing notifications (payment confirmations, renewal reminders, expiry notices); respond to support requests; detect fraud and abuse; and comply with legal obligations. We do not sell your personal data, and we do not use your business data for advertising.
We process your data to perform our contract with you (providing the Service), to meet legal obligations (tax and accounting records), and on the basis of legitimate interest (security, service improvement). Where consent is required, for example optional marketing emails, we ask for it separately and you may withdraw it at any time.
The Service is multi-tenant: every company account is logically isolated. Your products, movements, reports and users are never visible to any other company, and every request is verified against your company membership before data is returned.
We share data only with the service providers needed to run the platform: our hosting provider (website and database hosting), Paystack (payment processing, see the Paystack privacy policy), and our email delivery provider (transactional emails). Each processor receives only what it needs. We may disclose information if required by law or to protect our legal rights.
Your business data is retained for as long as your account exists. If your subscription expires, your data is preserved so you can reactivate. You may request permanent deletion of your account and all associated data at any time by contacting us; we will complete deletion within 30 days, except for payment records we must retain by law.
Subject to applicable law, including the Nigeria Data Protection Act (NDPA) and, where applicable, the GDPR, you have the right to access, correct, export and delete your personal data, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority. You can export your business data yourself at any time from Settings → Backup.
We protect your data with encrypted connections (HTTPS), hashed passwords, role-based access controls, signed payment webhooks and audit logs of administrative actions. No system is perfectly secure, so we encourage strong, unique passwords for all users.
We use strictly necessary cookies to keep you logged in and to secure forms. We do not use advertising cookies. If we add analytics in the future, this policy will be updated first.
The Service is intended for businesses and is not directed at children under 18. We do not knowingly collect data from children.
When we make material changes, we will update the date at the top of this page and, for significant changes, notify account owners by email.
Questions or requests regarding your data: onifadeazeez1@gmail.com, or use our contact page.