privacy | a·card
privacy policy

Privacy Policy

Last updated: 20 July 2026

What we collect

Your email and account details; wallet and transaction records (amounts, merchants, timestamps, decisions); and technical logs needed to run and secure the service. We never see or store full card numbers. Those live with our issuing partners.

What we don't collect

We don't read your agent's conversations. The MCP server sends us only the API calls it makes, the same requests a human client would send. No prompts, no chat history, no model context.

How we use it

To run the service: authorize charges, route approvals, keep the ledger balanced, prevent fraud, and meet applicable financial regulations. We don't sell your data, and we don't use it for advertising.

Who we share it with

Our issuing and payment partners (to process transactions), infrastructure providers, and authorities where the law requires it. Each partner receives only what it needs.

Where it lives

Data residency follows local regulatory requirements. Transaction records are retained for five years as required by financial regulation, then deleted.

Your rights

You can access, correct, or request deletion of your personal information, and object to processing. Write to hello@a-card.cc. We respond within 30 days.

Sharing data with our Custody Partner

Because funds you deposit are held by our issuing partner under their financial services license, we share certain personal information with them as necessary to open and maintain your funds custody arrangement, including:

Identity information you provide during registration or verification, including name, contact details, government-issued ID, and proof of address.
Transaction data needed for them to fulfil their regulatory reporting and anti-money-laundering obligations.
Any information required to respond to a lawful request from a regulator or law enforcement body with authority over our Custody Partner.

Our Custody Partner processes this information under their own privacy policy and regulatory obligations. We are not responsible for their handling of your data once shared, except as set out in our data-sharing agreement with them.

Why we are not the data controller for funds-related identity checks

Where identity verification is performed by our Custody Partner as part of their own regulatory compliance program, they act as an independent controller of that data, not as our processor. Questions about how they use identity data for compliance purposes should be directed to them by email.

Contact

Information officer: hello@a-card.cc.