Create a card
The small details

Privacy Policy

This is a card company that handles family photographs and video of people's children. This page says plainly what we do with them.

Last updated: 30 August 2026

Who we are

VirAR makes printed cards that carry an augmented-reality layer. It is run by Roman Vainshtain, an independent developer based in Gdańsk, Poland — ul. Obrońców Wybrzeża 11, Gdańsk, Poland. VirAR currently operates as unregistered business activity (działalność nierejestrowana) under Polish law, a form for which no company or VAT number is issued — that is why none appears here.

One person decides what is collected and why, which under the GDPR makes that person the data controller for everything described on this page. There is no separate data-protection officer; privacy enquiries are handled directly by the data controller at the contact address below.

For anything on this page — a question, correction or deletion request — write to contact@virar.io. Your request will be reviewed directly.

What we collect

WhatWhenWhy
Photos, videos and text you put on a cardWhile building a cardTo build the card, compile the AR scene and produce the print file
Your name and emailAt checkoutTo send the confirmation, the PDF or the shipping updates
Delivery address and phoneFor printed ordersPassed to the print partner so the parcel can be delivered
The recipient's name and addressIf you send a card directly to someoneSame reason — it is the delivery address for that parcel
Payment detailsAt checkoutEntered directly into Stripe. We never receive or store your card number — only whether the payment succeeded
Basic usage dataOnly with your consentTo see which parts of the builder people get stuck in

We do not ask for anything we do not need. There is no profile, no advertising identifier and no data bought from anyone else.

Your photos and videos

This is the part that matters most, so it gets its own section.

What we do with them

Your uploads are stored so the card can be built, so the print file can be produced, and so the AR scene can be served when someone scans the card. That is the entire list. We do not use them to train anything, and we do not sell or license them.

We do not use your photos or videos in our own materials. There is no checkbox anywhere that signs them over, and uploading a card grants nothing of the sort. If we ever wanted to show someone's card, we would write to the person who made it and ask about that specific card.

Face detection, and what it is not

When you crop a photo, our own server runs a small face-detection model to work out where the faces are, so the crop does not cut someone's head off. It returns a rectangle and nothing else. No face template, faceprint or biometric identifier is created, stored or compared against anything — this cannot recognise who is in a photo, only that a face is somewhere in it. The model runs on our server and the image is not sent to any third-party recognition service.

Who can watch the video on a finished card

Anyone holding the card. The QR code printed on it is the key, and that is the point of the product. The link is not listed, indexed or searchable, but it is not password-protected either — treat a card the way you would treat a printed photograph: whoever holds it can look at it.

Why we are allowed to

  • To perform our contract with you — building your card, taking payment, getting it printed and delivered. Without this data there is no card.
  • Your consent — analytics cookies. Consent can be withdrawn at any time, and withdrawing it never affects your order.
  • Our legitimate interests — keeping the service secure, preventing abuse of the contact form, and fixing faults. We only rely on this where it does not override your own interests.
  • Legal obligation — accounting and tax records for completed orders.

Who else sees it

We use a small number of processors. Each one gets only what it needs to do its job, and none of them may use your data for their own purposes.

WhoWhat they getWhat for
SupabaseCard data, uploads, ordersDatabase and file storage
StripePayment details, order amount, emailTaking payment
ResendYour email address and the message contentSending confirmations and notifications
Prodigi / GootenThe print file, plus the delivery name and addressPrinting and shipping the physical card
Vercel / RailwayTechnical request dataHosting the site and the API
Google Analytics, Microsoft ClarityUsage data — only if you consentedUnderstanding how the builder is used

Some of these operate outside the European Economic Area, including in the United States. Where that happens, the transfer is covered by the European Commission's standard contractual clauses or an equivalent safeguard.

We do not sell personal data, and we never have. If VirAR were ever acquired, the buyer would be bound by this policy until you were told otherwise and given the chance to object.

How long we keep it

WhatKept for
An unfinished card you never ordered24 hours after it goes stale, then the files are deleted automatically
An ordered card and its AR sceneOne year from the order date. We email a reminder 30 days before it lapses; if it is not renewed, the card and its files are deleted
Order and payment recordsAs long as tax and accounting law requires, then deleted
Contact-form messagesUntil the conversation is finished and no longer needed

These are enforced by a scheduled job, not by hand — deletion happens whether or not anyone remembers to do it.

Your rights

Under the GDPR, and equivalent rules elsewhere, you can ask us to:

  • give you a copy of what we hold about you;
  • correct anything wrong;
  • delete it — including your uploads, before or after an order;
  • restrict or object to a particular use;
  • hand your data to you in a portable format;
  • withdraw a consent you previously gave.

Write to contact@virar.io from the address the order was placed with, and we will act within one month. There is no charge, and we will not ask you why.

If we get it wrong, you have the right to complain to your national data-protection authority. We would rather you told us first, but that right stands either way.

Children

VirAR is for adults. We do not knowingly let anyone under 16 create an account or place an order.

Photographs and video of children, however, are a normal part of what people put on these cards — a grandchild, a first birthday. Those images are handled exactly like every other upload described above: used only to make and serve your card, never used for training or our materials, and deleted on request or on the schedule above. If you believe a child's image was uploaded by someone with no right to do so, write to us and we will remove it.

Security

Traffic is encrypted in transit. Card numbers never touch our servers — they go straight to Stripe. Access to the production database is limited to the people who maintain the service.

No system is perfect. If a breach ever affected your data in a way that posed a real risk to you, we would tell you and the relevant authority within the deadlines the law sets, rather than quietly hoping it went unnoticed.

Changes

When this page changes, the date at the top changes with it. If a change materially affects how your data is used — a new processor, a new purpose — we will say so directly rather than relying on you to re-read the page.