Privacy Policy
This is a card company that handles family photographs and video of people's children. This page says plainly what we do with them.
Last updated: 30 August 2026
Who we are
VirAR makes printed cards that carry an augmented-reality layer. It is run by Roman Vainshtain, an independent developer based in Gdańsk, Poland — ul. Obrońców Wybrzeża 11, Gdańsk, Poland. VirAR currently operates as unregistered business activity (działalność nierejestrowana) under Polish law, a form for which no company or VAT number is issued — that is why none appears here.
One person decides what is collected and why, which under the GDPR makes that person the data controller for everything described on this page. There is no separate data-protection officer; privacy enquiries are handled directly by the data controller at the contact address below.
For anything on this page — a question, correction or deletion request — write to contact@virar.io. Your request will be reviewed directly.
What we collect
| What | When | Why |
|---|---|---|
| Photos, videos and text you put on a card | While building a card | To build the card, compile the AR scene and produce the print file |
| Your name and email | At checkout | To send the confirmation, the PDF or the shipping updates |
| Delivery address and phone | For printed orders | Passed to the print partner so the parcel can be delivered |
| The recipient's name and address | If you send a card directly to someone | Same reason — it is the delivery address for that parcel |
| Payment details | At checkout | Entered directly into Stripe. We never receive or store your card number — only whether the payment succeeded |
| Basic usage data | Only with your consent | To see which parts of the builder people get stuck in |
We do not ask for anything we do not need. There is no profile, no advertising identifier and no data bought from anyone else.
Your photos and videos
This is the part that matters most, so it gets its own section.
What we do with them
Your uploads are stored so the card can be built, so the print file can be produced, and so the AR scene can be served when someone scans the card. That is the entire list. We do not use them to train anything, and we do not sell or license them.
We do not use your photos or videos in our own materials. There is no checkbox anywhere that signs them over, and uploading a card grants nothing of the sort. If we ever wanted to show someone's card, we would write to the person who made it and ask about that specific card.
Face detection, and what it is not
When you crop a photo, our own server runs a small face-detection model to work out where the faces are, so the crop does not cut someone's head off. It returns a rectangle and nothing else. No face template, faceprint or biometric identifier is created, stored or compared against anything — this cannot recognise who is in a photo, only that a face is somewhere in it. The model runs on our server and the image is not sent to any third-party recognition service.
Who can watch the video on a finished card
Anyone holding the card. The QR code printed on it is the key, and that is the point of the product. The link is not listed, indexed or searchable, but it is not password-protected either — treat a card the way you would treat a printed photograph: whoever holds it can look at it.
Why we are allowed to
- To perform our contract with you — building your card, taking payment, getting it printed and delivered. Without this data there is no card.
- Your consent — analytics cookies. Consent can be withdrawn at any time, and withdrawing it never affects your order.
- Our legitimate interests — keeping the service secure, preventing abuse of the contact form, and fixing faults. We only rely on this where it does not override your own interests.
- Legal obligation — accounting and tax records for completed orders.
How long we keep it
| What | Kept for |
|---|---|
| An unfinished card you never ordered | 24 hours after it goes stale, then the files are deleted automatically |
| An ordered card and its AR scene | One year from the order date. We email a reminder 30 days before it lapses; if it is not renewed, the card and its files are deleted |
| Order and payment records | As long as tax and accounting law requires, then deleted |
| Contact-form messages | Until the conversation is finished and no longer needed |
These are enforced by a scheduled job, not by hand — deletion happens whether or not anyone remembers to do it.
Your rights
Under the GDPR, and equivalent rules elsewhere, you can ask us to:
- give you a copy of what we hold about you;
- correct anything wrong;
- delete it — including your uploads, before or after an order;
- restrict or object to a particular use;
- hand your data to you in a portable format;
- withdraw a consent you previously gave.
Write to contact@virar.io from the address the order was placed with, and we will act within one month. There is no charge, and we will not ask you why.
If we get it wrong, you have the right to complain to your national data-protection authority. We would rather you told us first, but that right stands either way.
Children
VirAR is for adults. We do not knowingly let anyone under 16 create an account or place an order.
Photographs and video of children, however, are a normal part of what people put on these cards — a grandchild, a first birthday. Those images are handled exactly like every other upload described above: used only to make and serve your card, never used for training or our materials, and deleted on request or on the schedule above. If you believe a child's image was uploaded by someone with no right to do so, write to us and we will remove it.
Security
Traffic is encrypted in transit. Card numbers never touch our servers — they go straight to Stripe. Access to the production database is limited to the people who maintain the service.
No system is perfect. If a breach ever affected your data in a way that posed a real risk to you, we would tell you and the relevant authority within the deadlines the law sets, rather than quietly hoping it went unnoticed.
Changes
When this page changes, the date at the top changes with it. If a change materially affects how your data is used — a new processor, a new purpose — we will say so directly rather than relying on you to re-read the page.