Privacy Policy
Last updated: 26 August 2026
FamCard ("we", "us", "our") is a shared credit-card ledger for families in India, South Africa, and Nigeria. This policy explains what personal data we collect, why, who we share it with, and the rights you have over it under India's Digital Personal Data Protection Act 2023 ("DPDP"), South Africa's Protection of Personal Information Act ("POPIA"), and Nigeria's Data Protection Act 2023 ("NDPA").
1. What FamCard is
FamCard is a ledger only. We never move money, never connect to your bank, and never see or store your full card number, CVV, or expiry date — only a nickname and the last 4 digits, purely for your own identification. FamCard cannot make payments, cannot access your bank or card account, and is not a financial institution.
2. What we collect
We collect only what's needed to run the shared ledger:
- Account information: your name, email address, and (if you sign up with a password instead of Google) a securely hashed password. If you use "Sign in with Google", we receive your Google account's email, name, and a unique identifier — never your Google password.
- Family and card information: the families you belong to, your role in them, and — for cards you add — a nickname, the last 4 digits, credit limit, currency, and statement date.
- Spend and repayment records: amounts, dates, merchant notes, and repayment method labels you or other family members enter, since this is the core of a shared ledger.
- Receipt and proof photos, if you choose to attach one to a spend or repayment.
- A push notification token, so we can notify you about activity on your family's ledger.
We deliberately do not collect: your full card number, CVV, or expiry date; advertising identifiers; or your date of birth or government ID.
We use two lightweight tools to keep FamCard reliable, detailed further in section 4: Sentry, which reports app crashes and errors (from the mobile app, admin dashboard, and marketing website) so we can fix them; and Cloudflare Web Analytics, a cookie-less, aggregate visit-counting tool on our marketing website and admin dashboard. Neither is used for advertising, and we do not sell or share this data with advertisers.
3. Why we collect it, and our legal basis
Every piece of data above exists solely to make the shared ledger work — logging a spend, tracking a balance, confirming a repayment, or notifying you about activity. We process your data on the basis of your consent when you create an account, and because it's necessary to provide the service you've asked for (fulfilling our contract with you).
4. Who we share it with
We use a small number of service providers ("processors") to run FamCard. None of them are permitted to use your data for their own purposes.
- Cloudflare — hosts our application and database. This is where your account, family, and ledger data primarily lives.
- DigitalOcean Spaces (Amsterdam, Netherlands) — stores receipt and proof photos you upload, via short-lived (5-minute) private links. Photo bytes never pass through our own servers.
- Brevo — sends transactional emails (e.g. a welcome email at signup). We do not send marketing email through this or any channel today.
- Google — verifies your identity if you choose "Sign in with Google". We only ever receive your verified email, name, and account identifier from Google — never your password.
- Expo — delivers push notifications to your device using your push token.
- Sentry — receives crash and error reports from our platform(s), so we can diagnose and fix bugs. This can include device/browser type, app version, and the technical detail of the error itself, but not your ledger data.
- Cloudflare Web Analytics — counts visits to our platform(s). It's cookie-less and doesn't fingerprint or individually identify visitors — we only see aggregate traffic numbers, not who you are.
We do not sell your personal data, and we do not share it with advertisers.
5. Cross-border data transfers
Because FamCard runs on global cloud infrastructure, your data may be processed outside the country you live in — most notably, receipt and proof photos are stored on servers in the European Union (Amsterdam). If you are in India, South Africa, or Nigeria, this means your data crosses borders as part of normal operation. We rely on our processors' own data-protection safeguards for these transfers; if you have questions about a specific transfer, contact us using the details in section 10.
6. How long we keep your data
We keep your data for as long as your account is active. If you delete your account (see section 8), we permanently remove your identifying information — email, password, Google identity, display name, and photo — within 30 days. Because FamCard is a shared ledger, spends and repayments you were part of remain visible to the other family members you shared them with (so their own balances stay accurate), but are shown as coming from a "Deleted User" with no way to trace them back to you.
7. Your rights
Depending on where you live, you have some or all of the following rights over your personal data:
- India (DPDP Act 2023): the right to access a summary of your personal data and the processing of it, the right to correction and erasure, and the right to grievance redressal.
- South Africa (POPIA): the right to access the personal information we hold about you, to request correction or deletion, to object to processing, and to complain to the Information Regulator.
- Nigeria (NDPA): the right to access, correct, and request deletion of your data, and to lodge a complaint with the Nigeria Data Protection Commission.
You can delete your account and erase your personal data at any time from Settings in the app — no need to email us. For any other request (access, correction, or a question about your data), contact us using the details in section 10 and we'll respond within a reasonable time, and in any case within any statutory deadline that applies to you.
8. Deleting your account
Open the FamCard app, go to Settings, and choose "Delete my account". This is self-serve and takes effect immediately — no support request needed. See section 6 for what happens to shared ledger records afterward. If you currently own a card other family members use, you'll need to contact us first so we can help transfer it, since deleting your account would otherwise leave that card's repayments impossible for anyone to confirm.
No longer have the app installed? Visit famcard.app/delete-account for a way to request deletion without it.
9. Children's privacy
FamCard is a family app, and its parental control features (spend limits and approval-required spending, set up by the adult who owns a card) are specifically designed for a parent or guardian to supervise a minor family member's spending on a shared card. A minor may use FamCard only as part of a family account set up and supervised by a parent or legal guardian, who remains responsible for that family's account and for the information the minor's activity generates on the ledger. We do not knowingly collect personal data from a minor outside of this family and parental-supervision context. If you believe a minor is using FamCard outside of a parent or guardian's supervision, contact us and we will investigate and remove the account if appropriate.
10. Security
Passwords are never stored in plain text — we use industry-standard PBKDF2 hashing. Sign-in sessions use signed, short-lived tokens. Receipt and proof photos are stored privately and only ever accessible via time-limited links. All traffic to and from FamCard is encrypted in transit.
11. Changes to this policy
If we make material changes to this policy, we'll update the "Last updated" date above and, where required by law, notify you directly.
12. Contact us
For any privacy question or request — including as the contact point for DPDP grievance redressal, POPIA Information Officer inquiries, and NDPA data protection inquiries — email famcard@onlinesh.org.