Back to Home
Last updated: 1 September 2026
This Policy explains how CARDFORNIA PTE. LTD. handles personal data when you access our website, dashboard, APIs, cards and related services.
CARDFORNIA PTE. LTD. (UEN: 202625775N) (“Cardfornia”, “we”, “us”, “our”), a company incorporated in Singapore with registered address at 192 WATERLOO STREET #06-08 SKYLINE SINGAPORE (187966), is responsible for the personal data described in this Privacy Policy.
This Policy explains how we handle personal data when you access our website, dashboard, APIs, cards and related services (collectively, the “Services”).
Data Protection Officer. We have appointed a Data Protection Officer as required under the Personal Data Protection Act 2012 (Singapore). You may contact them at dpo@cardfornia.com or by post at the address above, marked for the attention of the Data Protection Officer.
Our Services are provided to business customers. Personal data reaches us in two ways, and our role differs in each case.
Where you are a business customer (“Client”). We act as controller of the personal data of your directors, beneficial owners, administrators and authorised contacts. We decide how that data is used, principally to verify your business, meet our legal and partner compliance obligations, and provide the Services to you.
Where you are a cardholder. Your employer or the entity that nominated you (the “Client”) provides your data to us so that a card can be issued to you.
If you are a cardholder and want to know why you were given a card, what your spending is used for internally, or how long your employer keeps its own records, those questions are for the Client, not for us.
Cards and funds. Cards are issued by licensed issuing institutions, and funds are held and processed by licensed partner institutions (“Partners”). Those institutions handle personal data for their own regulatory purposes and act as controllers in their own right. Their handling of your data is governed by their own privacy notices.
Where the EU or UK GDPR applies to our processing, the legal bases are as set out below. Under Singapore’s PDPA, we rely on consent or on an applicable exception, including compliance with legal requirements and legitimate interests.
| Purpose | Legal basis (GDPR) |
|---|---|
| Onboarding, KYB and KYC verification | Legal obligation; performance of a contract |
| Sanctions, PEP and adverse media screening | Legal obligation; substantial public interest |
| Blockchain analytics screening of funding | Legal obligation; legitimate interests (financial crime prevention) |
| Card issuance and management | Performance of a contract; processing on the Client’s instructions |
| Transaction processing, settlement and disputes | Performance of a contract; legal obligation |
| Transaction monitoring and fraud prevention | Legal obligation; legitimate interests (protecting the Services and users) |
| Regulatory reporting and responding to authorities | Legal obligation |
| Meeting Partner and issuing institution compliance requirements | Legal obligation; legitimate interests |
| Customer support and dispute resolution | Performance of a contract; legitimate interests |
| Service security, availability and improvement | Legitimate interests |
| Marketing communications to business contacts | Consent, or legitimate interests where permitted |
| Corporate transactions (merger, acquisition, restructuring) | Legitimate interests |
Service communications. We send communications about your account, security, service changes and transactions. These are necessary to provide the Services and you cannot opt out of them while you use the Services.
Marketing. You can opt out at any time by using the unsubscribe link or by contacting us at marketing@cardfornia.com. Opting out of marketing does not stop service communications.
Automated processing. We use automated systems to screen funding, monitor transactions and detect fraud. These systems may automatically decline a transaction, block a card or flag an account for review. Decisions that produce significant effects, such as declining onboarding or suspending an account, are reviewed by a person before they become final. If you believe an automated decision has affected you unfairly, contact us at support@cardfornia.com.
Cardfornia is based in Singapore. Our Partners, issuing institutions, card networks and service providers are located in a number of jurisdictions, and personal data will be transferred outside Singapore and outside your own country.
Where we transfer personal data internationally, we take steps to ensure it receives a standard of protection comparable to that required under the PDPA, and where the EU or UK GDPR applies, we rely on an appropriate transfer mechanism such as Standard Contractual Clauses or a finding of adequacy.
You may request information about the safeguards applied to a specific transfer by contacting our Data Protection Officer.
| Data | Retention period |
|---|---|
| KYB and KYC records, identity documents | 5 years after the end of the relationship, as required by anti-money laundering law |
| Transaction records | 5 years from the transaction date |
| Sanctions and screening records | 5 years from the date of screening |
| Suspicious activity records and related reports | 5 years, or longer where required |
| Support correspondence and dispute records | 3 years after resolution |
| Website usage and security logs | 12 months |
| Marketing preferences | Until you opt out, plus a record of the opt-out |
Where a legal claim, investigation or regulatory request is pending, we retain the relevant data until it is resolved.
Retention periods that arise from our Partners’ or issuing institutions’ own obligations are set by those institutions and may differ.
We maintain administrative, technical and physical safeguards appropriate to the sensitivity of the data, including access controls, encryption of data in transit and at rest, logging and monitoring, staff access on a need-to-know basis, and vendor security assessments.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You also have a role: keep credentials confidential, do not share card details, and notify us immediately at support@cardfornia.com if you become aware of unauthorised access.
Depending on the law that applies to you, you may have the right to:
Please note that we will often be unable to erase or stop processing data that we are legally required to retain, particularly KYC and transaction records held under anti-money laundering law. Where we cannot meet a request in full, we will tell you why.
How to exercise your rights. Contact our Data Protection Officer at dpo@cardfornia.com. We will respond within 30 days, or tell you if we need longer. We may need to verify your identity first.
If you are a cardholder, requests relating to data we process on your employer’s instructions should be directed to your employer in the first instance. We will forward such requests to the Client and assist them in responding.
Complaints. In Singapore, you may complain to the Personal Data Protection Commission (www.pdpc.gov.sg). If you are in the EEA or UK, you may complain to your local supervisory authority.
The Services are provided to businesses and are not directed at anyone under 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we hold such data, we will delete it and close any associated account. If you believe a person under 18 is using the Services, contact us at marketing@cardfornia.com.
The Services may contain links to sites we do not operate, including merchant and Partner sites. We are not responsible for their content or privacy practices, and we recommend reviewing their policies.
We may update this Policy. We will post the updated version on this page and update the “Last updated” date.
Where changes are material, we will give notice by email or by prominent notice on the Services at least 30 days before they take effect, unless a shorter period is required by law.
© 2026 Cardfornia Pte. Ltd. All rights reserved