WiseKidCard
WiseKidCard

Last updated: March 2026

Privacy Policy

WiseKidCard ("we", "us", or "our") is committed to protecting the privacy of parents and children who use our platform. This policy explains what data we collect, how we use it, and your rights.

1. What we collect

We collect only what's necessary to provide the service:

  • Parent account information: name, email address, and hashed password
  • Children's profiles: first name and optional avatar image
  • Transaction records: amounts, categories, notes, and timestamps
  • Savings goals and allowance plan settings
  • NFC card binding information (card number and PIN hash)
  • Email verification codes (temporary, deleted after use)
  • Feedback messages submitted through the Kiosk
  • Your approximate timezone (inferred from your IP address at registration)

2. How we use your data

  • To provide and operate the WiseKidCard platform
  • To send transactional emails (verification codes, account notices)
  • To process automatic allowance payments via scheduled tasks
  • To allow parents to manage their children's financial education records

We do not use your data for advertising, profiling, or any purpose beyond operating the service.

3. Children's privacy

WiseKidCard is designed for use by parents on behalf of their children. Children's profiles are created and managed by a verified parent account. We do not knowingly collect personal information directly from children without parental consent.

Children's names and avatars are stored solely to personalise the in-app experience and are never shared with third parties.

4. Data storage and security

All data is stored on Cloudflare's infrastructure (D1 database and R2 object storage). Passwords and PINs are never stored in plain text — they are hashed using PBKDF2-SHA256 before storage.

Sessions are secured with HMAC-signed cookies and expire after 7 days. We use HTTPS for all data in transit.

5. Third-party services

We use the following third-party services:

  • Resend — for sending transactional emails. Your email address is passed to Resend solely to deliver messages you've requested.
  • Cloudflare — for hosting, database, and file storage. Data is processed under Cloudflare's data processing terms.

We do not sell, rent, or share your personal data with any other third parties.

6. Your rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and associated data
  • Withdraw consent at any time by deleting your account

To exercise any of these rights, please contact us at the address below.

7. Data retention

We retain your data for as long as your account is active. When you delete your account, all associated data — including children's profiles, transaction history, and uploaded images — is permanently removed.

8. Changes to this policy

We may update this policy from time to time. When we do, we'll update the "Last updated" date at the top of this page. Continued use of the service after changes constitutes acceptance of the updated policy.

9. Contact

If you have any questions about this policy or how we handle your data, please visit our contact page.