Privacy Policy
Last updated 2026-07-17 · Version 1
CardCove.io ("CardCove," "we," "us," or "our") is owned and operated by Ethereal Springs LLC, a Texas entity with its principal business address at 817 S MacArthur Blvd, Ste 115 PMB 2037, Coppell, TX 75019. We respect your privacy and are committed to protecting it. This Privacy Policy (the "Policy") explains what information we collect through the CardCove.io website and related services (collectively, the "Services"), how we use and protect it, when we share it, and the choices available to you. This Policy is part of, and incorporated into, our Terms of Service. By accessing or using the Services and submitting your information, you agree to this Policy. This Policy does not apply to companies we do not own or control or to individuals we do not employ.
1. Information You Provide to Us
You can browse the Site without registering. To purchase, however, you must create an account and complete verification, and we receive and store the information you knowingly provide when you register, place an order, complete verification, or fill out any form on the Site. Depending on the feature, this may include:
- Account details (username, unique user ID, password)
- Contact information (email address, phone number)
- Basic personal information (name, country of residence, residential address, date of birth)
- Proof of identity (photo of a government-issued ID such as a driver's license or passport, and a selfie or live capture)
- Payment information (card details, bank details, billing address)
You may choose not to provide certain information, but you may then be unable to use some features of the Services — including making purchases. If you are unsure what is required, contact us.
2. Information Collected Automatically
When you visit the Site, our servers automatically record information your browser sends. This may include your device's IP address, browser type and version, operating system, language preferences, referring page, pages visited and time spent on them, searches performed, and access dates and times. We use automatically collected information to identify potential abuse, secure the platform, and compile statistical information about usage and traffic. We also record the IP address associated with registered activity and may retain server logs that include the IP address of every request to our server. Your email address is verified via a unique confirmation link; visiting that link tells us you control the address.
3. Identity Verification and Fraud Prevention
Because gift cards are a frequent target of fraud, identity verification and fraud screening are essential parts of the Services. If you decline to provide or allow processing of the data described in this section, you may be unable to complete purchases or use certain features.
KYC verification through Veriff. We use Veriff (Veriff OÜ and its affiliates), a third-party identity verification provider, to conduct Know Your Customer (KYC) verification on our behalf. Veriff gathers, processes, and stores verification data — which may include your full name, date of birth, residential address, images or short video of your government-issued ID, a corresponding selfie or live facial capture, and derived biometric identifiers used for identity matching. By proceeding with verification, you acknowledge and consent to the capture and processing of these images, videos, and biometric data strictly for identity verification and fraud prevention. You can review Veriff's privacy notice at https://www.veriff.com/privacy-notice.
Risk and device signals. We and our service providers may also analyze contact and payment details, device type, operating system, browser, IP address, and network characteristics — including signals suggesting use of a proxy, VPN, or remote connection — to assess whether a transaction, sign-up, or account activity presents elevated fraud risk. With your authorization under our Terms of Service, we may also request subscriber details from your mobile carrier and access information from credit bureaus for fraud-prevention purposes.
Limits on provider use. We share with these providers only the data necessary for them to perform fraud detection and identity verification, and they are contractually restricted from using it for any other purpose.
4. How We Use Information
We use the information we collect to:
- Create and manage user accounts
- Verify your identity and comply with legal and regulatory requirements
- Fulfill and manage orders and deliver gift cards to your account
- Process payments, refunds, and guarantee claims
- Detect and prevent fraud, chargebacks, and abuse of the platform
- Respond to customer service requests and support needs
- Send transactional emails such as order confirmations, delivery notifications, and account notices
- Run, operate, secure, and improve the Site and Services and personalize your experience
We may combine or aggregate information to better serve you and improve the Services; aggregated data that cannot identify you personally may be used even after you update or delete your information.
5. When We Share Information
We do not sell your personally identifiable information. We share information only with:
- Service providers — trusted vendors that help us operate the Site and conduct our business, including identity verification (Veriff), payment processing, hosting, and analytics providers. Service providers receive only what they need to perform their designated functions, must keep it confidential, and are not authorized to use it for their own marketing or other purposes.
- Legal and safety recipients — we may disclose information when required or permitted by law, such as to comply with anti-money laundering obligations, a subpoena, or similar legal process, or when we believe in good faith that disclosure is necessary to enforce our Terms of Service or collections rights, investigate or prevent fraud, respond to a government request, or protect our rights, property, or safety or those of others.
- Business transfers — if we undergo a business transition such as a merger, acquisition, or sale of all or a portion of our assets, your account and personal information may be among the assets transferred.
Non-personally identifiable, aggregated visitor information may be shared with other parties for marketing, advertising, or analytics purposes.
6. Cookies, Analytics, and Do Not Track
Cookies are small text files placed on your device by a web server; they cannot run programs or deliver viruses, and can only be read by servers in the domain that issued them. We use cookies for security, to keep you signed in, to associate your browser with your registered account, to save your preferences, and to compile aggregate data about site traffic and interaction so we can improve the Services. Most browsers accept cookies by default, and you can decline them in your browser settings — but some features of the Site may not function fully without them.
We may use third-party analytics tools that employ cookies, web beacons, or similar technologies to collect standard internet activity information used to compile statistical reports on user activity. The Services do not track visitors over time and across third-party websites, and therefore do not respond to browser Do Not Track signals; third-party sites you visit may follow their own tracking practices.
7. Email Communications
We send essential transactional emails (order confirmations, delivery notices, verification links, account notices) to all customers. If you subscribe to marketing emails or newsletters, we keep your email address confidential and will not disclose it except as described in this Policy or to a third-party provider used to send those emails. In compliance with the CAN-SPAM Act, our emails clearly identify the sender and how to contact us, and you may unsubscribe from marketing messages at any time via the link in the email or by contacting us. Transactional emails will continue regardless of marketing preferences.
8. Data Retention
We retain personal information for as long as your account remains active and as needed to enforce our agreements, resolve disputes, and comply with legal obligations. As a general matter, we make a good-faith effort to:
- Retain server logs containing request IP addresses no more than 90 days
- Retain IP addresses associated with registered users and their transactions no more than 5 years
- Retain KYC data as long as required to comply with legal obligations — typically up to 7 years — unless applicable law specifies otherwise
- Retain transaction records as required for tax, accounting, anti-money laundering, and dispute resolution purposes
KYC information collected through Veriff is stored securely on Veriff's platform, with retention aligned to our legal and operational needs and Veriff's own retention policies. Once an applicable retention period expires, personal information is deleted, and rights of access, erasure, rectification, and portability can no longer be exercised as to that information.
9. How We Protect Information; Data Breach
We secure the information you provide in a controlled environment protected from unauthorized access, use, and disclosure, and we maintain reasonable administrative, technical, and physical safeguards, including:
- Encrypting sensitive data (such as photo IDs and billing information) in transmission and storage
- Storing data on secure servers with restricted access
- Conducting regular reviews of our security systems
- Working with providers such as Veriff and PCI-compliant payment processors that follow stringent security practices
No transmission over the internet or wireless network can be guaranteed secure, however, and you acknowledge that the security and privacy of information exchanged with the Site cannot be absolutely guaranteed. Please also protect the security of your own device and credentials. If we become aware that Site security has been compromised or personal information has been disclosed to unrelated third parties as a result of external activity — such as a security attack or fraud — we reserve the right to take reasonably appropriate measures, including investigation, reporting, and cooperation with law enforcement. If we believe a breach creates a reasonable risk of harm to you, or where notice is required by law, we will make reasonable efforts to notify affected users by posting a notice on the Site and sending an email.
10. Your Choices and Rights
You may access and update certain account information through your account settings, and you may request deletion of certain personal information or of your account by contacting us. When information is deleted, we may retain copies as necessary to comply with the legal retention obligations described above (including KYC and transaction records).
Depending on your state of residence, you may have additional rights under state privacy laws — for example, California residents may request, once per calendar year, information about the categories and specific pieces of personal information we have collected and disclosed, and may request deletion of personal information, subject to legal exceptions. We do not sell personal information, and we will not discriminate against you for exercising your privacy rights. To exercise any right, contact us at support@cardcove.io. We will ask you to verify your identity (or an authorized representative's written authority) before responding, and we cannot fulfill requests we cannot verify.
11. Age Requirement
The Services are directed to adults. You must be 18 or older to use the Site, and we do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided personal information to us, contact us and we will delete it. Per COPPA, no one under 13 may use this Site.
12. Third-Party Links
The Services contain links to resources we do not own or control, and we are not responsible for their privacy practices. We encourage you to read the privacy statements of every resource that may collect personal information from you.
13. Changes to This Policy
We may modify this Policy at any time at our discretion. An updated version is effective immediately upon posting unless otherwise specified, and your continued use of the Services after the effective date constitutes your consent to the changes.
14. Contacting Us
If you have questions, concerns, or complaints about this Policy, or wish to exercise your rights, contact us at support@cardcove.io, or by mail at: Ethereal Springs LLC d/b/a CardCove, 817 S MacArthur Blvd, Ste 115 PMB 2037, Coppell, TX 75019. We will make every reasonable effort to honor your requests as quickly as possible and within the timeframes provided by applicable law.