Legal

Privacy Policy

This policy explains what personal data VarnaCard processes when you use VarnaCard, for what purposes, who else receives it, how long it is kept, and how to exercise your rights over it.

Last updated 4 September 2026

Scope and controller

VarnaCard is operated by VarnaCard, a company registered in the Islamic Republic of Iran (“VarnaCard”, “we”, “us”). VarnaCard determines the purposes and the means of the processing described in this policy.

This policy applies to the VarnaCard website, the host dashboard, the card pages opened by guests, and the memory-collection pages. It applies both to hosts who hold an account and to guests who open a card.

It does not apply to processing a host carries out outside VarnaCard, nor to any third-party website reached from a link placed within a card.

The service is currently offered to users in Iran. Requests and questions under this policy may be made on +98 902 522 8032.

Categories of personal data

We collect the categories set out below, and only to the extent necessary for the purposes stated in “Purposes and proportionality”.

  • Account data — the mobile number or email address used to sign in, and the one-time codes issued to it.
  • Profile data — the name, language and display preferences you enter.
  • Card content — the names, dates, locations, text, images and audio you add to a card.
  • Guest data — the first and last name a guest gives when they reply to a card, and any guest names you add by hand.
  • Response data — replies to invitations, messages sent by guests, and the photographs and videos uploaded to the Memory Inbox.
  • Transaction data — the items purchased, the amount, the date, the outcome and the reference returned by the payment gateway. Card numbers are not received.
  • Technical data — pages requested on the public site, device and browser characteristics, and the diagnostic reports produced when the service fails.

Sensitive personal data

Article 58 of the Electronic Commerce Act prohibits the storage, processing or distribution of personal data revealing ethnic or racial origin, ideological or religious belief, moral characteristics, or physical, mental or sexual condition, without the express consent of the person concerned.

VarnaCard does not request data of this kind and no field in the service is designed to hold it. Where content you upload incidentally reveals such data, we process that content solely in order to display it to you and to the recipients you designate.

Do not enter medical information, identity-document numbers or banking details into card content, guest notes or support messages. Those fields are not intended for them and are not treated as sensitive-data stores.

Purposes and proportionality

Article 59 of the Electronic Commerce Act requires that personal data be relevant to the purpose of processing and be collected and used only to the necessary and appropriate extent. We process the categories above for the following purposes only.

  • To open your account, authenticate you, and maintain your signed-in session.
  • To build, store, render and deliver the cards you create.
  • To open a card for the guests who receive its link, and to record the name and the response a guest gives through it.
  • To receive and store the photographs and videos guests send to your Memory Inbox.
  • To process payments and to keep the accounting record of them.
  • To answer your support requests.
  • To maintain the security and availability of the service, including rate limiting, prevention of abuse and diagnosis of faults.

Guests and the responsibility of the host

A guest’s name is given by the guest when they reply, or entered by the host. VarnaCard processes it on the host’s instruction and for the purposes stated above only.

By adding a person by hand, the host confirms that it has a legitimate reason to include that person in the event concerned. Responsibility for the lawfulness of that rests with the host.

Guests are not added to any marketing list, are not sent any message by VarnaCard, and are not disclosed to other hosts.

A guest who wishes their data to be corrected or erased may contact the host directly or reach us on +98 902 522 8032. We will identify the host who entered the record, act on that host’s instruction, and inform the guest of the outcome.

Sharing a card

A card has one link, which the host shares wherever they already talk to their guests. VarnaCard does not send the invitation. Anyone holding the link can open the card and reply under a name they give.

For that reason, card links are excluded from our usage statistics and from our diagnostic reports. The exclusion is implemented in the software itself and does not rely on policy alone.

The only text message VarnaCard sends is the one-time code a host receives when signing in with a mobile number. For that purpose the number and the code are transmitted to Kavenegar, an SMS provider established in Iran. Kavenegar receives only what is required to deliver that message and is not permitted to use it for any other purpose.

Payments

Card payments are processed through Sep, the payment gateway of Saman Bank. Card details are entered on the gateway’s own page.

VarnaCard does not receive, display or store card numbers, CVV2 values, expiry dates or internet-banking passwords, and no part of the service requests them. Any message that does request them does not originate from us.

For each transaction we retain the amount, the date, the outcome and the gateway reference, together with the account to which it relates.

The Memory Inbox

Photographs and videos uploaded by guests after an event are stored in an inbox accessible only to the host of the card concerned.

This content is not published, is not disclosed to other hosts, is not used to promote VarnaCard, and is not used to train any model.

The retention period depends on the plan purchased and on the host’s instruction. A host may ask support to erase the contents of their Memory Inbox at any time. Only the host of a card may make that request.

AI image generation and transfer abroad

If you use the AI image feature, the instruction you enter and any source image you supply are transmitted to Google and processed by its Gemini image model. Google carries out that processing outside Iran.

This is the only processing described in this policy that takes place outside Iran, and it occurs only when you use that feature.

Guest data, contact details and Memory Inbox content are never transmitted to Google or to any other provider of artificial-intelligence services. Every other part of the service operates without this feature.

Disclosure to third parties

We do not sell, rent or trade personal data and we do not use it for advertising. It is disclosed only to the recipients listed below and only to the extent each of them requires.

Each recipient processes the data on our instruction and under contract, except where it acts as an independent controller in discharge of its own legal obligations.

  • Kavenegar — delivery of one-time sign-in codes by SMS.
  • Sep, the payment gateway of Saman Bank — processing of card payments.
  • Google — the instruction and any source image submitted to the AI image feature.
  • ParsPack — hosting of our servers and storage of the database, uploaded files and diagnostic reports.
  • A competent Iranian authority, where disclosure is required by a specific, lawful and binding order.

Retention

Account data, card content, guest data and response data are retained for as long as the account exists. Guest data is retained so that it remains available to the host for subsequent events.

Memory Inbox content is retained in accordance with the plan purchased and the host’s instruction.

Transaction records are retained for the period required by the applicable accounting and tax rules, irrespective of any other erasure.

Diagnostic reports are retained for a limited period and are then deleted. Where personal data is no longer necessary for the purpose for which it was collected, it is erased.

Access, correction and erasure

You may ask us to confirm what personal data we hold about you, to correct it, or to erase it. Requests are made on +98 902 522 8032.

Account closure and erasure are carried out by our support team after verification that the request comes from the account holder. The service does not provide self-service deletion.

We respond to requests without undue delay. Where a request cannot be met in full — because a record must be retained under accounting rules, or because the data forms part of another host’s card — we will say so and state the reason.

Erasure of an account removes the cards, guest lists and responses associated with it, subject to the retention rules above.

Cookies and local storage

VarnaCard uses a small number of strictly necessary cookies and equivalent browser storage: one to keep you signed in, one to record your chosen language, and one to record your light or dark theme preference.

There are no advertising cookies and no third-party tracking cookies.

A guest link keeps one further cookie on the device that opens it, so that a guest who has given their name is recognised when they come back and does not have to give it again. It also records a visit for a day, so that the same phone opening a card twice is counted once. Neither identifies anyone to us beyond the name the guest typed, and neither is readable by the card.

Usage statistics are collected by an analytics service that we host on our own infrastructure, using a cookie of our own so that a returning visit is not counted as a new one. It does not follow individuals between websites, and nothing it records is shared with anyone else. Pages carrying a guest link or a memory-collection token are excluded from it.

Security and location of storage

Our servers and stored data are located in Iran and are hosted by ParsPack.

Access to production data is restricted to personnel who require it, data in transit is encrypted, uploaded files are served through links that expire, and guest links and collection tokens are removed from diagnostic reports before those reports are recorded.

No system is immune from compromise. In the event of a breach affecting your personal data, we will notify the account holders concerned and state what data was involved and what steps have been taken.

You are responsible for the security of your device and of the mailbox or SIM card used to receive one-time codes.

Changes to this policy

We may amend this policy. The date shown at the head of this page records the last revision.

Where an amendment materially changes the purposes of processing or the recipients of personal data, account holders will be notified before it takes effect.

If the business is transferred to another owner, this policy continues to apply to personal data transferred with it until it is replaced by a policy notified to you in advance.

Continued use of the service after an amendment has taken effect constitutes acceptance of the amended policy.