Cardstead
ProductSolutionsPricingResources
LoginBook a walkthrough
Privacy PolicyTerms of ServiceAcceptable UseSecurity DisclosureData Requests
Data

Data Requests

Last updated: June 27, 2026

This page explains how to request access, correction, export, deletion, or account closure for information processed by Cardstead.

Where to send requests

Send privacy, data, export, correction, deletion, or account closure requests to support@cardstead.com. Include the store name, tenant name if known, requester name, requester email, relationship to the store, requested action, and enough context for us to locate the records.

Verification

We may verify identity, account ownership, tenant authority, location access, and the legal basis for the request before disclosing, exporting, correcting, deleting, or restricting information. For tenant data, we may require owner approval or direct the request to the store that controls the data.

Requests by store owners

  • Tenant data export requests may include customer records, employee records, store credit records, trade-in records, money records, reminders, calendar records, reports, audit records, settings, and billing records where available and technically supported.
  • Account closure requests may restrict user access and begin offboarding, but certain records may remain for audit, ledger, billing, legal, security, backup, dispute, and accounting reasons.
  • Deletion requests are evaluated against operational integrity requirements. Ledger, audit, billing, export, and security records may be retained where deletion would compromise accurate business history or legal compliance.

Requests by store customers or employees

If your information was entered by a store that uses Cardstead, contact that store first. The store controls its own customer, employee, trade-in, credit, and operational records. Cardstead will generally process those records based on the store's instructions unless applicable law requires a direct response.

Response expectations

We will respond within a reasonable period and in accordance with applicable law. Some requests may require additional verification, clarification, store approval, technical work, or legal review. We may deny or limit a request where allowed by law, including where records must be retained for security, fraud prevention, accounting, tax, billing, audit, legal claims, backups, or operational integrity.

Backups and residual copies

Deleted or restricted information may remain in backups, logs, archives, or disaster recovery systems for a limited period until those systems expire or are overwritten. We restrict routine access to those systems and use them for security, continuity, and recovery purposes.

Cardstead

Daily operations software for card shops.

support@cardstead.com
ProductProduct overviewSolutionsPricingResourcesAboutCustomer login
SupportContact usSecurity and dataBook a walkthroughReport a security issue
SocialFacebookDiscord
LegalPrivacyTermsAcceptable UseData Requests
© 2026 Cardstead. All rights reserved.Built for the work behind the counter.