CardToWallet is provided by SamEarth, LLC. You do not need an account to use the app. We do not use card information for advertising, marketing profiles, or AI training, and we do not sell it.
Cards saved on your iPhone
Card names, barcode values, and images you save are stored locally on your device. Scanning and displaying a saved barcode take place on your device. Saving a card does not upload it to our signing service.
When you add a card to Apple Wallet
When you choose Add to Apple Wallet, the app sends the selected card’s name, barcode, appearance settings, and prepared artwork over an encrypted HTTPS connection to our signing service hosted on Google Cloud. The service processes this information temporarily to create and return a signed Wallet pass. Card contents are not saved in our server database or written to our application logs.
The resulting pass is added to Apple Wallet only after you confirm. Apple handles Wallet data and any related syncing under its own policies.
Service security and operational records
We use Apple App Attest to verify requests from the app and help prevent abuse. Our backend stores verification public keys, opaque Apple attestation receipts, replay-protection records, and usage counters. These records support verification and request limits; they do not contain the saved card contents.
Google Cloud may retain standard hosting, request, and audit metadata, such as IP addresses, request times, and response status. Security records may remain after a card or the app is deleted because they are separate from the locally saved cards.
Camera and photos
The camera is used when you choose to scan a card or take an artwork photo. The app uses photos you select for card artwork. Saved artwork stays with the local card and is sent to the signing service only when you choose to create a Wallet pass containing it.
Analytics and advertising
CardToWallet does not include advertising or third-party analytics SDKs. We do not track your use of cards at physical readers.
Support requests
If you email us, we receive your email address and the information you choose to send. We use it to answer your request and troubleshoot problems. Please avoid sending sensitive card details. Support correspondence is separate from the app’s card storage.
Deleting cards and backups
You can delete saved cards within CardToWallet. Removing a card from the app does not remove a pass already added to Apple Wallet; remove that pass separately in Wallet. Apple device backups and Wallet services may retain copies according to your Apple settings and Apple’s policies.
Service providers
Apple provides Wallet and App Attest. Google Cloud hosts the pass-signing service and its security database. These providers may process operational information under their own policies.
Policy updates
We will update this page if our data handling changes and revise the effective date.
Contact
For privacy questions or requests, contact SamEarth, LLC at samearth.net@gmail.com.