Privacy Policy
PostcardPal is operated by Havenwood Holdings. Contact: ch@havenwood.holdings.
What we collect
- Account: your email address (for sign-in codes and receipts) and the name you sign cards with; optionally a return address.
- Recipients: names and mailing addresses you provide or save as nicknames. These are USPS-verified through our print vendor.
- Postcards: the message, caption, place, photo (yours or a stock photo), the rendered artwork, and the approval record (time, price, connecting client).
- Payments: handled by Stripe. We store Stripe customer and payment-method references, never card numbers.
- Technical: server logs with IP addresses and timestamps, kept briefly for security.
How we use it
To design, screen, print and mail your postcards; to charge you; to send sign-in codes and, at most once per trip, a reminder email you can turn off with one click; to prevent abuse; and to respond to support and payment disputes.
Who sees it
- Our print and mail vendor (PostGrid) receives the recipient address, the optional return address and the print file.
- Stripe processes payments. Resend delivers our emails. Vercel and Neon host the service and database. Anthropic’s API screens content and, when you don’t provide a message, drafts suggestions; your data is not used to train models.
- Your AI assistant’s provider (Meta, Anthropic, OpenAI) sees what you and it exchange, including previews, under their own policies.
Retention
Artwork and photos are deleted 60 days after a card is mailed or a draft expires; the record of what was approved (without the image) is kept for accounting and dispute purposes. Saved recipients stay until you delete them. You can delete your account and data by emailing support.
Your choices
You can disconnect PostcardPal from your assistant at any time, revoke API keys at /account, and opt out of reminder emails via the link in them.