Last updated: 16 July 2026
CardMasters ("we", "us") is an independent credit-card intelligence platform for India. This policy explains, in plain language, what personal data we handle and how — consistent with the Digital Personal Data Protection Act, 2023 (DPDP Act).
Only what you declare voluntarily during onboarding and in your profile: your approximate monthly income, your monthly spending by category, the credit cards you already hold, your city, and your employment type. We do not collect your PAN, Aadhaar, card numbers, statements, or credit report. If you contact us, we store the name, email address, topic, and message you submit so we can respond. If you create an account, Supabase Auth processes your email address and authentication information so you can sign in and sync your profile.
Your profile is stored locally in your browser. When you sign in, the profile and any self-reported card application status are also stored in our Supabase project so they can sync across devices. Supabase processes this data on our behalf. Clearing browser storage removes the local copy; the Profile page lets you permanently delete your account and cloud data.
We do not sell your data. We do not share your declared income or spends with banks, advertisers, or anyone else. Card recommendations are computed on your device against our public card knowledge base.
When you tap "Apply", we send you to the bank or an affiliate-network redirect (currently EarnKaro). Any commission we may earn is disclosed next to the recommendation before you click. Affiliate links may include a pseudonymous attribution code containing the card identifier, a shortened internal user tag, and a timestamp; they do not contain your email, income, spending profile, or card details.
We use Vercel Web Analytics to understand aggregate page visits and product usage, including sign-in method, onboarding completion, recommendation and dashboard views, alert engagement, and contact topic. When you tap an Apply button, we record the card identifier, whether a tracked partner link was used, and the affiliate network name. We do not send your email, income, spending profile, city, card holdings, or application outcome in analytics events.
If you create a password-based account, your browser checks the password against Have I Been Pwned's Pwned Passwords service before signup. The browser sends only the first five characters of a SHA-1 hash and compares the padded response locally; the full password and complete hash are never sent to Have I Been Pwned or our servers. Supabase Auth receives the password to create and authenticate the account.
Under the DPDP Act you have the right to access, correct, and erase your personal data, and to raise a grievance. You can view and correct profile information on the Profile page, remove the local copy by clearing site data, and delete your account and associated cloud data from the Profile page. For anything else, write to us.
Questions, corrections or grievances: use our contact form. We aim to acknowledge support messages within 2 business days and privacy grievances within 7 days.