Heart Notes ("we", "our", or "us") is operated by Dioverse Technologies, Lagos, Nigeria. This Privacy Policy explains what personal information we collect when you use our platform, how we use it, and your rights. By using Heart Notes, you agree to the practices described here.
Heart Notes does not require you to create an account or log in. You simply visit the platform, create your card, pay, and receive your shareable card link. No passwords or user profiles are stored.
1. Information We Collect
1.1 Content You Provide During Card Creation
When you create a digital greeting card, we collect the content you enter directly on the platform:
- Text messages, dedications, and captions you write into your card
- Photos and images you upload to personalise your card
- Your email address — collected at checkout so we can send you the receipt and your card link
We do not collect your name unless you choose to include it in your card message. We do not create user profiles or link your activity to a persistent account.
1.2 Payment Information
All payments are processed securely by Paystack, a third-party payment provider. We do not store your card number, CVV, or any payment credentials on our servers. We only receive a transaction reference and a payment confirmation status from Paystack.
1.3 Technical Information
We may automatically collect limited technical data when you visit our platform, including:
- IP address and approximate location (country/city level)
- Browser type and device information
- Pages visited and time spent on the platform
- Error or crash data (used only for fixing technical issues)
2. How We Use Your Information
We use the information we collect solely to:
- Build, store, and generate your digital greeting card
- Process your payment and send you a transaction receipt via email
- Deliver your unique shareable card link to your email address
- Store your uploaded card images securely (via Cloudinary)
- Improve platform performance and resolve technical issues
- Respond to support requests if you contact us
- Comply with our legal obligations under Nigerian law
We do not sell your personal data. We do not use your data for advertising or share it with third parties for their own marketing purposes.
3. Third-Party Services We Use
Heart Notes relies on the following trusted third-party providers to operate. Each is bound by their own privacy policies and applicable data protection standards:
- Render — web hosting provider (servers in the United States)
- MongoDB Atlas — database where card content and transaction references are stored
- Cloudinary — stores and serves your uploaded card images
- Paystack — processes all payments. Governed by Paystack's Privacy Policy
- Brevo (formerly Sendinblue) — sends transactional emails (receipts and card delivery links)
By using Heart Notes, you acknowledge that your data may be processed in countries outside Nigeria (including the United States), where adequate data protection standards are maintained by these providers.
4. Data Retention
We retain your data as follows:
- Card content (text and images) is retained for 12 months after the card is created, after which it may be archived or permanently deleted
- Email addresses collected at checkout are retained only as long as needed to deliver your card and provide receipts
- Payment transaction references are retained for a minimum of 5 years in line with Nigerian financial regulations
You may request deletion of your card data at any time by contacting us. We will process deletion requests within 30 days, except where we are legally required to retain the data.
5. Cookies
Heart Notes uses only essential session cookies necessary for the platform to function — for example, to maintain your card creation progress within a single visit. We do not use third-party advertising cookies or behavioural tracking cookies. If we introduce analytics tools in future, this policy will be updated accordingly.
6. Children's Privacy
Heart Notes is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has submitted personal data to us, please contact us and we will delete it promptly.
7. Your Rights (NDPR & GDPR)
Depending on your location, you may have the following rights under the Nigerian Data Protection Regulation (NDPR) and other applicable laws:
- Access — request a copy of the data we hold that relates to you
- Correction — request that inaccurate data be corrected
- Deletion — request that your card data be permanently deleted
- Portability — receive your data in a readable format
- Objection — object to how we process your data
To exercise any of these rights, email: support@myheartnotes.com. We will respond within 30 days.
8. Security
We take reasonable technical and organisational steps to protect your data, including HTTPS encryption, secure cloud storage (MongoDB Atlas, Cloudinary), and restricted access controls on our systems. However, no online system is 100% secure. We encourage you to avoid sharing your card link with unintended recipients.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date at the top of this page. Continued use of Heart Notes after changes are posted constitutes your acceptance of the updated policy.
10. Contact Us
For any questions or requests regarding this Privacy Policy:
Heart Notes / Dioverse Technologies
Lagos, Nigeria
Email: support@myheartnotes.com
Website: https://myheartnotes.onrender.com