Terms of Service
Last updated: 24 August 2026
This English text is a translation provided for convenience only. Only the Portuguese version is binding and it prevails in the event of any discrepancy: read the Portuguese version.
1. Who these terms are for
These Terms of Service (the “Terms”) govern the use of Cardim (the “Service”) by businesses that create an account to manage bookings (the “Merchant”, “you”). They do not create any direct contractual relationship between Cardim and the Merchant’s customers — a customer who makes a booking through a Merchant’s page is contracting with that Merchant for the service they have booked (a haircut, a table, an appointment), and not with Cardim. See our Privacy Policy to find out how we process the personal data of Merchants and of their customers.
2. The Service
Cardim provides Merchants with a public booking page, an admin dashboard for managing services, staff, opening hours and bookings, automated confirmation and reminder emails and, optionally, two-way synchronisation with Google Calendar and/or with the Outlook/Office 365 calendar. By creating an account, you accept these Terms. If you do not agree with them, do not use the Service.
3. Your account
You must give true information about your business when creating the account and keep your access credentials confidential. You are responsible for all activity that takes place in your account, including bookings created or cancelled through it. Please tell us promptly if you believe your account has been compromised.
4. Acceptable use
You undertake not to use the Service to:
- run an illegal business, or accept bookings for any unlawful activity;
- send unsolicited marketing messages to customers who have made bookings with you, beyond what is reasonably necessary to confirm, send a reminder about or follow up that customer’s booking;
- attempt to disrupt or overload the Service, or to gain unauthorised access to the Service, or to another Merchant’s account or data; or
- collect from your customers, through the booking form (for example, in the optional notes field), more personal data than is necessary actually to provide the service they have booked.
5. Your customers’ data
When someone makes a booking through your public page, they give you (the Merchant) their name, their telephone number and their email address and, optionally, a free-text note. Under data protection law (including the UK and EU GDPR), you are the data controller of that information — it is you who decides why it is collected and what it is used for (running your business, contacting that customer about the booking). Cardim acts as your data processor: we store and process that data solely in order to provide you with the Service, in accordance with our Privacy Policy. It is your responsibility to have a legal basis for collecting and using your customers’ data, and to respond to requests to exercise rights that they address to you directly.
In that capacity, and for the purposes of Article 28(3) of the GDPR, Cardim gives you the following undertakings:
- we process your customers’ data only in accordance with your instructions, which are given through normal use of the Service, unless the law requires us to do otherwise — in which case we will inform you, if the law allows it;
- anyone who has access to that data is bound by a duty of confidentiality;
- we apply appropriate technical and organisational measures: encrypted connections, passwords stored only as hashes, calendar tokens encrypted at rest, rate limits on the public forms, and separation of each Merchant’s data at the point of access;
- we use sub-processors — currently, the providers listed in section 5 of the Privacy Policy. You are taken to give general authorisation for that use; we will give you at least 30 days’ notice before adding or replacing any of them, and you may object by terminating the contract at no cost;
- we assist you, with the means available to us, in responding to the requests your customers address to you under Articles 15 to 22 — the product includes export and deletion of a customer’s data;
- we assist you in complying with Articles 32 to 36 and, if we become aware of a data breach affecting you, we will notify you without undue delay and, wherever possible, within 48 hours of the moment we became aware of it, with the information available to us, so that you can meet the 72-hour deadline that falls to you;
- at the end of the contract, we delete your customers’ data or return it, at your choice, save where we are under a legal obligation to retain it; and
- we make available to you the information necessary to demonstrate compliance with these obligations and we allow audits, at most once per calendar year, on 30 days’ notice — or at any time, if a supervisory authority so requires.
One exception, stated plainly because point (a) on its own would hide it: in order to calculate what you pay us, we count your bookings — date, time, status and number of people, with no identification of who made the booking. That processing is carried out on our own account and not on your instructions, and in it we are the data controller. It is described in sections 3 and 4 of the Privacy Policy.
6. Costs
Cardim is free until 1 February 2027 and we do not ask for a card to get started. From that date, the price is the same for every Merchant, whatever the type of business: €0.20 per person on each booking made by a customer through the Merchant’s link. A booking for one person costs €0.20; a booking for five people costs €1. On bookings where the number of people is not asked, one person is counted.
No charge is made for bookings that are cancelled, for those the Merchant marks as no-shows, or for those the Merchant enters themselves — the ones taken over the telephone, the ones from people who walk in. Each booking counts towards the month of the date it was booked for, and each month’s bill is issued in the following month. Marking a no-show removes that booking from the bill for as long as the month has not been invoiced.
We give at least 30 days’ notice by email before we start charging anything at all, and you may close the account before then without paying anything. Cardim does not currently process payments or deposits on your behalf, and does not charge your customers anything directly.
7. Third-party integrations
The Service uses Resend to deliver transactional emails (booking confirmations, reminders, cancellations) and, if you choose to connect them, the Google Calendar API and/or the Microsoft Graph API for Outlook/Office 365 — each of them in order to read the free and busy periods in your calendar and to write an event, with the customer’s name and telephone number, for each booking made through Cardim — with Google, into a separate calendar that Cardim creates in your account, which is the only calendar Cardim is able to see or change. What the customer writes in the notes field is not copied into the calendar — the event states only that a note exists, to be read in Cardim. Connecting a calendar is entirely optional; in Settings you can disconnect it or connect another account whenever you wish. Use of any third-party service you connect is also subject to that provider’s terms.
8. Availability of the Service
We aim to keep the Service reliably available, but we do not warrant that it will operate uninterrupted or error-free. The Service is provided “as is”, without warranties of any kind, express or implied, to the fullest extent permitted by law.
9. Limitation of liability
To the fullest extent permitted by law, Cardim will not be liable for indirect, incidental or consequential damages arising out of your use of the Service, including revenue lost through a failed or duplicated booking, save where such liability cannot be excluded by law.
10. Termination
You may stop using the Service whenever you wish. You may also export your account data at any time, under Settings → Your data. To close the account and delete everything we hold about you, write to us: we delete the account and all associated data within 30 days and confirm by email once it is done. We may suspend or close an account that breaches these Terms, in accordance with our Privacy Policy.
11. Changes to these Terms
We may update these Terms from time to time. If we make material changes, we will update the “Last updated” date above and, wherever practicable, notify Merchants directly.
12. Governing law
Provisional text: Cardim does not yet have a registered legal entity, so no forum has in fact been chosen. Portugal is given below only as a working assumption of this draft, being the place from which the business currently operates — replace this as soon as a real entity and its registered office exist. Until then, these Terms are provisionally treated as governed by Portuguese law, without regard to its conflict of laws rules.
13. Contact
Questions about these Terms may be sent to support@usecardim.com.