Privacy
Research a card without becoming the product.
How 9cards handles account, community, security, preference and advertising data.
Last updated: 1 August 2026. 9cards is an independent Indian card-information website. Privacy questions and requests can be sent to [email protected].
Information we process
You can browse card research without creating an account. Search terms are used to return the requested results. If you create a forum account, we process your email address, display name, username, password hash, profile details, posts, reactions, reports and account activity. Public profile details and community contributions are visible to other visitors.
For security and abuse prevention, we process limited technical information such as a salted hash of your IP address, your browser user-agent and login-attempt records. Do not send card numbers, bank credentials, statements, OTPs, passwords or credit reports.
We keep a first-party count of how many pages are viewed and how many people visit, measured on our own server. Per day we store a view count for each page path, a salted hash of your IP address recorded once so a repeat visit is not counted twice, and an aggregate of client IP address × page path used only for abuse review on the operator dashboard, together with the country, region and city reported by our CDN edge for that address. Against that same address we also keep two coarse labels per day: a client class derived from your browser’s user-agent — one of crawler, phone, tablet, desktop or unidentified, with a recognised name such as Chrome or Googlebot where the name is one on a short fixed list — and the hostname of the site that referred you, classified as a search engine, AI assistant, social network, other site or none. The user-agent string itself is not stored, and neither is the referring address beyond its hostname, so a search you ran on another site is never recorded here. Separately, and with no address attached, we count how many visits each page received from each of those referrer classes per day — for example “three visits to the comparison page from a search engine” — which is how we see which pages are useful enough to be found. No cookie is used for this, no third-party script is loaded, no per-request log is kept in the application database, and the search terms and query strings you use are never recorded. These counts are not used to build a marketing profile and are deleted after 180 days. Separately, the reverse-proxy access log used to operate the site may retain requesting IP addresses, page paths with query strings removed, response status and timing for about 30 days for security and reliability analysis.
If you write to us through the contact form, we process the name, email address and message you provide in order to reply. Those messages are kept until the enquiry is resolved and are not used for marketing.
Cookies and local storage
Signed-in users receive a secure, HTTP-only session cookie needed for authentication and account security. It expires after inactivity and has a maximum lifetime of 90 days. Your theme, comparison shortlist and catalogue-view preferences may be stored locally in your browser. These essential features are not used for advertising.
Why we use information
We use information to provide requested pages and account features, operate and moderate the community, secure the service, prevent fraud and abuse, respond to requests, and meet legal obligations. We do not sell card application or financial-account data, and the site does not request that data.
Advertising and analytics
9cards does not load third-party advertising or analytics trackers. The visit counting described above is first-party, server-side and cookieless. If Google advertising is enabled, Google and its partners may use cookies or similar technologies to serve, measure and personalise ads where permitted. We will identify the providers and purposes and present consent controls where required before those technologies load. You can learn how Google uses information from sites that use its services at Google’s partner-sites policy.
Retention, sharing and your choices
Session records expire automatically. Account and community records are kept while the account and community need them, including where moderation history is necessary for safety and integrity. We disclose information only to service providers that operate the site, when required by law, or to protect users and the service. You may request access, correction or deletion by emailing us; some records may be retained where legally required or necessary for security, dispute resolution or community integrity.
We will update this notice before materially changing how personal information is used. The date above shows the latest revision.