CardVault is a Garmin Connect IQ app that stores your loyalty cards, tickets and two‑factor (2FA) codes on your watch. This policy explains, in plain language, what happens to your data.
In short: CardVault has no accounts, no analytics and no tracking. Your cards live on your watch. The optional sync feature moves data through a server only briefly and then deletes it. Nothing is sold or shared.
What we do not do
We do not require an account or login.
We do not use analytics, advertising or tracking of any kind.
We do not collect personal information such as your name, email, location or contacts.
We do not sell, rent or share your data with third parties.
Where your cards are stored
Your cards (barcode numbers, QR contents, 2FA secrets, names and colours) are stored locally on your Garmin watch. You can add them in two ways:
Garmin Connect settings — you paste your card data directly into the app settings. This never touches our server. Note that Garmin app settings are stored in your Garmin Connect account, so card data (including 2FA secrets) added this way is kept by Garmin as ordinary app settings.
The companion website (cardvault.site) — scanning and reading of QR codes and barcodes happens entirely in your browser. Data is only sent anywhere when you actively choose to sync (see below).
The sync feature
If you choose to send cards from the website to your watch, the data is transmitted to our sync server, matched to a short pairing code shown on your watch, and picked up by the app. For this feature:
Data is held in memory only, is deleted moments after your watch has picked it up, and expires after at most 30 minutes regardless.
There is no database and the contents of your cards are not logged.
Transmission uses an encrypted (HTTPS) connection.
Your watch holds a secret pairing token of 100 bits that the server generates; only that token can retrieve your cards. The 6-character code you type into the website is valid for 10 minutes, can be used once, and only grants permission to send cards to your watch.
Using sync is entirely optional — you can add all cards via Garmin Connect instead, in which case no data ever reaches our server.
Two‑factor (2FA) secrets
2FA codes are generated on your watch from a secret you provide. If you use the sync feature for a 2FA card, its secret passes through the sync server under the same temporary, non‑logged, auto‑deleted conditions described above. If you prefer these secrets never to leave your own devices, add 2FA cards through Garmin Connect settings instead of sync.
Security
You can lock the app with an optional PIN. The PIN is stored as a salted, repeatedly hashed SHA-256 digest — never as the code itself — and the screen locks for increasing periods after repeated wrong entries.
Card data on the watch is stored in the app's private storage. Connect IQ offers no encrypted key store, so treat the PIN as a lock on the display rather than as encryption of the data.
The website loads no external scripts, fonts or trackers: everything is served from our own domain, so your card and 2FA data never passes a third party.
The sync server keeps data only transiently and never persists it. You can disconnect a paired browser at any time from the watch menu (Disconnect sync).
Children
CardVault is not directed at children and does not knowingly collect data from anyone.
Changes
If this policy changes, the updated version will be posted on this page with a new date.
Contact
Questions about your privacy? Reach out via the contact details on the Connect IQ store listing.