ISIC Logo Full
LEGAL DOCUMENTS

Privacy Policy

Last updated: August 26, 2026

1. Who is responsible for processing your data?

The entity responsible for processing your personal data is Contemporary Student Solutions Albania SHPK (hereinafter, “CSSA”), located at “Rruga Bulevardi Kryesor, Nr. pasurie 2/83+2-5, Zona kadastrale 8514, Durrës, Albania, 2001”, registered in the National Business Registry on 16/07/2024 with identification number M41916501C.

This Privacy Policy governs access to and use of the website www.studentcard.al (hereinafter, the “Website”) that CSSA makes available to internet users (hereinafter, the “Users”) interested in the products and services (hereinafter, the “Services”) offered by CSSA.

Contact email: contact@studentcard.al

2. Recommendations

Please read and follow these recommendations carefully:

  • Keep your device updated with antivirus software against malware and spyware that could compromise your internet navigation and stored information.
  • Read and review this Privacy Policy and all legal texts provided by CSSA on the Website.

3. Information collected by CSSA through the Website

For proper functionality, CSSA may access the following data provided by the User:

  • Identification data: name, surname, identity document (national ID card or passport), and identification photo.
  • Personal characteristics: date of birth, gender, nationality.
  • Contact data: email and phone number.
  • Academic data: level of education, educational institution, faculty, and study programme.
  • Usage data, collected automatically: the pages you visit, the actions you take on the Website, your device and browser type, approximate location (IP), session replays of your visit, and technical error reports. See Section 5.
  • Email engagement data, collected automatically: whether an email CSSA sent you was opened and when, and which links inside it you clicked — including the time of the click, the approximate location (IP) it was made from, and the browser or mail application used. See Section 5.

As part of the application, the User uploads images of their identity document and proof of study. These documents are processed solely to verify the User’s eligibility for an ISIC card. Payment for the card is handled by our third-party payment provider; CSSA does not store the User’s full card or banking details.

4. Why is CSSA authorized to process your data?

CSSA relies on a different legal basis depending on what the data is used for:

  • Performance of a contract— for everything needed to deliver the Service the User applied for or purchased: processing the application, verifying student status, issuing and delivering the card, taking payment, and sending the communications described in section 5 that form part of the Service.
  • Legitimate interests— for keeping the Website secure and working, and for reminding a User about an application or order they began and have not completed. The User can stop those reminders at any time.
  • Consent— for analytics cookies and session replays only, which are described in section 5. This consent is asked for separately, on the User’s first visit, and can be changed at any time from the Cookie Policy. Declining does not affect the Service.
  • Legal obligation— where CSSA is required to retain records, for example for accounting purposes.

Because the Service cannot be delivered without the data listed under performance of a contract, that data is not optional; a User who does not wish to provide it can choose not to apply for a card.

CSSA ensures the secure handling of your personal data in accordance with the EU General Data Protection Regulation (GDPR) (Regulation 2016/679) and Albanian Law No. 124/2024 “On the Protection of Personal Data” (in force since 31 January 2025), which is harmonised with the GDPR.

Where processing is based on consent, Users can withdraw it at any time — for analytics, from the control in the Cookie Policy; for anything else, by emailing contact@studentcard.al, without affecting the lawfulness of prior data processing.

5. Purposes of data processing

Your personal data collected by CSSA may be used for the following purposes:

  • To provide the services and content of the Website.
  • To send the emails required to operate a User’s account and order— sign-in links, order confirmations, and updates on the status of documents they have submitted. These are necessary to deliver the Service and cannot be switched off while the account is active.
  • To remind a User about something they started and have not finished— an application or order left incomplete, or a card approaching expiry. Every such email contains a link to switch these reminders off.
  • To send communications about student discounts, benefits and partner offers by email. Access to those offers is the purpose of the ISIC Card and forms part of the Service the User purchases (Article 3.3 of the Terms of Service), so these are sent on the basis of performing that contract rather than on separate consent. Every such email contains a link to stop receiving them, and doing so does not affect the validity of the card.
  • To measure whether the emails above are useful— CSSA’s email provider records whether and when a message was opened and, if a link is clicked, which link, the time, the approximate location (IP), and the browser or mail application used. This helps us send fewer but more useful emails. It stores nothing on your device and is never used for advertising. An open is measurable only when your mail application loads remote images — most let you block them.
  • To manage and respond to User’s requests, inquiries, or issues.

CSSA uses PostHog, an analytics and error-monitoring tool, to understand how the Website is used and to improve the application process. PostHog records the pages you visit, the actions you take on the Website, your device and browser type, approximate location (IP), and technical error reports. Where you are signed in, this activity is linked to your account, so that we can find and fix the points where Users get stuck. PostHog processes this data on servers within the European Union. CSSA does not use it for advertising and does not sell it.

To find the points where Users get stuck, PostHog also makes session replays. A replay is a reconstruction of your visit, rebuilt from the page itself rather than from any image of your screen: it shows the pages you viewed, your mouse movement, clicks and scrolling, and the text you type into forms. This means information you enter while applying for an ISIC, such as your name, date of birth, phone number, and academic details, can appear in a replay.

The identity documents, study documents and photograph you upload are never captured. They are blocked inside your browser and are not sent to PostHog, so no document or photograph of yours ever appears in a replay — not while you are applying, and not later on your profile page. Replays are stored on servers within the European Union and are deleted automatically after 30 days.

Session replays, and any linking of this activity to your account, happen only if you consent. On your first visit you are asked to accept or decline. If you decline — and equally for as long as you have not answered — PostHog stores nothing on your device, no session replay is made, your IP address is not stored, and your activity is not linked to your account; we then only count visits using a daily code that cannot be traced back to you. Your choice is remembered for 12 months, after which you are asked again. You can change it at any time from the control at the top of our Cookie Policy, which also explains this in full.

CSSA also uses Vercel Web Analytics, provided by the company that hosts the Website, purely to count visits. It records the address of the page opened, the country the request came from, the device type and browser, and the referring website. It sets no cookie, stores nothing on your device, does not use your IP address to build a profile, and cannot recognise you on a later visit or link your activity to your account. Because it stores nothing on your device and identifies no one, it runs whether or not you consent to analytics cookies; we rely on it as an independent measure of how many people use the Website.

6. Accuracy of data provided by Users

Users guarantee the accuracy of their data and commit to informing CSSA of any changes. CSSA reserves the right to deny services to any User who provides false information.

Users should protect their data diligently using appropriate security tools. CSSA will not be responsible for unauthorized alterations, theft, or data loss unless caused by CSSA’s negligence.

7. Data retention

User data will be retained as long as it remains relevant for the purposes for which it was collected, or until the User requests deletion. Afterward, CSSA will retain information for legally mandated periods.

The identity and study documents uploaded by the User are securely stored for as long as the User’s ISIC application and membership remain active, after which they are deleted in line with CSSA’s retention periods.

Session replays made by PostHog (Section 5) are kept for a shorter period than other data and are deleted automatically 30 days after they are made.

CSSA is committed to maintaining the confidentiality of personal data as required by law.

8. User rights

Users have the right to:

  • Access their personal data.
  • Request the correction of inaccurate data.
  • Request the deletion of their data.
  • Limit data processing.
  • Object to data processing.
  • Request data portability.
  • Avoid decisions based solely on automated data processing.

To exercise these rights, Users can email contact@studentcard.al with their request and a copy of their ID.

Users can file complaints with supervisory authorities if they believe their rights are violated.

9. Data security

CSSA has implemented measures to protect User data against unauthorized access, loss, or misuse, ensuring compliance with applicable legislation. However, Users should be aware that no online security system is infallible.

10. Transfers to third parties

CSSA does not sell your personal data. We share it only with the service providers that help us deliver the Services, and only to the extent necessary for the purposes set out in Section 4. These providers act as our processors and are bound to protect your data:

  • ISIC Association (Nytorv 5, 1450 Copenhagen, Denmark; CVR 26746760) — issues and verifies ISIC cards and maintains cardholder records.
  • Supabase — database, authentication, and secure storage of uploaded documents.
  • Vercel — hosting of the Website, and cookieless counting of visits that identifies no individual (Section 5).
  • POK (Nebula Ltd) — secure payment processing.
  • Google and Microsoft — sign-in, only where the User chooses to log in with one of these providers.
  • PostHog — product analytics, session replays and error monitoring, to measure how the Website and the application process are used. Data is stored on servers within the European Union.
  • Resend — delivery of the emails described in Section 5, and measurement of whether they were opened and their links clicked. Data is stored on servers within the European Union.

International transfers: in connection with issuing and verifying your ISIC card, ISIC Association stores cardholder data on servers within the European Union (Amazon Web Services, Ireland) and may verify your card internationally when you use it to obtain benefits abroad. Any such transfer is carried out under appropriate safeguards as required by applicable data-protection law.

11. Questions

For any questions about this Privacy Policy, contact contact@studentcard.al.

Users can file complaints with the Albanian Commissioner for the Right to Information and Protection of Personal Data (IDP.al) via phone (+355 42237200), postal address (Rr. “Abdi Toptani”, Nd. 5, Kodi postar 1001, Tiranë), or online at https://idp.al/kontakt/.

12. Acceptance and consent

By accepting this Privacy Policy, the User agrees to the processing of their personal data by CSSA in the manner and for the purposes stated.

Ready to start saving more as a student?

Get your ISIC today and unlock 150,000+ exclusive discounts from your favorite brands.

Apply Now