In plain words
The CardDeck privacy policy explains how CardDeck collects, uses and protects personal data from account holders, from people who view or scan CardDeck cards and QR codes, and from contacts captured through cards. We collect only what the service needs, never sell personal data, and let you access, correct, export or delete it.
- Draft pending legal review; placeholders in brackets will be completed before publication.
- We collect account data, card content, captured contacts and aggregate usage data.
- For contacts you capture, you decide how they're used; we process them on your behalf.
- Scan analytics are aggregated and do not identify visitors.
- We don't sell personal data or use it for third-party advertising.
- You can access, correct, export or delete your data by emailing support@carddeck.co.
This summary is for convenience; the full text below is what applies.
01Draft notice
This privacy policy is a draft pending legal review. It is published to show how CardDeck intends to handle personal data and may change before it is finalized. Text in square brackets, such as [registered company name and address], marks details that are still to be confirmed. If anything here conflicts with a signed agreement between you and CardDeck, the signed agreement applies.
02Who we are
CardDeck is operated by [registered company name], a company registered in [country] with its registered office at [registered company address] ("CardDeck", "we", "us"). CardDeck provides an online service at carddeck.co for creating, sharing and managing digital business cards, QR codes, barcodes, ID cards, event badges, membership cards and profiles.
For questions about this policy or your personal data, email support@carddeck.co with "Privacy request" in the subject line, or write to us at [registered company address].
- EU representative (GDPR Article 27): [name and address, if required]
- UK representative: [name and address, if required]
- Grievance Officer for India: [name, designation and contact details]
- Data Protection Officer: [name and contact details, if appointed]
03Whose data this policy covers
This policy covers three groups of people:
- Account holders. People who sign up for CardDeck, including members invited to a team workspace.
- Visitors. People who open a CardDeck card or profile, or scan a CardDeck QR code, without signing in.
- Captured contacts and card subjects. People who share their details through a card's contact exchange form, and people whose details appear on cards, IDs or badges created by an organization (for example, an employee or student whose data is uploaded in a batch file).
Our role
For account holders and visitors, CardDeck decides how and why data is processed and acts as the controller (called a "data fiduciary" under India's DPDP Act).
For captured contacts and for data that an organization uploads about its employees, students, members or attendees, the CardDeck customer is the controller or data fiduciary, and CardDeck acts as a processor on their behalf. If you're one of those people, the organization or card owner is your first point of contact. We'll help them respond to your request. Business customers can request a data processing agreement at [link or contact for DPA].
04What personal data we collect
Data you give us
- Account data: name, email address, password (stored in hashed form) and, for teams, your role and workspace.
- Card content: the details you add to cards, IDs, badges and profiles, such as name, title, company, phone, email, photo, links, department, employee or student number and validity dates.
- Batch files: the rows of CSV or Excel files you upload to generate cards or codes.
- Billing data: billing name, address, tax details and plan history. Card payments are handled by our payment processor, [payment processor name]; we don't store full card numbers.
- Support messages: what you send us when you contact support or sales.
Data from visitors and contacts
- Contact exchange form: the details a visitor chooses to share with a card owner, such as name, email, phone, company and a note.
- Aggregate usage data: for card views and dynamic QR code scans we record date and time, sharing channel, device type and approximate region derived from the IP address. We use this to produce aggregate counts and do not use it to identify individual visitors.
Data collected automatically from account holders
- Technical data: IP address, browser type, device and log data needed to keep the service secure and working.
- Cookies: essential cookies to keep you signed in and remember preferences, and [describe any analytics cookies, if used]. Where the law requires consent for non-essential cookies, we ask first.
05How we use personal data and our legal bases
We use personal data only for the purposes below. For people in the EU and UK, we list the GDPR legal basis for each.
- To provide the service: create and host your cards, generate codes and batches, store captured contacts and show analytics. *Basis: performance of a contract.*
- To manage accounts and billing: sign-in, plan changes, invoices and tax records. *Basis: contract and legal obligation.*
- To keep CardDeck secure: detect abuse, fraud, spam and unauthorized access. *Basis: legitimate interests.*
- To support you: answer questions and fix problems. *Basis: contract and legitimate interests.*
- To improve the product: understand, in aggregate, which features are used. *Basis: legitimate interests.*
- To send service emails: security notices, billing receipts and changes to these policies. *Basis: contract and legal obligation.*
- To send product news: only where you've opted in or where the law allows, with an unsubscribe link in every email. *Basis: consent or legitimate interests.*
- To comply with the law: respond to lawful requests and keep required records. *Basis: legal obligation.*
For people in India, we process personal data for the specified purposes above on the basis of your consent or for legitimate uses permitted by the DPDP Act, and you can withdraw consent at any time, as described below.
We do not sell personal data, use it for third-party advertising, or use visitor data to build profiles.
07International transfers
CardDeck and its service providers may process data in countries other than where you live, including [list of primary processing locations]. When we transfer personal data out of the EU, UK or India, we use safeguards the law recognizes, such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, and we follow any restrictions on transfers notified by the Government of India under the DPDP Act.
08How long we keep data
We keep personal data only as long as we need it:
- Account and card data: while your account is active. After you delete your account we remove it within [30] days, except where we must keep records for legal reasons.
- Captured contacts: until the card owner deletes them or closes their account.
- Batch files: uploaded files are kept only as long as needed to generate and deliver the batch, then deleted within [X] days.
- Aggregate analytics: kept while the card or code is active; aggregate counts don't identify individuals.
- Billing records: for the period required by tax and accounting law, typically [X] years.
- Backups: deleted data may remain in backups for up to [X] days before being overwritten.
09How we protect data
All connections to CardDeck use HTTPS encrypted with TLS. Access to customer data is restricted to staff who need it to provide the service. Team workspaces use roles and locked templates, and Business plans can use single sign-on. Passwords are stored in hashed form. No system is perfectly secure, so if we become aware of a breach that affects your personal data, we'll notify you and the relevant authorities as the law requires, including the Data Protection Board of India where applicable. Read more on our security page.
10Your rights
Depending on where you live, you have some or all of these rights:
- Access: get a copy of the personal data we hold about you.
- Correction: fix inaccurate or incomplete data. Most card data you can edit yourself.
- Deletion: ask us to erase your data.
- Portability: receive your data in a common machine-readable format, such as CSV.
- Objection and restriction: object to processing based on legitimate interests, or ask us to limit it.
- Withdraw consent: where we rely on consent, withdraw it at any time, as easily as you gave it.
- Nominate: in India, nominate another person to exercise your rights in case of death or incapacity.
- Grievance redressal: in India, raise a grievance with our Grievance Officer, and then with the Data Protection Board of India if unresolved.
- Complain: in the EU or UK, complain to your local data protection authority or the UK Information Commissioner's Office.
US state privacy rights
If you live in a US state with a consumer privacy law, such as California, you may have rights to know, access, correct and delete personal data, and to opt out of the sale or sharing of personal data. CardDeck does not sell personal data or share it for cross-context behavioral advertising. We won't discriminate against you for exercising your rights.
How to make a request
Email support@carddeck.co with "Privacy request" in the subject line. We'll verify your identity, then respond within the time the law requires, usually within one month. If your data was uploaded by an organization or captured by a card owner, we may refer your request to them as the controller.
11Children
CardDeck accounts are for adults and organizations. You must be at least 18 to create an account. Schools and other organizations may create ID cards for students under 18; in that case the organization is responsible for having a lawful basis and any required parental consent, including verifiable parental consent under India's DPDP Act, and CardDeck processes that data only on the organization's instructions. If you believe a child has created an account, contact us and we'll delete it.
12Changes to this policy
We'll update this policy when our practices or the law change. The "Last reviewed" date at the top shows when it was last changed. If a change is significant, we'll tell account holders by email or in the dashboard before it takes effect. Read this alongside our terms of service.
Frequently asked questions
Does CardDeck sell my personal data?
No. CardDeck does not sell personal data or share it for third-party advertising. We use it only to provide, secure and improve the service.
Who controls the contacts I capture with my card?
You do. For contacts captured through your card, you are the controller and CardDeck processes them on your behalf. You can tag, export and delete them at any time.
What does CardDeck record when someone scans my QR code?
CardDeck records the date, sharing channel, device type and approximate region to produce aggregate counts. It does not identify the person who scanned unless they choose to share their details.
How do I delete my CardDeck account?
Email support@carddeck.co from your account email with "Privacy request" in the subject line. We'll verify your identity and delete your data, except records we must keep by law.
My school created my student ID with CardDeck. Who do I ask about my data?
Ask your school first, because it decides how your data is used. CardDeck processes that data on the school's instructions and will help the school respond.
Is this privacy policy final?
No. It is a draft pending legal review, and bracketed details will be completed before it is finalized. The last reviewed date shows the current version.