Digital business card security and data privacy at CardDeck
Digital business card security comes down to three questions: who can see your card and contact data, who can change it, and what happens when someone leaves. This page explains how CardDeck handles each one, in plain language.
Digital business card security at CardDeck means your card and contact data travels only over encrypted HTTPS connections, is visible only to your account and the team members you authorize, can be deactivated instantly when someone leaves, and can be exported or deleted on request. Scan analytics are aggregated and don't identify visitors.
- All traffic to CardDeck cards, codes and the dashboard uses HTTPS with TLS encryption.
- Team roles (owners, admins, editors, members) control who can see and change what.
- Admins can deactivate a card or ID in one click; verification pages update immediately.
- Scan analytics are aggregate counts with no personal data unless a visitor chooses to share it.
- You can export contacts to CSV and request deletion of your data at any time.
What data does CardDeck hold?
CardDeck holds three kinds of data: the details you put on your cards, the contacts people choose to share with you, and aggregate analytics about how your cards and codes are used.
- Card data. Your name, title, photo, logo, links and contact details, plus the content of ID cards, badges and membership cards you create. For batch jobs, this includes the rows of the CSV or Excel file you upload.
- Captured contacts. When someone opens your card and fills in the contact exchange form, the details they choose to share are stored in your account so you can tag, annotate and export them.
- Usage and analytics. Counts of views and scans, with date, sharing channel, device type and approximate region.
- Account and billing data. Your login email, workspace settings and billing records.
We collect what the product needs to work and nothing more. See the privacy policy for the full list and legal basis.
How does CardDeck protect data in transit?
Every connection to CardDeck uses HTTPS, encrypted with TLS. That covers your public card pages, dynamic QR code redirects, the dashboard where you edit cards, file uploads for batch jobs and contact exchange forms.
This means someone on the same café WiFi as you, or as the person scanning your card, cannot read or alter the data passing between their phone and CardDeck. Card links use the carddeck.co domain, or your own custom domain on the Business plan.
Who can access my cards and contacts?
Only you and the people you authorize can see your private data. Public card pages show exactly the fields you choose to publish; everything else, including captured contacts and analytics, stays behind your login.
Team roles and permissions
In a team workspace, access is controlled by role:
- Owners manage billing, workspace settings and every member.
- Admins invite and remove members, manage templates and deactivate or reassign cards.
- Editors create and update cards and templates within the workspace.
- Members edit their own card details within the locked template.
Locked brand templates mean members can change their phone number or photo but not the design, so nobody can publish an off-brand or misleading card under your company name. On the Business plan, single sign-on (SSO) lets you manage access through your existing identity provider.
Internal access
CardDeck staff access customer data only when it's needed to provide the service, for example to investigate a support request you've raised, and only with the minimum access required.
What happens when an employee leaves?
An admin can deactivate or reassign the person's card in one click from the team dashboard. Deactivation takes effect immediately.
For business cards, the public page stops showing the former employee's details, so prospects are never left with a dead number or a contact who no longer represents you. You can reassign a shared card, such as a territory or reception card, to someone else so the printed QR code keeps working.
For employee ID cards, the QR code on the card opens a verification page that shows whether the ID is active. Deactivate an ID and that page updates straight away, so security and reception can see that a card is no longer valid even if the physical card hasn't been returned. This is one reason enterprise teams manage IDs and business cards in the same workspace.
How does CardDeck handle scan analytics privacy?
CardDeck analytics are privacy-first: we record aggregate counts, not people. For each card view or dynamic QR code scan, we record the date, the sharing channel, the device type and an approximate region.
What we do not do:
- We don't identify the person who scanned a code or opened a card.
- We don't build profiles of visitors or follow them across other websites.
- We don't sell visitor data.
A visitor becomes a named contact only if they choose to share their details through the contact exchange form. Even then, those details belong to the card owner's account and are used to follow up, not for advertising. Learn more about how this works in contact management.
Can I export or delete my data?
Yes. Your data is yours, and you can take it with you or remove it.
- Export contacts. Export captured contacts to CSV from the Pro plan, with CRM export on Team and Business.
- Export analytics. Basic analytics with CSV export on Pro; advanced analytics with export on Business.
- Delete contacts and cards. Remove individual contacts or cards from your dashboard at any time.
- Delete your account. Ask us to delete your account and associated data by emailing support@carddeck.co. We'll confirm your identity first.
If someone who shared their details with you asks to be removed, delete their contact record. If they contact us directly, we'll help them reach you or handle the request as the privacy policy describes.
What happens to QR codes if I cancel or downgrade?
Static QR codes and barcodes keep working forever, because the data lives in the code itself. Dynamic QR codes depend on CardDeck's redirect service, so before any plan change that affects them, CardDeck shows you exactly which codes will be affected and lets you choose which to keep active.
How does CardDeck approach privacy by design?
We build privacy into the product rather than bolting it on:
- Minimal by default. Cards show only the fields you choose to publish.
- No app required. Visitors open cards in their browser without creating an account or installing anything.
- Consent for contact sharing. Visitors decide what, if anything, to share back.
- Clear ownership. You control your card data and the contacts you capture; we process them to run the service.
- Respecting regional law. We design our practices with GDPR in the EU and UK and India's Digital Personal Data Protection Act, 2023 in mind.
CardDeck does not currently claim third-party security certifications. If your organization has a security questionnaire or procurement checklist, email sales@carddeck.co and we'll work through it with you.
Frequently asked questions
Is a digital business card safe to share?
Yes, as long as you only publish details you're comfortable making public. A CardDeck card shows only the fields you choose, travels over HTTPS and can be edited or deactivated at any time, which is more control than a paper card gives you.
Can someone track me when I scan a CardDeck QR code?
No. CardDeck records aggregate scan counts with date, channel, device type and approximate region. It does not identify you unless you choose to share your details through the card's contact form.
Does CardDeck have SOC 2 or ISO 27001 certification?
CardDeck does not currently claim third-party certifications. If you need answers for a vendor security review, email sales@carddeck.co with your questionnaire.
Can I stop a lost employee ID card from being used?
Yes. Deactivate the ID in your team dashboard and its QR verification page immediately shows that the card is no longer active. You can then issue a replacement from the same template.
Does CardDeck sell my contacts?
No. Contacts captured through your card belong to your account. CardDeck processes them to provide the service and does not sell them.
Is CardDeck GDPR compliant?
CardDeck is designed with GDPR and India's DPDP Act in mind: minimal data collection, consent-based contact sharing, export and deletion on request. The privacy policy sets out the details, including your rights as a data subject.
Every card, code and contact — in one deck.
Start free with one digital business card. Upgrade when your team is ready.