Privacy Policy
Last updated: October 12, 2025
This Privacy Policy explains how Cardyvo (“we”, “us”, “our”) collects, uses, and shares information when you use our website and services. Cardyvo lets you create and share a digital business card that opens in any browser via NFC tap, QR scan, or short link. Digital cards are free & unlimited. Optional add-ons include a physical NFC card and an offline share page.
At a glance (summary)
- We collect account details you give us and basic usage/device data.
- Your **card content** is chosen by you and can be edited or removed any time.
- Offline page stores essentials locally on your device when enabled.
- We don’t sell your personal information.
1. Who we are & contacts
Cardyvo is operated by TODO: Company legal name, registered in TODO: jurisdiction, with registered address TODO: address. Data controller: TODO: same company / representative. Data Protection Officer (if applicable): TODO: DPO name/email.
Contact: TODO: privacy@yourdomain.com
2. Scope
This Policy covers our websites, app-like experiences (e.g., “Add to Home Screen”), free digital cards, and optional add-ons (physical NFC card and offline share page). It does not cover third-party sites linked from your card.
3. Information we collect
Category | Examples | Source |
---|---|---|
Account information | Name, email, password hash, basic settings. | You |
Card content | Profile photo, role, bio, phone, email, website, social links, buttons, theme choices, logo/cover image. | You |
Usage & device data | Pages viewed, referral URLs, general location (city/region from IP), language, browser type, OS, timestamps. | Automatic |
Cookies & local storage | Preferences (e.g., language), session tokens, analytics identifiers. See Cookies. | Automatic |
Support communications | Messages you send us (email, forms), metadata needed to respond. | You |
Orders for add-ons | Shipping details, contact details, order contents, payment confirmation (from our payment processor). | You / Payment provider |
Offline share page (add-on)
If you enable the offline share page, a minimal copy of your contact (QR + vCard) is stored locally on your device for offline presentation. This is not transmitted to us unless you later use the online service. You can disable the feature any time.
Physical NFC card (add-on)
When ordering, we collect shipping and custom branding details to fulfill your order. Payments are processed by a third-party provider (we do not store full card numbers).
4. How we use information
- Provide the service: host your card, show your QR, support NFC/links, maintain accounts.
- Improve & troubleshoot: understand usage, fix problems, enhance reliability and UX.
- Communicate: send service messages (account, security, changes). You may opt out of non-essential emails.
- Safety & integrity: detect abuse, fraud, security incidents.
- Legal: comply with law, enforce Terms, protect our rights and users.
5. Legal bases (GDPR)
- Contract — to create your account and provide Cardyvo features you request.
- Legitimate interests — to improve, secure, and market our services responsibly.
- Consent — for optional things like certain cookies/analytics or marketing emails.
- Legal obligation — to comply with accounting, tax, and regulatory requirements.
7. Data retention
We keep personal data only as long as necessary for the purposes described above: account data for the life of the account, support communications for TODO: X months, order records for TODO: Y years to meet legal obligations. You may delete your card content or request account deletion at any time.
8. Security
We use reasonable technical and organizational measures to protect personal data (encryption in transit, access controls, backups). No method of transmission or storage is 100% secure.
9. International transfers
Your data may be processed in countries other than your own. Where required, we rely on appropriate safeguards (e.g., EU Standard Contractual Clauses) to protect data transferred internationally.
10. Your rights
Depending on your location, you may have rights to:
- Access, correct, or delete your personal data.
- Object to or restrict certain processing, and withdraw consent where processing is based on consent.
- Receive a copy of your data in portable format (data portability).
- Lodge a complaint with a supervisory authority (e.g., in the EU: your local DPA).
To exercise rights, contact us at TODO: privacy@yourdomain.com. We may verify your request. For authorized agents (where applicable), provide proof of authorization.
12. Children
Cardyvo is not directed to children under the age where parental consent is required in your region. Do not use Cardyvo if you are under that age. If you believe a child has provided personal data, contact us to request deletion.
13. Changes to this Policy
We may update this Policy from time to time. We will change the “Last updated” date and, where appropriate, provide additional notice. Your continued use of Cardyvo after the effective date means you accept the updated Policy.
14. Contact us
Questions or requests? Email TODO: privacy@yourdomain.com or write to TODO: postal address. For Terms & Conditions, see Terms.
Disclaimer: This template is for convenience and does not constitute legal advice. Please ask a qualified attorney to review and adapt it to your business and jurisdiction.