CardoraWallet business cards

Effective

Privacy Policy

This policy explains the information Cardora handles when you visit the service or create and share wallet-first business cards.

1. Information You Provide

We collect information you provide when you create or use an account, including your email address, authentication identifiers, and basic profile details. We also process card content you choose to add, such as names, titles, companies, contact links, images, branding, QR settings, wallet-pass settings, public-profile settings, team workspace details, and invitations.

If a visitor uses a card's contact-exchange feature, we process the information submitted through that form so it can be delivered to the card owner. Published card profiles are public by design, and anyone with a public link may be able to view or download the information the owner publishes.

2. Usage, Attribution, and Technical Information

We collect operational events needed to provide and secure Cardora, including authentication, wallet generation, card publication, profile-view, QR/vCard, link, billing, team administration, delivery, error, and diagnostic events.

When first-party usage analytics is enabled, we also collect limited website and product events. These may include a randomly generated browser identifier, a session identifier, timestamps, landing-page path, referring hostname, coarse device class, campaign parameters such as source, medium, campaign, content, and term, and actions such as page views, signup steps, card creation or publication, sharing, and recipient interactions. Signed-in events may be associated with an account or card identifier so we can measure whether the product is working.

The analytics record is designed not to contain raw IP addresses, full browser user-agent strings, email addresses, one-time passwords, contact-exchange form values, card-field values, or outbound-link destinations. Campaign and path values are limited and normalized, and event metadata is restricted to approved fields.

3. How We Use Information

We use information to:

  • provide accounts, cards, public profiles, vCards, QR codes, and wallet passes;
  • process subscriptions and administer team workspaces;
  • deliver requested messages and contact exchanges;
  • secure the service, prevent abuse, diagnose errors, and provide support;
  • understand acquisition, feature usage, and product performance; and
  • comply with law and enforce our agreements.

Cardora does not use its first-party analytics events for cross-site advertising, and we do not sell those events as a data product.

4. Legal Bases Where Applicable

Where law requires a legal basis, we process information as needed to perform our contract with you, pursue legitimate interests such as operating, securing, and improving Cardora, comply with legal obligations, and obtain consent where applicable. The legal basis may depend on the data, purpose, and location involved.

5. Cookies and Similar Technologies

Cardora uses cookies for authentication, security, service operation, and first-party usage analytics. Analytics cookies use random identifiers and campaign details; they do not contain your email address or card content. Our Cookie Notice lists their names, purposes, and standard durations.

6. Service Providers and Disclosures

We use service providers for hosting, databases, authentication, email delivery, payments, logging, security, and Apple or Google Wallet integrations. They may process information as needed to provide those services to Cardora and subject to their agreements and legal obligations.

We may also disclose information when required by law, to protect rights or safety, to investigate abuse, or as part of a merger, financing, acquisition, reorganization, or sale of assets. We do not sell personal information for money or share it for cross-context behavioral advertising.

7. Retention

We generally retain first-party analytics events for 90 days. We retain account, card, subscription, security, and transaction records for as long as needed to provide the service, meet legal or accounting obligations, resolve disputes, maintain security, and enforce agreements. Retention may differ for backups and records that must be preserved by law.

8. Security

We use technical and organizational measures designed to protect information, including access restrictions and data-minimization controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. International Data Transfers

We and our service providers may process information in countries other than your own. Where required by law, we use appropriate safeguards for cross-border transfers.

10. Your Choices and Rights

You can edit or unpublish card content in the app and manage cookies through your browser. You may request access, correction, deletion, or export of personal information, and may object to or request restriction of certain processing where applicable. Some requests may be limited by identity-verification, legal, security, or operational requirements.

To make a privacy request, email privacy@cardora.io. You may also have the right to complain to the privacy or data-protection authority where you live.

11. Children

Cardora is not intended for children under 13, and we do not knowingly collect personal information from children under 13. Additional age restrictions may apply depending on location.

12. Changes to This Policy

We may update this policy as Cardora changes. We will update the effective date above and, when required, provide additional notice through the service or by email.

13. Contact

Privacy questions or requests can be sent to privacy@cardora.io.