Skip to main content

Legal

Privacy Policy

Last updated October 2, 2026

Social Card, LLC, a Delaware limited liability company ("us", "we", or "our"), operates: (a) the Social Card websites, including joinsocialcard.com, socard.me, and app.joinsocialcard.com (the "Site"); (b) the Social Card mobile application for iOS (the "App"); (c) digital business card passes delivered through Apple Wallet and Google Wallet (the "Wallet Passes"); and (d) related products, features, and services (collectively with the Site, the App, and the Wallet Passes, the "Service"). This page informs you of our policies regarding the collection, use, and disclosure of Personal Information we receive from users of the Service. By using the Service, you agree to the collection and use of information in accordance with this policy.

Information Collection And Use

While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you. Personally identifiable information may include but is not limited to your name, company name, billing information, billing address, phone number, or email ("Personal Information"). The categories of Personal Information we collect, the sources from which we collect it, and how we use it are described in the sections below.

Categories of Personal Information We Collect

We collect the following categories of Personal Information. These categories align with those defined in the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and other applicable U.S. state privacy laws.

  • Identifiers. Name, email address, phone number, account username, IP address, device identifiers (such as Apple ID when you use Sign in with Apple, device advertising identifiers, and Identifier for Vendor), and similar identifiers.
  • Commercial Information. Records of products or subscriptions purchased, obtained, or considered, and other purchase or usage histories.
  • Internet or Other Electronic Network Activity Information. Information regarding your interaction with the Site and App, and information regarding interactions with digital business cards and links shared through our link and webpage analytics features.
  • Geolocation Data. Approximate geolocation derived from IP address. We do not collect precise (GPS-level) geolocation data.
  • Professional or Employment-Related Information. Job title, company name, role, and similar information that you include on your digital business card or that is extracted from business cards you scan.
  • Audio, Visual, and Similar Information. Images of paper business cards or conference badges captured through the card scanning feature; profile photos; and company logos.
  • Inferences. Inferences drawn from the above to support product features, analytics, and advertising (for example, that a browser has visited our pricing page).

We do not knowingly collect Sensitive Personal Information as defined under CCPA/CPRA (such as Social Security numbers, precise geolocation, racial or ethnic origin, religious beliefs, genetic data, or biometric identifiers used for identification).

Sources of Personal Information

We collect Personal Information directly from you (when you create an account, complete a digital business card, make a purchase, or submit information through the Service), automatically from your device and browser (when you use the Service), and from third parties such as identity providers (for example, Sign in with Apple) when you elect to use them to access the Service.

How We Use Information

We use Personal Information for the following purposes:

  • To provide and maintain the Service, including creating and managing your account, displaying your digital business card, processing card scans, and delivering Wallet Passes.
  • To process payments and manage subscriptions through our payment processors.
  • To communicate with you about the Service, including service announcements, security alerts, billing, and customer support responses.
  • To send marketing communications about Social Card products and features, subject to your preferences and applicable law.
  • To analyze usage and improve the Service, including measuring feature adoption, diagnosing technical issues, and developing new features.
  • To advertise the Service and measure our advertising, including learning which ads lead to sign-ups and demo requests and showing our ads to people who have visited our website, as described in "Advertising" below.
  • To detect, prevent, and address security issues, fraud, abuse, and violations of our Terms of Service.
  • To comply with legal obligations, respond to lawful requests, and enforce our rights.

Information We Share

We do not sell Personal Information for money. The advertising cookies and tags on our website, described in "Advertising" below, are considered "sharing" for cross-context behavioral advertising under California law, and may be considered a "sale" or "targeted advertising" under the laws of other U.S. states. You can opt out at any time, as described in "How to Opt Out of Sale or Sharing" below. We may disclose Personal Information in the following circumstances:

  • Service Providers and Sub-Processors. We share Personal Information with third parties that perform services on our behalf, such as cloud hosting, payment processing (Stripe), banking and invoicing (Mercury), AI-based card scanning (Google Gemini), analytics, customer support, email delivery, and authentication (Apple Sign In). A current list is maintained on our Sub-Processors page.
  • Advertising Partners. Google, Microsoft, and LinkedIn receive information about visits to our website through their advertising tags, as described in "Advertising" below. They are listed separately on our Sub-Processors page.
  • Recipients of Digital Business Cards. Information you include on your digital business card is shared with recipients you designate, and with anyone you make the card public to.
  • Business Customers and Administrators. If you access the Service through an employer or organization, your account administrators may have access to your account information, usage, and any content associated with your account.
  • Legal and Safety. We may disclose Personal Information where required by law, in response to lawful requests from government authorities, to enforce our rights, or to protect the safety of our users or the public.
  • Business Transfers. In the event of a merger, acquisition, reorganization, financing, or sale of all or a portion of our assets, Personal Information may be transferred as part of that transaction. We will notify affected users of any such transfer and any material changes to privacy practices.

Business Card Scanning

When you use the card scanning feature in our App, images of paper business cards or conference badges are captured using your device's camera or photo library. These images are sent to our servers and processed using a third-party AI service to extract contact information such as name, company, phone number, email, and job title.

We currently use Google Gemini as our AI model provider for card scanning. Under Google's terms for the paid Gemini API that we use, card image data submitted through Social Card is not used to train Google's AI models. Card images and extracted data are processed for the purpose of providing the scanning feature only.

Card images are stored within your account so you can reference them later alongside the extracted contact data. Extracted contact information is saved within your Social Card account and may optionally be saved to your device's contacts.

You are responsible for ensuring that you have an appropriate legal basis (such as legitimate interest in the ordinary course of professional contact exchange) to store contact information from cards you scan. Individuals whose cards you scan may have rights under applicable law to access, correct, or request deletion of their information, which you should honor as a data controller with respect to that information.

For a complete list of third-party services that process data on our behalf, see our Sub-Processors page.

Public-Facing Data

Social Card allows users to create digital business cards that are intended to be shared publicly. By using our services, you acknowledge and agree to the following terms regarding public-facing data:

User Choice and Control

  • Voluntary Disclosure: The information you include on your digital business card (e.g., name, contact details, company information) is provided voluntarily by you. You have complete control over what information to include.
  • Public Sharing: Digital business cards are designed to be shared publicly. This means that when you share your business card via email, social media, QR codes, or any other method, the information on the card becomes accessible to the recipient and potentially to the public at large.

Transparency and User Rights

  • Clear Information: We inform all users that the information included on their business cards will be public when shared. It is the user's responsibility to ensure that they are comfortable with sharing this information publicly.
  • Data Management: You can update, modify, or delete the information on your business card at any time through your account settings. This ensures that you retain control over your personal data.

Security Measures

  • Data Protection: While we facilitate the sharing of business card information, we implement security measures to protect against unauthorized access or misuse of the data. This includes encryption, secure access controls, and regular security audits.
  • Monitoring and Response: We monitor our platform for any potential misuse of public-facing data. If misuse is detected, we take appropriate action to mitigate any risks and protect user data.

Social Card provides analytics to users about interactions with their digital business cards, shared links, and landing pages (for example, view counts, click counts, approximate location derived from IP, referring source, user agent, and timestamps). This information is made available to the Social Card user whose card, link, or page was accessed.

If you interact with a Social Card digital business card, link, or page, the user who shared it may see engagement data about your interaction. This information is used to provide analytics to Social Card users and is not associated with any broader advertising profile.

Log Data

Like many operators, we collect information that your browser or device sends whenever you access our Service ("Log Data"). Log Data may include your Internet Protocol ("IP") address, browser type, browser version, device type, operating system, the pages of our Site that you visit, the time and date of your visit, the time spent on those pages, and other statistics. We may use third-party analytics services to collect, monitor, and analyze this data. A current list of such services is maintained on our Sub-Processors page.

Mobile Device Information

When you use the App on iOS, we may automatically collect the following device-level information:

  • Device identifiers, such as Identifier for Vendor (IDFV). We do not currently track users across apps or websites owned by other companies, and we do not collect the Identifier for Advertisers (IDFA). If we introduce tracking features in the future, we will do so only after obtaining your explicit consent through Apple's App Tracking Transparency (ATT) framework.
  • Device model, operating system version, and mobile network information.
  • Push notification tokens, used to deliver push notifications if you have enabled them.
  • Crash and performance diagnostics collected by our mobile analytics and crash reporting providers to help us diagnose issues and improve App stability.

Sign in with Apple

If you elect to sign in using Sign in with Apple, Apple transmits to us limited information associated with your Apple ID, which may include your name and an email address (or a private relay email address forwarded by Apple). We use this information solely to create and authenticate your Social Card account. Apple's privacy practices for Sign in with Apple are governed by Apple's own privacy policy.

App Permissions

The App may request the following device permissions. You may grant or deny each permission and may change your choices at any time in your device settings.

  • Camera and Photo Library — used only for the card scanning feature, to capture or import images of paper business cards or conference badges.
  • Notifications — used to deliver push notifications if you have enabled them.
  • Contacts (optional) — used only if you choose to save extracted card contacts to your device's contacts.

We do not request or collect: biometric identifiers (Face ID and Touch ID authentication occurs locally on your device and we do not receive the biometric data), Bluetooth, NFC, precise geolocation, or SMS permissions.

Communications

We may use your Personal Information to contact you with transactional communications (such as service announcements, security alerts, billing notices, and customer support responses) and, subject to your preferences and applicable law, marketing communications about Social Card products and features. You may opt out of marketing communications at any time by following the unsubscribe link in the email or by contacting us at [email protected]. Transactional communications are necessary to operate the Service and are not subject to opt-out.

Cookies

We use cookies and similar tracking technologies on our Site. Cookies are small files placed on your device that store information.

The cookies we use fall into the following categories:

  • Strictly Necessary Cookies — required to operate the Site and provide basic features such as authentication and session management. These cookies cannot be disabled without breaking Site functionality.
  • Functional Cookies — remember your preferences and settings to enhance your experience.
  • Analytics Cookies — help us understand how visitors use the Site so we can improve it. Set only with your consent where required by law.
  • Marketing Cookies — used to measure the effectiveness of our advertising. When you reach the Site from one of our ads, a campaign link, or another website, we store the details of your first and most recent such visit (ad click identifier, campaign details, the page you arrived on, and the referring site's address) in a cookie for up to 90 days. That cookie is shared between our website and our application at app.joinsocialcard.com, so a later sign-up or demo request can be credited to the visit that led to it. Set only with your consent where required by law, never when your browser sends a Global Privacy Control signal, and removed if you decline through Your Privacy Choices.
  • Advertising Cookies — set by the advertising tags of Google, Microsoft, and LinkedIn to measure which of our ads lead to sign-ups and demo requests, and to show our ads to people who have visited our website. See "Advertising" below.

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept strictly necessary cookies, some portions of the Service may not function properly.

In the European Economic Area, the United Kingdom, and Switzerland, we ask for your consent through our cookie banner before setting any non-essential cookie, and advertising cookies are not set at all. Elsewhere, analytics, marketing, and advertising cookies may be set by default, and you can opt out at any time by selecting Your Privacy Choices in the footer of our website and choosing Decline, or by enabling Global Privacy Control in your browser.

Advertising

We advertise Social Card on other websites and platforms. To measure and improve that advertising, our website may use advertising tags from the following partners:

  • Google Ads (Google LLC)
  • Microsoft Advertising (Microsoft Corporation), through its Universal Event Tracking (UET) tag
  • LinkedIn Insight Tag (LinkedIn Corporation)

These tags set cookies and collect information such as your IP address, browser and device information, cookie identifiers, the pages you visit on our website, the ad you clicked to reach us, and whether you then started a trial or requested a demo. Our partners use this information to report which of our ads lead to sign-ups and demo requests (conversion measurement) and to show our ads to people who have visited our website (remarketing). They may combine it with other information they hold about you, under their own privacy policies.

When you submit our demo request form, we send Google a one-way hashed (SHA-256) version of the email address you entered, so that Google can match the request to an earlier ad interaction ("enhanced conversions"). We do this for conversion measurement. We may also report to an advertising partner when a visit that began with one of its ads later leads to a sign-up, a qualified demo request, or a purchase, using the ad click identifier from that visit.

Advertising tags do not load on our website for visitors in the European Economic Area, the United Kingdom, or Switzerland, when your browser sends a Global Privacy Control signal, or after you decline through Your Privacy Choices. In those cases we also remove the cookies they set on our website.

You can also control how these partners use your information for advertising through Google's My Ad Center, Microsoft's ad settings, and LinkedIn's advertising preferences, and through the industry opt-out tools of the Digital Advertising Alliance and the Network Advertising Initiative.

Security

The security of your Personal Information is important to us. We implement technical and organizational measures, including encryption of data in transit and at rest, access controls, and ongoing security monitoring, to protect Personal Information. However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Information, we cannot guarantee its absolute security.

Data Retention

We retain Personal Information for as long as your account is active or as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Specific retention periods are as follows:

  • Account and profile data — retained while your account is active. Deleted from active systems promptly upon account deletion.
  • Digital business card and contact data — retained while associated with an active account. Deleted promptly upon account deletion or when you delete the specific item.
  • Scanned business card images — retained while the associated contact exists in your account. Deleted when you delete the contact, delete your account, or request deletion.
  • Billing and tax records — retained for at least seven (7) years as required by U.S. tax and accounting regulations, even after account deletion.
  • Backups — residual copies in our backup systems may persist for up to ninety (90) days after deletion from active systems, after which they are overwritten in the normal course of backup rotation.
  • Analytics and log data — log data in identified form is retained for up to twenty-four (24) months, after which it is aggregated or deleted. Certain analytics events and system log entries may persist after account deletion in aggregated or otherwise non-identifiable form that cannot reasonably be used to identify you as an individual.

Account Deletion

You may delete your account at any time. If you are using the iOS App, deletion is available from within the App. For accounts created through our other products, you may request deletion by contacting us at [email protected]. Account deletion is irreversible, subject to the retention periods listed above for billing, tax, and backup records.

International Data Transfers

Social Card is based in the United States, and the Service is operated from the United States. If you access the Service from outside the United States, your Personal Information may be transferred to, stored, and processed in the United States and other countries where our service providers operate.

For transfers of Personal Information from the European Economic Area, the United Kingdom, or Switzerland to the United States, we rely on appropriate safeguards, which may include the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum. Social Card is not currently certified under the EU-U.S. Data Privacy Framework; however, certain of our service providers may be certified under that framework and may rely on their own certification as an additional transfer mechanism. For more information or to request copies of the safeguards we rely on, please contact us at [email protected].

Children's Privacy

The Service is not directed at children under the age of 13 (or the applicable minimum age for consent to the processing of personal data in your jurisdiction, which may be higher, such as 16 in the European Economic Area). We do not knowingly collect Personal Information from children under the applicable minimum age.

If you are a parent or legal guardian and you believe that your child has provided us with Personal Information, please contact us at [email protected] and we will take steps to delete the information and terminate the child's account.

Your Rights Under the GDPR and UK GDPR

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights with respect to your Personal Information under the GDPR, UK GDPR, and Swiss Federal Act on Data Protection:

  • Right of access — to request a copy of the Personal Information we hold about you.
  • Right to rectification — to request correction of inaccurate or incomplete Personal Information.
  • Right to erasure ("right to be forgotten") — to request deletion of your Personal Information, subject to certain legal exceptions.
  • Right to restrict processing — to request that we limit how we process your Personal Information in certain circumstances.
  • Right to data portability — to receive your Personal Information in a structured, commonly used, machine-readable format and to transmit it to another controller.
  • Right to object — to object to our processing of your Personal Information based on legitimate interests or direct marketing.
  • Right to withdraw consent — where we rely on consent as a legal basis, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
  • Right not to be subject to automated decision-making — you have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not engage in such automated decision-making.
  • Right to lodge a complaint — you have the right to lodge a complaint with the data protection authority in your country of residence, place of work, or place of the alleged infringement.

To exercise any of these rights, please contact us at [email protected]. We will respond within thirty (30) days, or as otherwise required by applicable law.

We process Personal Information under the following legal bases:

  • Contractual necessity — to provide and operate the Service, including creating and managing your account, hosting your digital business card, processing card scans you submit, delivering Wallet Passes, and providing other features you have requested.
  • Consent — for marketing communications, non-essential cookies, and any other processing that relies on consent under applicable law. You may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
  • Legitimate interests — for analytics, security, fraud prevention, service improvement, and, in the case of the card scanning feature, the processing of third-party contact information extracted from business cards you scan, on the basis that business cards are voluntarily distributed for the purpose of contact exchange.
  • Legal obligation — to comply with applicable laws, including tax, accounting, and legal process requirements.

EU and UK Representative

Social Card is a small, U.S.-based business that operates the Service from the United States. Social Card does not maintain an establishment in the European Union or the United Kingdom, prices the Service in U.S. Dollars, and does not conduct marketing, advertising, or solicitation activities specifically targeted at residents of the European Union or the United Kingdom.

Social Card acknowledges that residents of the European Economic Area, the United Kingdom, and Switzerland may access and use the Service, and Social Card is committed to respecting applicable rights under the GDPR, the UK GDPR, and the Swiss Federal Act on Data Protection with respect to Personal Information of such residents.

Social Card has not at this time designated a representative under Article 27 of the GDPR or the UK GDPR, and is continuing to evaluate whether such designation is required based on the nature and scale of its processing activities and the degree to which the Service may be deemed to be offered to data subjects in the European Union or the United Kingdom. Social Card will designate a representative and update this Privacy Policy if and when required.

For questions or requests concerning Personal Information of EU, UK, or Swiss residents — including requests to exercise any of the rights described above, or to lodge a complaint — please contact us at [email protected]. Social Card will respond to such requests within the timelines required by applicable law and, where we are unable to fulfill a request, will explain the basis for our determination and advise you of your right to lodge a complaint with your local supervisory authority.

Data Processing Agreement (DPA)

If you are a business customer of Social Card and you are based in the EU, UK, or otherwise process Personal Data of EU or UK residents, our Data Processing Agreement governs our processing of such data on your behalf.

Your California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you specific rights regarding your Personal Information. This section applies to Personal Information collected about California residents.

Categories of Personal Information Collected, Sources, Uses, and Disclosures

The categories of Personal Information we collect, the sources from which we collect it, the purposes for which we use it, and the categories of third parties to whom we disclose it are described above in "Categories of Personal Information We Collect," "How We Use Information," and "Information We Share."

Sale and Sharing of Personal Information

We do not sell Personal Information for money. We do "share" Personal Information for cross-context behavioral advertising, as that term is defined by the CPRA, through the advertising tags described in "Advertising" above. The categories of Personal Information we share, and have shared in the preceding twelve (12) months, are:

  • Identifiers, such as IP address, cookie identifiers, ad click identifiers, and a hashed email address when you request a demo.
  • Internet or other electronic network activity information, such as the pages you visit on our website and the ad that brought you there.
  • Commercial information, such as whether a visit that began with an ad led to a trial, a demo request, or a purchase.
  • Geolocation data, limited to approximate location derived from IP address.

We share these categories with advertising networks (currently Google, Microsoft, and LinkedIn). We do not sell or share Sensitive Personal Information, and we do not knowingly sell or share Personal Information of consumers under the age of 16.

Your California Rights

Subject to certain exceptions, California residents have the following rights:

  • Right to Know — to request that we disclose the specific pieces and categories of Personal Information we have collected about you, the sources of that information, the purposes for collecting it, and the categories of third parties with whom we share it.
  • Right to Delete — to request that we delete Personal Information we have collected from you.
  • Right to Correct — to request that we correct inaccurate Personal Information we maintain about you.
  • Right to Opt Out of Sale or Sharing — to opt out of the sale or sharing of your Personal Information for cross-context behavioral advertising. See "How to Opt Out of Sale or Sharing" below.
  • Right to Limit Use of Sensitive Personal Information — because we do not use Sensitive Personal Information for purposes beyond those permitted by the CPRA, there is no additional limit-use process.
  • Right to Non-Discrimination — we will not discriminate against you for exercising any of your California privacy rights.

How to Exercise Your California Rights

To exercise any of these rights, please contact us at [email protected]. We will verify your request using reasonable means (such as matching identifiers you provide to information we have on file). You may designate an authorized agent to submit a request on your behalf by providing written authorization and verifying your identity with us directly. We will respond within forty-five (45) days and may extend our response period by an additional forty-five (45) days when reasonably necessary.

How to Opt Out of Sale or Sharing

You can opt out of the sale or sharing of your Personal Information, and of targeted advertising, in either of these ways:

  • Your Privacy Choices. Select Your Privacy Choices in the footer of our website and choose Decline. Our advertising tags stop loading and their cookies are removed from our website.
  • Global Privacy Control. Turn on Global Privacy Control in a browser or extension that supports it. We treat the signal as a valid opt-out request, as described in "Global Privacy Control and Do Not Track" below.

Your choice is stored in your browser, so it applies to the browser and device where you make it. If you clear your cookies or browser storage, or use a different browser or device, you will need to opt out again there. You do not need to create an account to opt out.

Shine the Light

California Civil Code Section 1798.83 permits California residents who have an established business relationship with Social Card to request certain information regarding our disclosure of Personal Information to third parties for those third parties' own direct marketing purposes. We do not disclose Personal Information to third parties for their own direct marketing purposes.

Other U.S. State Privacy Rights

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Delaware (DPDPA), Tennessee (TIPA), and other U.S. states with comprehensive privacy laws may have rights similar to those described under California and GDPR above, including the right to access, correct, delete, and obtain a copy of Personal Information, and the right to opt out of certain processing activities (such as sale, targeted advertising, and certain profiling). We apply these rights to residents of those states consistent with the respective state's law.

We engage in targeted advertising, as described in "Advertising" above, and some of these laws may treat it as a sale. You can opt out of targeted advertising and of any sale using the methods described in "How to Opt Out of Sale or Sharing" above. We treat Global Privacy Control as a universal opt-out mechanism where state law recognizes one.

To exercise your other rights under an applicable state law, please contact us at [email protected]. If we decline to take action on your request, you may appeal our decision by replying to our response or by emailing us with the subject "Privacy Appeal." We will respond to your appeal within the time required by your state's law and explain the result. If your appeal is denied, you may contact your state's Attorney General.

Global Privacy Control and Do Not Track

Some browsers and browser extensions communicate "Do Not Track" or "Global Privacy Control (GPC)" signals to websites. We honor GPC as a valid request to opt out of the sale and sharing of your Personal Information and of targeted advertising, for the browser that sends it. When we detect GPC, our advertising tags do not load, we remove their cookies from our website, and we do not set or read the marketing cookie described in "Cookies" above. GPC takes precedence over an earlier Accept in our cookie banner, and we do not ask you to confirm the signal.

We do not currently respond to generic Do Not Track browser signals.

Changes To This Privacy Policy

This Privacy Policy is effective as of the "Last updated" date shown at the top of this page and will remain in effect except with respect to any changes in its provisions in the future, which will be in effect immediately after being posted on this page. We reserve the right to update or change our Privacy Policy at any time and you should check this Privacy Policy periodically. Your continued use of the Service after we post any modifications to the Privacy Policy on this page will constitute your acknowledgment of the modifications and your consent to abide and be bound by the modified Privacy Policy. If we make any material changes to this Privacy Policy, we will update the "Last updated" date at the top of this page and provide any additional notice required by applicable law.

Contact Us

For privacy-related questions, to exercise a privacy right, or to make a complaint, please contact us:

  • Email: [email protected]
  • Postal mail (via our registered agent): Social Card, LLC, c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, USA

You may also reach us through our contact page.