Skip to main content

Legal

Privacy Policy

Last updated April 17, 2026

Social Card, LLC, a Delaware limited liability company ("us", "we", or "our"), operates: (a) the Social Card websites, including joinsocialcard.com, socard.me, and app.joinsocialcard.com (the "Site"); (b) the Social Card mobile application for iOS (the "App"); (c) digital business card passes delivered through Apple Wallet and Google Wallet (the "Wallet Passes"); and (d) related products, features, and services (collectively with the Site, the App, and the Wallet Passes, the "Service"). This page informs you of our policies regarding the collection, use, and disclosure of Personal Information we receive from users of the Service. By using the Service, you agree to the collection and use of information in accordance with this policy.

Information Collection And Use

While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you. Personally identifiable information may include but is not limited to your name, company name, billing information, billing address, phone number, or email ("Personal Information"). The categories of Personal Information we collect, the sources from which we collect it, and how we use it are described in the sections below.

Categories of Personal Information We Collect

We collect the following categories of Personal Information. These categories align with those defined in the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and other applicable U.S. state privacy laws.

  • Identifiers. Name, email address, phone number, account username, IP address, device identifiers (such as Apple ID when you use Sign in with Apple, device advertising identifiers, and Identifier for Vendor), and similar identifiers.
  • Commercial Information. Records of products or subscriptions purchased, obtained, or considered, and other purchase or usage histories.
  • Internet or Other Electronic Network Activity Information. Information regarding your interaction with the Site and App, and information regarding interactions with digital business cards and links shared through our link and webpage analytics features.
  • Geolocation Data. Approximate geolocation derived from IP address. We do not collect precise (GPS-level) geolocation data.
  • Professional or Employment-Related Information. Job title, company name, role, and similar information that you include on your digital business card or that is extracted from business cards you scan.
  • Audio, Visual, and Similar Information. Images of paper business cards or conference badges captured through the card scanning feature; profile photos; and company logos.
  • Inferences. Inferences drawn from the above to support product features and analytics.

We do not knowingly collect Sensitive Personal Information as defined under CCPA/CPRA (such as Social Security numbers, precise geolocation, racial or ethnic origin, religious beliefs, genetic data, or biometric identifiers used for identification).

Sources of Personal Information

We collect Personal Information directly from you (when you create an account, complete a digital business card, make a purchase, or submit information through the Service), automatically from your device and browser (when you use the Service), and from third parties such as identity providers (for example, Sign in with Apple) when you elect to use them to access the Service.

How We Use Information

We use Personal Information for the following purposes:

  • To provide and maintain the Service, including creating and managing your account, displaying your digital business card, processing card scans, and delivering Wallet Passes.
  • To process payments and manage subscriptions through our payment processors.
  • To communicate with you about the Service, including service announcements, security alerts, billing, and customer support responses.
  • To send marketing communications about Social Card products and features, subject to your preferences and applicable law.
  • To analyze usage and improve the Service, including measuring feature adoption, diagnosing technical issues, and developing new features.
  • To detect, prevent, and address security issues, fraud, abuse, and violations of our Terms of Service.
  • To comply with legal obligations, respond to lawful requests, and enforce our rights.

Information We Share

We do not sell Personal Information, and we do not share Personal Information for cross-context behavioral advertising. We may disclose Personal Information in the following limited circumstances:

  • Service Providers and Sub-Processors. We share Personal Information with third parties that perform services on our behalf, such as cloud hosting, payment processing (Stripe), banking and invoicing (Mercury), AI-based card scanning (Google Gemini), analytics, customer support, email delivery, and authentication (Apple Sign In). A current list is maintained on our Sub-Processors page.
  • Recipients of Digital Business Cards. Information you include on your digital business card is shared with recipients you designate, and with anyone you make the card public to.
  • Business Customers and Administrators. If you access the Service through an employer or organization, your account administrators may have access to your account information, usage, and any content associated with your account.
  • Legal and Safety. We may disclose Personal Information where required by law, in response to lawful requests from government authorities, to enforce our rights, or to protect the safety of our users or the public.
  • Business Transfers. In the event of a merger, acquisition, reorganization, financing, or sale of all or a portion of our assets, Personal Information may be transferred as part of that transaction. We will notify affected users of any such transfer and any material changes to privacy practices.

Business Card Scanning

When you use the card scanning feature in our App, images of paper business cards or conference badges are captured using your device's camera or photo library. These images are sent to our servers and processed using a third-party AI service to extract contact information such as name, company, phone number, email, and job title.

We currently use Google Gemini as our AI model provider for card scanning. Under Google's terms for the paid Gemini API that we use, card image data submitted through Social Card is not used to train Google's AI models. Card images and extracted data are processed for the purpose of providing the scanning feature only.

Card images are stored within your account so you can reference them later alongside the extracted contact data. Extracted contact information is saved within your Social Card account and may optionally be saved to your device's contacts.

You are responsible for ensuring that you have an appropriate legal basis (such as legitimate interest in the ordinary course of professional contact exchange) to store contact information from cards you scan. Individuals whose cards you scan may have rights under applicable law to access, correct, or request deletion of their information, which you should honor as a data controller with respect to that information.

For a complete list of third-party services that process data on our behalf, see our Sub-Processors page.

Public-Facing Data

Social Card allows users to create digital business cards that are intended to be shared publicly. By using our services, you acknowledge and agree to the following terms regarding public-facing data:

User Choice and Control

  • Voluntary Disclosure: The information you include on your digital business card (e.g., name, contact details, company information) is provided voluntarily by you. You have complete control over what information to include.
  • Public Sharing: Digital business cards are designed to be shared publicly. This means that when you share your business card via email, social media, QR codes, or any other method, the information on the card becomes accessible to the recipient and potentially to the public at large.

Transparency and User Rights

  • Clear Information: We inform all users that the information included on their business cards will be public when shared. It is the user's responsibility to ensure that they are comfortable with sharing this information publicly.
  • Data Management: You can update, modify, or delete the information on your business card at any time through your account settings. This ensures that you retain control over your personal data.

Security Measures

  • Data Protection: While we facilitate the sharing of business card information, we implement security measures to protect against unauthorized access or misuse of the data. This includes encryption, secure access controls, and regular security audits.
  • Monitoring and Response: We monitor our platform for any potential misuse of public-facing data. If misuse is detected, we take appropriate action to mitigate any risks and protect user data.

Social Card provides analytics to users about interactions with their digital business cards, shared links, and landing pages (for example, view counts, click counts, approximate location derived from IP, referring source, user agent, and timestamps). This information is made available to the Social Card user whose card, link, or page was accessed.

If you interact with a Social Card digital business card, link, or page, the user who shared it may see engagement data about your interaction. This information is used to provide analytics to Social Card users and is not associated with any broader advertising profile.

Log Data

Like many operators, we collect information that your browser or device sends whenever you access our Service ("Log Data"). Log Data may include your Internet Protocol ("IP") address, browser type, browser version, device type, operating system, the pages of our Site that you visit, the time and date of your visit, the time spent on those pages, and other statistics. We may use third-party analytics services to collect, monitor, and analyze this data. A current list of such services is maintained on our Sub-Processors page.

Mobile Device Information

When you use the App on iOS, we may automatically collect the following device-level information:

  • Device identifiers, such as Identifier for Vendor (IDFV). We do not currently track users across apps or websites owned by other companies, and we do not collect the Identifier for Advertisers (IDFA). If we introduce tracking features in the future, we will do so only after obtaining your explicit consent through Apple's App Tracking Transparency (ATT) framework.
  • Device model, operating system version, and mobile network information.
  • Push notification tokens, used to deliver push notifications if you have enabled them.
  • Crash and performance diagnostics collected by our mobile analytics and crash reporting providers to help us diagnose issues and improve App stability.

Sign in with Apple

If you elect to sign in using Sign in with Apple, Apple transmits to us limited information associated with your Apple ID, which may include your name and an email address (or a private relay email address forwarded by Apple). We use this information solely to create and authenticate your Social Card account. Apple's privacy practices for Sign in with Apple are governed by Apple's own privacy policy.

App Permissions

The App may request the following device permissions. You may grant or deny each permission and may change your choices at any time in your device settings.

  • Camera and Photo Library — used only for the card scanning feature, to capture or import images of paper business cards or conference badges.
  • Notifications — used to deliver push notifications if you have enabled them.
  • Contacts (optional) — used only if you choose to save extracted card contacts to your device's contacts.

We do not request or collect: biometric identifiers (Face ID and Touch ID authentication occurs locally on your device and we do not receive the biometric data), Bluetooth, NFC, precise geolocation, or SMS permissions.

Communications

We may use your Personal Information to contact you with transactional communications (such as service announcements, security alerts, billing notices, and customer support responses) and, subject to your preferences and applicable law, marketing communications about Social Card products and features. You may opt out of marketing communications at any time by following the unsubscribe link in the email or by contacting us at [email protected]. Transactional communications are necessary to operate the Service and are not subject to opt-out.

Cookies

We use cookies and similar tracking technologies on our Site. Cookies are small files placed on your device that store information.

The cookies we use fall into the following categories:

  • Strictly Necessary Cookies — required to operate the Site and provide basic features such as authentication and session management. These cookies cannot be disabled without breaking Site functionality.
  • Functional Cookies — remember your preferences and settings to enhance your experience.
  • Analytics Cookies — help us understand how visitors use the Site so we can improve it. Set only with your consent where required by law.
  • Marketing Cookies — used to deliver relevant content and measure the effectiveness of our marketing campaigns. Not currently in use; if we enable them in the future, we will do so only with your consent where required by law.

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept strictly necessary cookies, some portions of the Service may not function properly. Where required by applicable law (such as in the European Economic Area, the United Kingdom, and California when applicable), we obtain consent before setting non-essential cookies through our cookie consent banner.

Security

The security of your Personal Information is important to us. We implement technical and organizational measures, including encryption of data in transit and at rest, access controls, and ongoing security monitoring, to protect Personal Information. However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Information, we cannot guarantee its absolute security.

Data Retention

We retain Personal Information for as long as your account is active or as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Specific retention periods are as follows:

  • Account and profile data — retained while your account is active. Deleted from active systems promptly upon account deletion.
  • Digital business card and contact data — retained while associated with an active account. Deleted promptly upon account deletion or when you delete the specific item.
  • Scanned business card images — retained while the associated contact exists in your account. Deleted when you delete the contact, delete your account, or request deletion.
  • Billing and tax records — retained for at least seven (7) years as required by U.S. tax and accounting regulations, even after account deletion.
  • Backups — residual copies in our backup systems may persist for up to ninety (90) days after deletion from active systems, after which they are overwritten in the normal course of backup rotation.
  • Analytics and log data — log data in identified form is retained for up to twenty-four (24) months, after which it is aggregated or deleted. Certain analytics events and system log entries may persist after account deletion in aggregated or otherwise non-identifiable form that cannot reasonably be used to identify you as an individual.

Account Deletion

You may delete your account at any time. If you are using the iOS App, deletion is available from within the App. For accounts created through our other products, you may request deletion by contacting us at [email protected]. Account deletion is irreversible, subject to the retention periods listed above for billing, tax, and backup records.

International Data Transfers

Social Card is based in the United States, and the Service is operated from the United States. If you access the Service from outside the United States, your Personal Information may be transferred to, stored, and processed in the United States and other countries where our service providers operate.

For transfers of Personal Information from the European Economic Area, the United Kingdom, or Switzerland to the United States, we rely on appropriate safeguards, which may include the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum. Social Card is not currently certified under the EU-U.S. Data Privacy Framework; however, certain of our service providers may be certified under that framework and may rely on their own certification as an additional transfer mechanism. For more information or to request copies of the safeguards we rely on, please contact us at [email protected].

Children's Privacy

The Service is not directed at children under the age of 13 (or the applicable minimum age for consent to the processing of personal data in your jurisdiction, which may be higher, such as 16 in the European Economic Area). We do not knowingly collect Personal Information from children under the applicable minimum age.

If you are a parent or legal guardian and you believe that your child has provided us with Personal Information, please contact us at [email protected] and we will take steps to delete the information and terminate the child's account.

Your Rights Under the GDPR and UK GDPR

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights with respect to your Personal Information under the GDPR, UK GDPR, and Swiss Federal Act on Data Protection:

  • Right of access — to request a copy of the Personal Information we hold about you.
  • Right to rectification — to request correction of inaccurate or incomplete Personal Information.
  • Right to erasure ("right to be forgotten") — to request deletion of your Personal Information, subject to certain legal exceptions.
  • Right to restrict processing — to request that we limit how we process your Personal Information in certain circumstances.
  • Right to data portability — to receive your Personal Information in a structured, commonly used, machine-readable format and to transmit it to another controller.
  • Right to object — to object to our processing of your Personal Information based on legitimate interests or direct marketing.
  • Right to withdraw consent — where we rely on consent as a legal basis, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
  • Right not to be subject to automated decision-making — you have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not engage in such automated decision-making.
  • Right to lodge a complaint — you have the right to lodge a complaint with the data protection authority in your country of residence, place of work, or place of the alleged infringement.

To exercise any of these rights, please contact us at [email protected]. We will respond within thirty (30) days, or as otherwise required by applicable law.

We process Personal Information under the following legal bases:

  • Contractual necessity — to provide and operate the Service, including creating and managing your account, hosting your digital business card, processing card scans you submit, delivering Wallet Passes, and providing other features you have requested.
  • Consent — for marketing communications, non-essential cookies, and any other processing that relies on consent under applicable law. You may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
  • Legitimate interests — for analytics, security, fraud prevention, service improvement, and, in the case of the card scanning feature, the processing of third-party contact information extracted from business cards you scan, on the basis that business cards are voluntarily distributed for the purpose of contact exchange.
  • Legal obligation — to comply with applicable laws, including tax, accounting, and legal process requirements.

EU and UK Representative

Social Card is a small, U.S.-based business that operates the Service from the United States. Social Card does not maintain an establishment in the European Union or the United Kingdom, prices the Service in U.S. Dollars, and does not conduct marketing, advertising, or solicitation activities specifically targeted at residents of the European Union or the United Kingdom.

Social Card acknowledges that residents of the European Economic Area, the United Kingdom, and Switzerland may access and use the Service, and Social Card is committed to respecting applicable rights under the GDPR, the UK GDPR, and the Swiss Federal Act on Data Protection with respect to Personal Information of such residents.

Social Card has not at this time designated a representative under Article 27 of the GDPR or the UK GDPR, and is continuing to evaluate whether such designation is required based on the nature and scale of its processing activities and the degree to which the Service may be deemed to be offered to data subjects in the European Union or the United Kingdom. Social Card will designate a representative and update this Privacy Policy if and when required.

For questions or requests concerning Personal Information of EU, UK, or Swiss residents — including requests to exercise any of the rights described above, or to lodge a complaint — please contact us at [email protected]. Social Card will respond to such requests within the timelines required by applicable law and, where we are unable to fulfill a request, will explain the basis for our determination and advise you of your right to lodge a complaint with your local supervisory authority.

Data Processing Agreement (DPA)

If you are a business customer of Social Card and you are based in the EU, UK, or otherwise process Personal Data of EU or UK residents, our Data Processing Agreement governs our processing of such data on your behalf.

Your California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you specific rights regarding your Personal Information. This section applies to Personal Information collected about California residents.

Categories of Personal Information Collected, Sources, Uses, and Disclosures

The categories of Personal Information we collect, the sources from which we collect it, the purposes for which we use it, and the categories of third parties to whom we disclose it are described above in "Categories of Personal Information We Collect," "How We Use Information," and "Information We Share."

Sale and Sharing of Personal Information

We do not "sell" Personal Information as that term is defined by the CCPA/CPRA, and we do not "share" Personal Information for cross-context behavioral advertising as that term is defined by the CPRA. We have not sold or shared Personal Information in the preceding twelve (12) months, and we do not sell or share Personal Information of consumers under the age of 16.

Your California Rights

Subject to certain exceptions, California residents have the following rights:

  • Right to Know — to request that we disclose the specific pieces and categories of Personal Information we have collected about you, the sources of that information, the purposes for collecting it, and the categories of third parties with whom we share it.
  • Right to Delete — to request that we delete Personal Information we have collected from you.
  • Right to Correct — to request that we correct inaccurate Personal Information we maintain about you.
  • Right to Opt Out of Sale or Sharing — because we do not sell or share Personal Information, there is no "Do Not Sell or Share My Personal Information" link or process to opt out. If our practices change, we will update this Privacy Policy and provide the required opt-out mechanism.
  • Right to Limit Use of Sensitive Personal Information — because we do not use Sensitive Personal Information for purposes beyond those permitted by the CPRA, there is no additional limit-use process.
  • Right to Non-Discrimination — we will not discriminate against you for exercising any of your California privacy rights.

How to Exercise Your California Rights

To exercise any of these rights, please contact us at [email protected]. We will verify your request using reasonable means (such as matching identifiers you provide to information we have on file). You may designate an authorized agent to submit a request on your behalf by providing written authorization and verifying your identity with us directly. We will respond within forty-five (45) days and may extend our response period by an additional forty-five (45) days when reasonably necessary.

Shine the Light

California Civil Code Section 1798.83 permits California residents who have an established business relationship with Social Card to request certain information regarding our disclosure of Personal Information to third parties for those third parties' own direct marketing purposes. We do not disclose Personal Information to third parties for their own direct marketing purposes.

Other U.S. State Privacy Rights

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Delaware (DPDPA), Tennessee (TIPA), and other U.S. states with comprehensive privacy laws may have rights similar to those described under California and GDPR above, including the right to access, correct, delete, and obtain a copy of Personal Information, and the right to opt out of certain processing activities (such as sale, targeted advertising, and certain profiling). We apply these rights to residents of those states consistent with the respective state's law.

To exercise your rights under an applicable state law, please contact us at [email protected].

Global Privacy Control and Do Not Track

Some browsers and browser extensions communicate "Do Not Track" or "Global Privacy Control (GPC)" signals to websites. Where required by law (such as under the CPRA for California residents), we honor GPC signals as valid opt-out-of-sale and opt-out-of-sharing requests. Because we do not sell or share Personal Information for cross-context behavioral advertising, these signals do not change our current practices; we will continue to honor them if our practices change.

We do not currently respond to generic Do Not Track browser signals.

Changes To This Privacy Policy

This Privacy Policy is effective as of April 17, 2026 and will remain in effect except with respect to any changes in its provisions in the future, which will be in effect immediately after being posted on this page. We reserve the right to update or change our Privacy Policy at any time and you should check this Privacy Policy periodically. Your continued use of the Service after we post any modifications to the Privacy Policy on this page will constitute your acknowledgment of the modifications and your consent to abide and be bound by the modified Privacy Policy. If we make any material changes to this Privacy Policy, we will notify you either through the email address you have provided us or by placing a prominent notice on our website.

Contact Us

For privacy-related questions, to exercise a privacy right, or to make a complaint, please contact us:

  • Email: [email protected]
  • Postal mail (via our registered agent): Social Card, LLC, c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, USA

You may also reach us through our contact page.