D-Card
Privacy Policy
Effective date: 2026-08-18 Last updated: 2026-08-18 D-Card respects your privacy. This Privacy Policy describes how personal information is collected, used, disclosed, retained, and protected when you interact with:
- D-Card mobile applications
- https://d-card.io and related web properties
- Public D-Card profiles and digital cards
- Account, support, and related services operated by D-Card
This notice is an initial product draft for operational readiness. It is not a substitute for review by qualified legal counsel. We process personal data in accordance with applicable data protection laws and the practices described in this Privacy Policy. This Policy does not claim certification under GDPR, SOC 2, ISO, or similar frameworks.
1. Who We Are
D-Card operates D-Card (the "Service"). For privacy questions, requests, or grievances related to personal data:
- Privacy: privacy@d-card.io
- Registered address: Registered office details available on request at support@d-card.io
- Website: https://d-card.io Do not treat this Policy as published until entity and contact tokens are resolved and legal review is complete.
2. Scope of This Privacy Policy This
Policy applies to personal information processed in connection with:
- The D-Card iOS and Android apps
- The public website and marketing pages on https://d-card.io
- Public card and profile pages shared by link or QR code
- Account registration, authentication, and preference services
- Support tickets, feedback, and related communications Third-party websites, apps, payment processors (if introduced later), social networks, and services that you link to or open from a card are governed by their own privacy policies. D-Card is not responsible for those practices.
3. Information You Provide
Depending on how you use the Service, you may provide:
Account information Email address, phone number (where used), password (stored hashed), display name, verification status, and related account metadata.
Business and profile details Company or business name, designation/position, about text, working hours, website, and other business profile fields you choose to enter.
Digital card content Names, contact details, logos, photos, colors/template selections, social links, and other content you place on a card.
Business networks and associations Selections from the Admin-managed business networks / associations catalog that you attach to a business profile (subject to product entitlements).
Products and gallery Product names, descriptions, images, and gallery media you upload for showcase on supported surfaces.
Support and feedback Support ticket messages, attachments you upload for support, star ratings, and optional feedback text.
Referral information Referral codes, attribution links, and referral relationship metadata when you participate in referral features.
Public visibility choices Fields and content you intentionally make available on a public card or profile. Public card fields may be visible to anyone with the public link or QR code, including people who do not have the D-Card app, depending on your visibility and card settings. We do not currently operate in-app payment or billing checkout. Do not expect this Policy to describe card numbers, invoices, or purchase receipts unless paid features are later introduced and this Policy is updated.
4. Information Collected Automatically
When you use the Service, we may automatically collect:
- Device and app information (device type/OS, app version, language)
- IP address and general network metadata needed for security, abuse prevention, and reliable delivery
- Usage analytics and product events (subject to your analytics preference where the product exposes one)
- Crash and error diagnostics (for example via a configured monitoring provider when enabled)
- Security and session events (sign-in, session refresh, logout, revocation)
- Public-card interaction metadata reasonably needed to operate sharing (for example that a public card was requested)
We do not claim continuous background location tracking. See Section 5 for location specifics.
5. Location Information
D-Card distinguishes between:
Business address (user-entered) You may enter a business or contact address for display on your profile or card. That address is information you provide, not continuous device GPS tracking.
Device location (optional, limited) If you use Maps / Places-assisted address search (when that capability is enabled in the app or Admin tools), the device or map provider may process location or place-search queries only for that search experience. D-Card does not claim that it continuously tracks your device location in the background for advertising or profiling. You can typically control OS-level location permission in your device settings. Denying location permission may limit address-search convenience but should not prevent core card creation with a manually typed address.
6. Public Profile and Public Card Information
D-Card is designed so professionals can share a digital business identity. You may choose to make certain information publicly available on a card or profile. Depending on product configuration and your choices, public content may include fields such as:
- Name and designation
- Business name and logo / profile image
- Phone, email, and website
- Address and working hours
- Social links
- Products and gallery items
- Business networks / associations Anyone with a valid public URL or QR code may access that public information, including viewers who never install the app. Treat public fields as public. Search-engine indexing of public profiles, if enabled by product configuration, may make public content discoverable through search.
If indexing is disabled for a surface, that surface should not be described as indexed.
7. How We Use Information
We use personal information to:
- Create and operate accounts
- Authenticate users and verify contact information (for example OTP / verification flows)
- Create, store, render, and display digital cards and templates
- Enable QR codes, share links, and public profile viewing
- Save scanned cards and related contact relationships you create
- Send transactional email when a mail provider (such as Brevo) is configured — for example verification, password reset, security notices, and account-deletion notices
- Send push notifications when push is enabled and a device token is registered
- Provide support tickets and respond to feedback
- Maintain security, detect abuse, and enforce Acceptable Use rules
- Analyze product performance and improve the Service
- Operate referral features when enabled
- Comply with legal obligations and respond to lawful requests
We do not describe targeted third-party advertising as a current processing purpose. If advertising practices change, this Policy will be updated before those practices are presented as active.
8. Legal Bases
/ Grounds for Processing LEGAL REVIEW REQUIRED. Depending on applicable law and your relationship with us, processing may rely on one or more of the following grounds (wording subject to counsel review):
- Performance of the services you request (providing accounts, cards, sharing, support)
- Consent where we expressly request it (for example optional marketing preferences or certain optional permissions)
- Legitimate / authorized business, security, fraud-prevention, and service-improvement purposes where lawful
- Compliance with legal obligations
This section does not assert that a specific statute (for example GDPR) applies to every user worldwide. Applicable bases depend on your location and the laws that apply to D-Card.
9. Sharing and Disclosure
We may share personal information with:
- Service providers / processors that host infrastructure, send email, deliver push notifications, store media, provide maps/places search, or monitor errors — only as needed to operate the Service
- Cloud and database infrastructure providers that store application data
- Authorities when required by law, legal process, or to protect rights, safety, and security
- Business transfer parties in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards D-Card does not sell personal data as that term is commonly understood in consumer privacy laws.
If a jurisdiction uses a broader definition of "sale" or "share," counsel should confirm the precise claim before publication. When you share a public card link or QR code, the recipients (and anyone they forward it to) can view the public fields you chose to expose. That is disclosure you initiate.
10. Third-Party Service Providers
We use subprocessors only when configured for an environment. Categories that may apply when enabled include:
- Transactional email (for example Brevo, when mail delivery is enabled for that environment)
- Push delivery (for example Firebase / FCM and Apple push pathways when push is enabled)
- Object storage / CDN for media (for example AWS S3 / CloudFront when configured)
- Maps / Places providers for address search when keys are configured
- Error/diagnostics providers when monitoring is configured
- Hosting, database, cache, and DNS/CDN operators for the environments we run Public legal copy should list only providers that are active and contractually approved for that environment. An internal processing inventory is maintained for operations; it is not automatically a public guarantee. See also /cookies and /security.
11. Cookies and Similar Technologies
Our websites and Admin/Web authenticated surfaces may use cookies or similar technologies that are strictly necessary for security and session continuity, and may use preference or analytics technologies where carefully enabled. We do not invent named cookie inventories in this Policy. Details and cautious "may" language appear in our Cookie & Tracking Technologies Policy. Mobile apps primarily use local storage, secure storage, and device permissions rather than browser cookies.
12. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including security, legal, accounting, and operational requirements. Specific numeric retention periods (for account data, support tickets, analytics, security logs, backups, and soft-deleted accounts) are configuration and legal decisions. Do not treat any duration in marketing copy as binding until published here after legal approval. After an account deletion request is approved, we apply the deletion workflow described in Section 13 and on /account-deletion. Backups and security logs may persist for a limited operational period consistent with backup rotation and legal holds.
13. Account and Data Deletion
You may request deletion of your D-Card account.
How deletion works today 1. You submit a deletion request from the mobile app (see path on the Account Deletion page). 2. The request enters a PENDING state for Admin review. 3. When an Admin approves the request, the account is soft-deleted (account marked deleted) and active sessions, API keys, and push device tokens associated with the account are revoked so the account can no longer sign in or receive push to those tokens. 4. A transactional email notice may be sent when mail is configured. This is not described as an immediate full hard wipe of every historical row (cards, media, tickets, referrals, and similar records may be retained or orphaned under current product behavior unless a further purge policy is approved). For accurate user-facing steps and scope, read: https://d-card.io/account-deletion Web visitors can read instructions at `/account-deletion` without signing in; initiating deletion for an end-user account is performed in the mobile app under the current product design.
14. User Privacy Rights
Depending on applicable law, you may have rights to:
- Access personal information we hold about you
- Correct inaccurate information
- Request deletion (subject to the workflow above and legal exceptions)
- Withdraw consent where processing relies on consent
- Lodge a grievance with us using the contacts below
- Portability or objection only where those rights apply under law
We do not claim that every listed right applies to every user in every country. To exercise a privacy request, contact privacy@d-card.io. You can also manage many preferences in-app; see /privacy-choices.
15. Children
D-Card is intended for business and professional users. D-Card is not designed for children, and we do not knowingly seek to collect personal information from children in circumstances prohibited by applicable law. LEGAL REVIEW REQUIRED before publication regarding any specific age threshold or regional children's privacy statute.
16. Security
We implement reasonable technical and organizational measures designed to protect personal information, such as encrypted transport (HTTPS/TLS), hashed passwords, authenticated sessions, role-based Admin access, and operational controls described on /security. No method of transmission or storage is completely secure. We do not claim that the Service is 100% secure, military-grade, ISO-certified, or SOC 2 certified. Report suspected vulnerabilities to security@d-card.io.
17. International Data Transfers
D-Card may process and store information on infrastructure that is not located in your country of residence, depending on hosting and subprocessors configured for each environment. We do not claim that all data remains in a single country unless that residency is verified for the relevant environment and reflected here after review. Where required by law, appropriate transfer safeguards will be addressed in contracts and this Policy after legal review.
18. Changes to This Policy We may update this Privacy Policy from time to time. Material changes may be communicated through the app, email, website notice, or other appropriate channels. The
Effective date and Last updated values at the top of this page will change when a revised version is published. Continued use of the Service after an update becomes effective means you acknowledge the revised Policy, except where applicable law requires a different mechanism (for example affirmative consent for certain changes).
19. Contact
/ Grievance
- Privacy: privacy@d-card.io
- Support: support@d-card.io
- Security: security@d-card.io
- Legal: legal@d-card.io
- Grievance Officer: Grievance Officer — privacy@d-card.io
- Entity: D-Card
- Address: Registered office details available on request at support@d-card.io
- Website: https://d-card.io
- Account deletion help: https://d-card.io/account-deletion
If a Grievance Officer is required for your jurisdiction, use the configured officer contacts above once those tokens are populated.