Privacy policy

2026-09-01

PLACEHOLDER operates bcards, a digital business card service. This policy sets out what we process, why, for how long, and how to have it deleted.

Two kinds of people

bcards handles data about two distinct groups, under different rules.

  • Account holders: people who create a card. They have an account, a password and direct access to their own data.
  • Visitors who leave their details: people who never signed up and cannot log in to find their record. The "Your rights" section is written for them.

Account holder data

Name, email address, password (stored as a hash, never in clear text), interface language, and whatever you publish on your cards: headline, bio, links, images, sections.

Legal basis: performance of our contract with you. Without this the service cannot work.

Retention: until you delete your account, which you can do yourself from Settings.

Details captured through a card's form

When someone fills in the "Share your details" form on a card, we record what they entered — name, email, phone, company, message — along with the moment they consented and the exact version of the notice they were shown.

Those details go to the holder of that one card. They are never sold, never pooled across cards, and never used for advertising.

Legal basis: consent, given explicitly through a tick box that is never pre-ticked.

Retention: the window is set by the card's holder and copied onto the record at the moment of capture. Changing that setting later therefore cannot extend a window already communicated. When the window expires the record is permanently deleted — no copy, no tombstone.

Where no window has been set, the record is kept until deleted by hand or on request.

Visit statistics

We count views, QR scans, contact-file downloads and captured details, per card and per day.

No IP address is stored anywhere. To avoid counting the same person twice in a day, the address is put through a one-way function combining a salt that is regenerated daily and a secret key. The result is scoped to the card, so the same person produces a different fingerprint on two different cards and browsing cannot be reconstructed across them.

The day's salt is deleted after two days. From that point the fingerprint can no longer be recomputed from an address, by us or by anyone else: the link is permanently broken.

What remains is aggregate counters, which relate to no identifiable person.

Cookies

bcards sets a session cookie when you sign in. It is strictly necessary to operate the service and therefore requires no consent.

We use no advertising cookies, no third-party trackers and no external analytics. Public card pages set no cookie at all unless you are signed in.

Embedded content

A card may embed a video or other content hosted by a third party. When it does, your browser connects directly to that third party, which may set its own cookies and will see your IP address. That connection is outside our control and is governed by the third party's own privacy policy.

Only providers on a closed list can be embedded, and the URL actually loaded is rebuilt by us from a resource identifier: an address typed by a user never reaches a display frame.

Images

Uploaded images are reprocessed on the server. EXIF metadata is stripped, which includes the GPS coordinates phones write into photographs. Orientation is applied before stripping, so the image still displays the right way up.

Where the data is and who reaches it

The application and its database are hosted by Railway Corporation / Cloudflare R2, in Amsterdam, Netherlands (EU). Uploaded files are stored in a bucket created with European Union jurisdiction.

We use a transactional email provider, which processes the recipient's address and the message content on our behalf and on our instructions only.

No data is sold, rented or passed on for commercial purposes. Disclosure happens only on a lawful demand from an authority entitled to make one.

Your rights

You have the right of access, rectification, erasure, portability and objection.

If you have an account: Settings lets you export everything we hold about you as a readable file, and delete your account. Deletion is immediate and permanent.

If you only left your details on someone's card: the "Deletion request" page gets your record erased without creating an account. You enter the email or phone number you gave; if we hold a matching record, a single-use confirmation link is sent to the email address on that record — never to an address typed into the form, which would otherwise let anyone have someone else's data deleted by guessing.

If the record we hold carries no email address, we have no safe way to reach you: contact the card's holder directly, or write to us.

For any question, or to exercise a right in writing: PLACEHOLDER.

You may also complain to the Instance Nationale de Protection des Données Personnelles (INPDP) in Tunisia, or to the supervisory authority where you live.

Security

Traffic is encrypted in transit. Passwords are stored as hashes. Access is partitioned by workspace and by role, and every privileged action is written to an audit log.

Uploaded files are checked on their actual bytes rather than their name or declared type; formats that can carry script are refused.

Changes

The date this wording last changed is shown at the top of this page. The notice displayed in the capture form is versioned separately, and every record keeps the version actually shown to the person: a later revision of our text cannot retroactively count as consent.