Privacy Policy
Last updated 08 Aug 2026 · Applies to CardLink and every card published through it.
This policy explains what personal information CardLink collects, why we hold it, who can see it, and what you can ask us to do with it. It is written in plain language on purpose.
1. Who is responsible for your information
Two different parties handle information here, and it matters which is which:
- Your organisation decides what goes on its cards and who is on its team. For that information, your organisation is the controller and we act on its instructions.
- We operate the service itself — accounts, sign-in, billing records and security logs. For that, we are the controller.
If you want your details changed or removed from a card, the fastest route is your own organisation's administrator. If they cannot help, contact us at support@cloud-novasolutions.com.
2. What we collect
| Category | Examples | Why |
|---|---|---|
| Account details | Name, work email, hashed password, role | To create your account and decide what you are allowed to do |
| Card content | Job title, phone numbers, address, website, photo, links | This is the information your card exists to share |
| Organisation details | Organisation name, logo, colours, country, timezone, currency | To brand your cards and show dates and prices correctly |
| Usage records | Card views and saves, with date, referring site and browser family | So you can see whether your card is being used |
| Security records | Sign-in attempts, IP address, audit log of administrative actions | To detect misuse and to show your administrators who changed what |
We do not collect special-category information (health, beliefs, biometrics), we do not buy personal information from data brokers, and we do not run third-party advertising or analytics scripts on this site.
3. A note about people who scan your card
When somebody scans a card, we record that a view happened — the date, the browser family, and the site that referred them if there was one. We do not ask who they are, we do not require them to have an account, and we do not build a profile of them. The contact details they save go straight into their own phone; they are never sent to us.
4. Why we are allowed to hold it
- Contract — we cannot provide the service without your account and card details.
- Legitimate interests — keeping the service secure, preventing abuse, and keeping records of administrative changes.
- Consent — for anything optional; you can withdraw it at any time.
- Legal obligation — where we are required to keep records.
5. Who we share it with
Card content is public by design: a published card is intended to be opened by anyone holding its link or QR code. Everything else is shared only with:
- other people in your own organisation, according to their role;
- our hosting and email providers, who process data on our instructions only;
- an authority where we are legally required to, and where we are permitted to tell you, we will.
We do not sell personal information. There is no arrangement under which we could.
6. Where it is stored
Data is stored on our hosting provider's infrastructure. Because the internet is not regional, information may be processed outside your country. Where that happens we rely on the provider's contractual data-protection terms.
7. How long we keep it
- Account and card data — while your workspace is open.
- Deleted workspace — removed from the live database immediately; backups roll off within 30 days.
- Analytics — kept as a rolling history so you can compare periods.
- Security and audit records — kept longer than ordinary data, because a log you delete on request is not evidence.
- Failed sign-in attempts — pruned automatically.
8. Your rights
You can ask us to:
- Show you what we hold — signed-in owners and administrators can export the whole workspace as JSON from Settings → Account without asking anyone.
- Correct anything wrong — most fields are editable directly.
- Delete your account, or the entire workspace if you own it.
- Object to a particular use, or ask us to restrict it.
- Complain to your national data-protection authority.
We answer requests within 30 days and we do not charge for them.
9. How we protect it
- Passwords are stored as bcrypt hashes. Nobody — including us — can read them.
- Every request is scoped to one organisation at the database layer; a query that loses its organisation context fails rather than returning everyone's rows.
- Sign-in attempts are rate-limited, and forms are protected against cross-site request forgery.
- Administrative actions are written to an audit log your owners can read.
- Uploads are validated by actual image content, not by file name.
No system is perfectly secure. If a breach affects you, we will tell you and the relevant authority as required by law.
10. Children
This is a workplace product and is not directed at children. We do not knowingly create accounts for anyone under 16.
11. Changes
If we change this policy we will update the date at the top, and for anything significant we will tell account holders by email before it takes effect.
12. Contact
support@cloud-novasolutions.com