Privacy Policy

How Cardigo collects, uses, and protects your information across our website, web app, and mobile apps.

Last updated: August 5, 2026

1. Introduction

Cardigo ("we", "us", or "our") operates the Cardigo digital networking platform, including the website at https://cardigoapp.com, the web application at https://app.cardigoapp.com, and our iOS and Android mobile applications (collectively, the "Service"). This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and the choices you have.

By creating an account or using the Service, you acknowledge that you have read this Privacy Policy. If you do not agree, please do not use Cardigo.

2. Information we collect

We collect information you provide directly, information generated through your use of the Service, and limited technical data needed to operate and secure the platform.

  • Account data: name, email address, password (stored in hashed form), and authentication tokens.
  • Profile data: photo, job title, company, phone number, biography, social links, branding preferences, and public share slug.
  • Contact data: people you save through QR scans, handshake exchange, event mode, manual entry, or business card OCR.
  • Usage and analytics: profile views, scans, connection events, and in-app actions related to networking features.
  • Uploaded content: avatars, company logos, and branding assets you choose to store in Cardigo.
  • Device and app data: device type, operating system, app version, and diagnostic logs when needed to troubleshoot issues.
  • Camera and media access (with your permission): used for QR scanning, business card OCR, and profile photo uploads on mobile and web.
  • NFC data (with your permission): used only to exchange digital business card information when you initiate a tap exchange.

3. How we use your information

  • Provide, maintain, and improve the Service, including digital cards, sharing, scanning, contacts, events, and analytics.
  • Authenticate you and keep your account secure.
  • Display your public profile when someone visits your Cardigo link or scans your QR code.
  • Process OCR requests to extract contact details from business card images you submit.
  • Generate Apple Wallet and Google Wallet passes when you request them.
  • Send transactional messages such as verification codes, security alerts, and service notices.
  • Respond to support requests and enforce our Terms of Service.
  • Analyze aggregated usage trends to improve product performance and reliability.

5. How we share information

We do not sell your personal information. We share data only as described below:

  • Public profile sharing: information you mark as visible on your digital card may be viewed by anyone with your link, QR code, or NFC exchange.
  • Other users: when you exchange contacts or save a connection, relevant profile fields are shared according to the feature you use.
  • Service providers: infrastructure and hosting (including Supabase for database, authentication, and storage), analytics, email delivery, and wallet pass generation partners that process data on our instructions.
  • Legal and safety: when required by law, court order, or to protect the rights, safety, and integrity of Cardigo, our users, or the public.
  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to continued protection of your information.

6. Data retention

We retain personal data for as long as your account is active or as needed to provide the Service. You may delete your account or specific content where the product supports it. We may retain certain records for a limited period to comply with legal obligations, resolve disputes, enforce agreements, and maintain security backups.

7. Security

We use administrative, technical, and organizational measures designed to protect your information, including encrypted transport (HTTPS), access controls, and industry-standard authentication practices. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. International transfers

Cardigo may process and store information in countries other than your own through our service providers. Where required, we use appropriate safeguards for cross-border transfers.

9. Your rights and choices

Depending on your location, you may have the right to access, correct, delete, restrict, or port your personal data, and to object to or withdraw consent for certain processing. You can update much of your profile information in the app. To exercise other rights, contact us at the address below.

  • Access and correction via profile settings in the web or mobile app.
  • Account deletion by contacting support or using in-product deletion tools when available.
  • Marketing emails: use unsubscribe links where provided.
  • Device permissions: manage camera, photos, and NFC access in your device settings.

10. Children

Cardigo is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will take appropriate steps to delete it.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date. Material changes may be communicated by email or in-app notice where appropriate.

12. Contact us

Privacy questions or requests: privacy@cardigoapp.com. General support: hello@cardigoapp.com.