Privacy Policy
Last updated August 18, 2026
This policy explains what personal data NimiCard handles, why, and the choices you have. It is maintained by the NimiCard team and applies to the NimiCard website, dashboard and public card pages.
Who this covers
We handle data for two groups: account holders who create digital business cards, and visitors who open a public card. Card owners decide what appears on their own card and act as the controller of the leads they receive.
Data we collect from account holders
- Account data: email address, and name or avatar if you sign in with Google.
- Card content you enter: name, job title, company, biography, contact details, links, and any images or documents you upload.
- Usage data needed to run the product, such as which cards exist and when they were last updated.
Data we collect from card visitors
Viewing a card does not require an account. We record privacy-friendly engagement events — page views, QR or NFC visits, contact saves, shares, and taps on buttons such as call, email or website — so the card owner can see what is working.
- We do not sell visitor data or use it for advertising.
- A random identifier is stored in your browser to estimate unique visitors. It is one-way hashed with a server-side secret before it is stored, and it is not linked to your identity.
- Personal details are only recorded when you voluntarily submit the contact exchange form and tick the consent box.
Lead exchange forms
When you submit the form on a card, the details you enter (name, email, mobile, company, job title and message) are sent to that card owner and stored in their contact list. The card owner is responsible for how they use those details. Contact them directly, or write to us through our contact form and we will pass the request on.
Business-card scanning
Business-card scanning is optional and runs only after you accept a short, versioned consent. That consent is stored against your account and remembered, so you are not asked on every scan. You can revoke it at any time in Settings, and we ask again if the terms change. When consent is active, the cropped card image and the visible contact details on it are sent to OpenAI for extraction. We do not intentionally persist the image or the raw extraction: only the lead fields you review and keep are saved when you press Save. We record a minimal consent entry containing your account id, the scan id, the consent version, the purpose, the timestamp and the workspace scope — no image, no contact data. Revoking consent disables card scanning until you accept again; adding leads manually remains available.
By default, data sent through the OpenAI API is not used to train their models unless the API account owner opts in. OpenAI may retain API content for up to 30 days for abuse monitoring under their default policy.
How we use data
- To create, host and display your digital business card.
- To authenticate you and keep your account secure.
- To show engagement analytics to the card owner.
- To respond to support requests.
- To detect abuse, spam and fraudulent activity.
Setting up your card
While you are setting up your card, NimiCard saves your progress automatically so you can stop and continue later. Until you choose to publish, that card is a private draft: it is not reachable at a public link, is not included in QR codes, vCards or search engines, and collects no visitor analytics.
We also record simple setup milestones for your account — for example that setup was started, which step was reached, that a card was published and that it was shared for the first time. These are used to improve the setup experience and are reported to our team only as aggregate totals, never as an individual profile.
Contacting NimiCard
When you contact NimiCard through our Contact & Support form, we may collect the name, email address, subject, topic and message you provide. We may also record limited request information such as the page the request came from, app release and general device category where available.
We use this information to respond to your request, provide account or technical support, investigate privacy or security concerns, prevent abuse or spam, and improve NimiCard where appropriate.
Contact and support inquiries are available only to authorized NimiCard support personnel through our protected support workspace.
If you are signed in, your request may appear in your NimiCard support history so you can continue the conversation from your dashboard.
Sharing and processors
We do not sell personal data. We use infrastructure providers to run the service — application hosting, the managed PostgreSQL database, authentication and file storage. They process data on our instructions only. Google is involved solely when you choose Google sign-in. OpenAI processes card images and visible contact details only when you use the optional Enhanced Scan feature and your Enhanced Scan consent is active.
NimiCard uses technology and infrastructure providers, including Lovable, to operate the service. Lovable maintains recognized security and information-security controls, including SOC 2 Type II and ISO 27001:2022. These certifications apply to Lovable, not independently to NimiCard.
Data-processing arrangements with our technology providers support our privacy and security obligations.
Public information
Anything you place on a published card is public by design and can be indexed by search engines. Set a card to draft, or remove a field, if you do not want it public.
Retention
Card content and leads are kept while your account is active. Delete a card to remove its content, leads and analytics. Ask us to close your account and we will delete the associated personal data, except where we must keep records to comply with law.
Your rights
Depending on where you live, you may request access, correction, deletion, export, or object to certain processing. Most of this is self-service in your dashboard. For anything else, write to us through our contact form and we will respond within a reasonable period.
Children
NimiCard is a professional networking tool and is not intended for under-16s.
Changes and contact
We will update this page when our practices change and revise the date above. Questions about privacy can be sent through our contact form.
This document is written and maintained by the NimiCard team. It has not been reviewed or approved by a qualified lawyer, and a final legal review is still recommended before relying on it. Questions can be sent through our contact form.