Privacy Policy

Last updated February 2026

This policy explains what personal data NimiCard handles, why, and the choices you have. It is maintained by the NimiCard team and applies to the NimiCard website, dashboard and public card pages.

Who this covers

We handle data for two groups: account holders who create digital business cards, and visitors who open a public card. Card owners decide what appears on their own card and act as the controller of the leads they receive.

Data we collect from account holders

  • Account data: email address, and name or avatar if you sign in with Google.
  • Card content you enter: name, job title, company, biography, contact details, links, and any images or documents you upload.
  • Usage data needed to run the product, such as which cards exist and when they were last updated.

Data we collect from card visitors

Viewing a card does not require an account. We record privacy-friendly engagement events — page views, QR or NFC visits, contact saves, shares, and taps on buttons such as call, email or website — so the card owner can see what is working.

  • We do not sell visitor data or use it for advertising.
  • A random identifier is stored in your browser to estimate unique visitors. It is one-way hashed with a server-side secret before it is stored, and it is not linked to your identity.
  • Personal details are only recorded when you voluntarily submit the contact exchange form and tick the consent box.

Lead exchange forms

When you submit the form on a card, the details you enter (name, email, mobile, company, job title and message) are sent to that card owner and stored in their contact list. The card owner is responsible for how they use those details. Contact them directly, or write to us at mattobial@gmail.com and we will pass the request on.

How we use data

  • To create, host and display your digital business card.
  • To authenticate you and keep your account secure.
  • To show engagement analytics to the card owner.
  • To respond to support requests.
  • To detect abuse, spam and fraudulent activity.

Sharing and processors

We do not sell personal data. We use infrastructure providers to run the service — application hosting, the managed PostgreSQL database, authentication and file storage. They process data on our instructions only. Google is involved solely when you choose Google sign-in.

Public information

Anything you place on a published card is public by design and can be indexed by search engines. Set a card to draft, or remove a field, if you do not want it public.

Retention

Card content and leads are kept while your account is active. Delete a card to remove its content, leads and analytics. Ask us to close your account and we will delete the associated personal data, except where we must keep records to comply with law.

Your rights

Depending on where you live, you may request access, correction, deletion, export, or object to certain processing. Most of this is self-service in your dashboard. For anything else, email mattobial@gmail.com and we will respond within a reasonable period.

Children

NimiCard is a professional networking tool and is not intended for under-16s.

Changes and contact

We will update this page when our practices change and revise the date above. Questions about privacy go to mattobial@gmail.com.

This document is written and maintained by the NimiCard team. It has not been reviewed or approved by a qualified lawyer, and a final legal review is still recommended before relying on it. Questions can be sent to mattobial@gmail.com.