Trust & safety

Security & Data Protection

Your connections are valuable. So is the data behind them.

NimiCard is designed with security and privacy controls at multiple layers — from authentication and account isolation to private storage, server-side authorization and privacy-friendly analytics.

We continuously work to protect account information, private leads and platform data while giving you control over what you intentionally publish on your NimiCard.

Updated August 8, 2026

Secure authentication

Account access is handled through managed authentication with email/password and Google Sign-In.

Private by default

Private dashboard data such as leads, analytics and support conversations is not publicly exposed.

Account isolation

Access controls are designed so one user cannot read or modify another user's private NimiCard data.

Server-side protection

Sensitive operations and privileged actions are authorized on the server, not only hidden in the interface.

Privacy-friendly analytics

Visitor identifiers used for estimating unique visitors are one-way hashed before storage.

Controlled staff access

NimiCard staff permissions are role-based, limited to the work each role needs to perform.

Built on a security-focused technology platform

NimiCard is developed using Lovable, a technology platform that maintains recognized security and information-security controls.

SOC 2 Type II

Lovable maintains SOC 2 Type II assurance covering controls related to the security and operation of its platform.

ISO 27001:2022

Lovable maintains ISO 27001:2022 certification for its information security management system.

AIUC-1

Lovable has achieved AIUC-1 certification covering security, safety and reliability controls for AI coding agents.

GDPR support

Lovable supports GDPR requirements and provides data-processing commitments for customers through its contractual and privacy framework.

Learn more about Lovable's security practices

What these certifications mean for NimiCard

These certifications and assurances apply to Lovable and its platform. They do not constitute SOC 2, ISO 27001 or AIUC-1 certification of NimiCard itself.

NimiCard builds on that security-focused foundation and applies its own application-level safeguards, including account isolation, server-side authorization, private storage, role-based staff access, audit logging and privacy-focused analytics.

Why this matters

Using a technology provider with established security controls helps NimiCard reduce infrastructure and platform risk while allowing us to focus additional protections on the NimiCard application itself.

Layer 1

Security-focused technology platform

  • Platform security governance
  • Infrastructure controls
  • Information-security management
  • AI-development governance

Layer 2

NimiCard application protections

  • Authenticated account access
  • Account and data isolation
  • Server-side authorization
  • Private storage
  • Role-based administrative permissions
  • Hashed analytics identifiers
  • Moderation controls
  • Protected support workspace

Layer 3

NimiCard verification

  • Account-isolation verification
  • Authorization testing
  • Analytics integrity testing
  • Moderation and appeal testing
  • Production release testing
  • Production smoke testing

You control what becomes public

A digital business card is designed to be shared. Information you intentionally place on a published NimiCard — such as your name, company, job title, biography, phone number, email address, website and social links — becomes publicly accessible.

Information in your private dashboard, including leads, analytics, support conversations and account information, is not part of your public card.

Public by choice

Information you publish on your NimiCard.

Private to your account

Dashboard data, leads, analytics, account settings and support conversations.

If you do not want information to be public, remove that field or keep the card unpublished.

Secure account access

NimiCard keeps sign-in simple without cutting corners.

  • NimiCard supports email and password sign-in.
  • NimiCard supports Google Sign-In.
  • Password sign-in is handled by our managed authentication provider.
  • Passwords are stored only as salted password hashes by that provider.
  • NimiCard never receives or stores your Google password.
  • Protected dashboard pages require a valid signed-in session.
  • Signing out clears your session and the app's client-side data cache.

Your private data stays separated from other accounts

Private information is protected by per-user database access rules and server-side ownership checks — not just by which screens you can see.

Private account data includes:

  • Unpublished card content
  • Leads collected through your card
  • Engagement analytics
  • Feedback and support conversations
  • Account settings
  • Private administrative information

NimiCard is designed so Account A cannot access Account B's private information simply by changing a URL, card ID or request.

Account-isolation behaviour is part of our release verification process before changes go live.

Protection beyond the interface

NimiCard does not rely only on hiding buttons or pages.

  • The database enforces per-user, per-row access rules.
  • Ownership is validated on the server before data is returned or changed.
  • Privileged operations run through server-side capability checks.
  • Administrative functions are restricted to authorized staff roles.
  • Sensitive actions cannot be authorized just by changing something in the browser.

Restricted administrative access

NimiCard uses role-based staff permissions. Each role receives only the capabilities needed for its responsibilities.

  • Platform administrator — full administrative access, restricted to a small number of people.
  • Support agent — works with support tickets.
  • Moderator — handles reports and card moderation.
  • Analyst — can access aggregate analytics.
  • Operations viewer — reviews operational status and audit information.

Important administrative and moderation actions are recorded in audit logs.

Protecting leads and contact exchanges

Lead records exist only because someone chose to share their details with you.

  • Lead information is created only when a visitor voluntarily submits a contact form.
  • Lead submissions are validated on the server before anything is stored.
  • Leads belong to the relevant card owner.
  • Anonymous visitors cannot browse a card owner's leads.
  • Submissions are protected by validation, spam controls and rate limiting.

Card owners are responsible for using the contact information they receive lawfully and appropriately.

Private file storage

  • Uploaded files are stored in private storage, not an open public folder.
  • Storage paths are separated per account and per card.
  • File type and size are validated before upload.
  • Where public display is needed, access uses controlled, time-limited links.
  • Uploading an image does not make unrelated account files publicly browseable.

Privacy-friendly engagement analytics

NimiCard analytics are intended to measure engagement, not build advertising profiles.

What is measured:

  • Page and card views
  • QR visits
  • NFC visits
  • Contact saves
  • Shares
  • Link and action interactions

A random browser identifier may be used to estimate unique visitors. Before storage it is transformed into a one-way SHA-256 hash using server-side protection. The raw browser identifier is not stored in the analytics database.

NimiCard does not sell visitor analytics data for advertising.

Cleaner analytics

When NimiCard can reliably identify activity from a card owner's verified browser, that activity can be excluded from external engagement analytics so owners do not inflate their own statistics.

Protecting the community

Visitors can report a card they believe is fraudulent, misleading, impersonating someone, spam, inappropriate or privacy-violating.

Authorized moderators can suspend a reported card while it is reviewed. Suspended cards are blocked from public access, and the owner can submit an appeal for review.

Sensitive actions leave a trail

Important administrative actions are written to an audit log.

  • Moderation decisions
  • Card suspension
  • Card restoration
  • Appeal decisions
  • Staff actions where applicable

This helps NimiCard investigate issues and maintain accountability for privileged actions.

Secure connection

NimiCard is served over HTTPS, so information transmitted between supported browsers and nimicard.com is protected while in transit.

We collect what the service needs

NimiCard aims to avoid unnecessary collection.

  • Visitors do not need an account to view a public card.
  • No personal visitor information is required just to open a card.
  • Lead information is only collected when someone voluntarily submits it.
  • Analytics use privacy-friendly identifiers instead of named visitor profiles.

Security is a shared responsibility

We secure the platform. A few habits keep your side strong too.

  • Use a strong, unique password.
  • Protect access to the email or Google account you sign in with.
  • Sign out on shared or public devices.
  • Publish only information you are comfortable sharing publicly.
  • Review your card information regularly.
  • Handle the leads you collect responsibly.

Our commitment — without unrealistic promises

No internet-connected service can guarantee absolute security. NimiCard uses multiple technical and operational safeguards designed to reduce risk and protect private account information, but we do not claim that any online platform can eliminate every possible security threat.

This page describes controls currently implemented by NimiCard. It is not a security certification or an independent audit.

Found a security issue?

Please report it privately through our contact form. Helpful reports include:

  • The affected page or feature
  • Steps to reproduce
  • Expected versus actual behaviour
  • Screenshots where helpful

Please do not access, alter or download information belonging to another user while testing.

Security FAQ

Want to understand how we handle personal information?

Our Privacy Policy explains what data we collect, why, and the choices you have.