← Back to home
Legal

Privacy Policy

Last updated: August 17, 2026

1. Data controller

The data controller is VisitCard, operated by Fiducium Sàrl, Rue des Beaux-Arts 14, c/o Gaël Ghislain Monney, 2000 Neuchâtel, Switzerland (Company ID: CHE-488.904.546). Contact: hello@visitcard.app. This company is subject to the Swiss Federal Act on Data Protection (nFADP) and, for users located in the European Union, endeavours to comply with GDPR principles. Under these frameworks, the formal designation of a data protection officer is not mandatory for our organisation size. All data protection enquiries: hello@visitcard.app.

2. Data collected & legal bases

3. Storage and security

Your data is hosted on Cloudflare infrastructure (global network, ISO 27001 certified datacenters). The database uses D1 SQLite with encryption at rest. Passwords are hashed using PBKDF2-SHA256 with 100,000 iterations and a unique salt per user. All communications are encrypted with TLS 1.3. CSRF tokens protect all forms. IP-based rate limiting is applied on all sensitive routes via Cloudflare KV.

4. Sub-processors (art. 28 GDPR)

Sub-processorRoleLocationPolicy
Cloudflare, Inc.Hosting, CDN, D1 database, KVUSA (SCC)cloudflare.com/privacypolicy
Stripe, Inc.Payment processing, billing, VATUSA (SCC)stripe.com/privacy
Resend, Inc.Transactional email deliveryUSA (SCC)resend.com/privacy
Google LLC (GTM/GA4/Google Ads)Analytics and advertising conversion measurement (with consent only)USA (SCC)policies.google.com/privacy

5. Cookies

VisitCard uses two strictly necessary cookies: visitcard_session (authentication, HttpOnly, SameSite=Lax) and csrf_token (CSRF protection, SameSite=Lax, Max-Age 24h). Google Analytics 4 and Google Ads, loaded via Google Tag Manager, are only activated after explicit consent (cookie banner), each per the accepted category (Analytics / Marketing). By default, all collection is disabled (Google Consent Mode v2: analytics_storage and ad_storage set to denied). Your choice is stored in the vc_consent cookie (365 days). Details: Cookie Policy.

6. Your rights (GDPR)

Under GDPR articles 15–22, you have the right to access (art. 15), rectification (art. 16), erasure (art. 17), restriction (art. 18), portability (art. 20), and objection (art. 21). To exercise these rights: hello@visitcard.app. We respond within 30 days. You also have the right to lodge a complaint with your national supervisory authority.

7. Retention periods

Data categoryRetention period
Active user accountDuration of subscription + 30 days after account deletion
Contacts received via card form3 years from last contact (legitimate interest), erasable on request at hello@visitcard.app
Billing data & invoices10 years (statutory accounting obligation)
Rate-limiting logs (IP)2 × time window (max 2 h) in Cloudflare KV
Aggregated analytics (card views)Duration of account, deleted with account
Google Analytics data (GA4)Collected only after consent; retained 14 months at Google
Transactional emails (Resend)30 days in Resend logs, then deleted
Database backups30 days, managed by Cloudflare D1

8. International transfers

Cloudflare, Stripe, and Resend are US companies. Data transfers to the United States are governed by Standard Contractual Clauses (SCCs) approved by the European Commission (decision 2021/914). Data may transit Cloudflare datacenters located in Europe (Paris, Amsterdam, Frankfurt) to minimise latency.

9. Public contact form

When a visitor sends a message via the contact form on a VisitCard business card, the data entered (name, email, optional phone, optional company, message) is forwarded by email to the card’s owner and stored in VisitCard’s database (Cloudflare D1) to enable contact management. The legal basis is legitimate interest (GDPR art. 6.1.f). Data is retained for 3 years from the last interaction and can be erased on request at hello@visitcard.app. An optional marketing opt-in is offered; declining does not prevent message delivery. Rate limit: 3 messages/hour per IP.

10. Minors

VisitCard is intended for users aged 16 and over, in accordance with GDPR art. 8. We do not knowingly collect data from children under 16.

11. Contact & complaints

For any data protection query: hello@visitcard.app. If you are not satisfied with our response, you can contact the Swiss Federal Data Protection and Information Commissioner (FDPIC): edoeb.admin.ch. If you reside in the European Union, you also retain the right to lodge a complaint with your national supervisory authority.