Cardigo

Privacy Policy

Legal

Privacy Policy

This Privacy Policy describes how White Hat Digital Agency Limited (“Cardigo”, “we”, “us”, or “our”) collects, uses, discloses, and protects personal information when you use the Cardigo website, web application, and mobile applications for iOS and Android.

Last updated: August 18, 2026Effective: August 18, 2026Privacy requests →

We do not sell your data

Cardigo does not sell personal information. We use data only to operate the networking features you choose to use.

You control your profile

Edit your card, branding, and contact details anytime. Delete your account from Profile in the app.

Permissions are optional

Camera, photos, and NFC are requested only when you use scanning, OCR, or tap-to-exchange features.

Questions or requests

Contact privacy@cardigoapp.com for privacy rights requests or hello@cardigoapp.com for general support.

1. Introduction and scope

This Privacy Policy applies to personal information processed through Cardigo’s marketing website (https://cardigoapp.com), authenticated web application (https://app.cardigoapp.com), APIs, and native mobile apps published under the name “Cardigo” (collectively, the “Service”).

By creating an account, using the Service, or otherwise providing information to us, you acknowledge this Privacy Policy. If you do not agree, please do not use Cardigo.

Data controller

White Hat Digital Agency Limited is the data controller for personal information processed through the Service, unless stated otherwise. Contact: privacy@cardigoapp.com.

2. Information we collect

We collect information in three ways: (1) information you provide directly; (2) information generated when you use the Service; and (3) limited technical information from your device and browser.

Information you provide

  • Account registration: name, email address, password (stored in hashed form), and authentication session data.
  • Profile and card content: photo, job title, company, phone number, biography, social links, theme preferences, public share slug, and branding assets such as logos.
  • Contacts you save: names, employers, phone numbers, emails, notes, and source metadata (QR scan, NFC tap, handshake, manual entry, or OCR).
  • Support communications: messages you send to our support or privacy inboxes.

Information collected automatically

  • Usage data: profile views, scans, exchanges, feature interactions, and timestamps needed for analytics and product improvement.
  • Device and app data: operating system, app version, device model, language, and diagnostic logs when troubleshooting errors.
  • Network data: IP address, browser type, and referral URLs when using the web app.
  • Advertising identifiers: advertising ID on mobile devices when you interact with rewarded ads (Free plan).

Information from device permissions

  • Camera: QR code scanning and business card capture for OCR.
  • Photo library: selecting profile photos or logos.
  • NFC (Near Field Communication): tap-to-exchange when you initiate an NFC exchange.
  • Contacts (optional): saving exchanged details to your device address book when you choose that action.

3. Summary of data use (App Store & Google Play)

The table below summarizes categories of data processed by Cardigo. This helps you understand what we collect and why, as required by app store data disclosure forms.

CategoryExamplesLinked to you?Purpose
Contact infoName, email, phone, company, roleYesAccount, digital card, contact exchange
User contentProfile photo, logo, bio, social linksYesDisplay and share your digital card
ContactsPeople you scan, save, or exchange withYesContacts list and networking features
IdentifiersUser ID, share slug, device advertising IDYesAuthentication, analytics, rewarded ads
Usage dataViews, scans, feature eventsYesAnalytics and product improvement
DiagnosticsCrash logs, performance dataMay be linkedStability and security
Photos / cameraBusiness card images for OCRYesOCR extraction when you scan a card

4. How we use information

  • Provide, operate, and maintain the Service, including digital cards, sharing links, QR codes, NFC exchange, contacts, events, and analytics.
  • Authenticate users, secure accounts, prevent fraud and abuse, and enforce our Terms of Service.
  • Display your public profile to people who visit your share link, scan your QR code, or complete an exchange you initiate.
  • Process OCR requests to extract contact fields from business card photos you submit.
  • Generate Apple Wallet and Google Wallet passes when you request them.
  • Deliver rewarded advertisements on the Free plan and measure ad performance.
  • Send transactional communications such as verification codes, security alerts, and service notices.
  • Respond to support requests and legal or regulatory inquiries.
  • Analyze aggregated trends to improve reliability, performance, and user experience.

6. Advertising and analytics

Cardigo’s Free plan may display rewarded video advertisements powered by Google AdMob. AdMob may collect device identifiers and interaction data according to Google’s policies to deliver and measure ads.

  • Rewarded ads are optional — they appear when you choose to watch an ad to unlock certain Free-plan limits.
  • Pro subscribers do not see rewarded ads for plan-gated features.
  • You can reset or limit ad personalization in your device settings (Limit Ad Tracking on iOS, Opt out of Ads Personalization on Android).
  • Google’s privacy policy: https://policies.google.com/privacy

7. How we share information

We do not sell personal information. We share data only as described below:

  • Public sharing: fields on your digital card may be visible to anyone with your link, QR code, or NFC exchange.
  • Other users: when you exchange or save contacts, relevant profile fields are shared according to the feature you use.
  • Legal and safety: when required by law, regulation, legal process, or to protect rights, safety, and integrity.
  • Business transfers: in connection with a merger, acquisition, or asset sale, subject to continued protection of your information.

Service providers

  • Supabase — database, authentication, and file storage
  • Vercel — web application hosting
  • Google — AdMob advertising, Google Wallet pass generation, ML Kit text recognition (OCR on Android)
  • Apple — Apple Wallet pass generation

8. Data retention

We retain personal data for as long as your account is active or as needed to provide the Service. Typical retention periods include:

Data typeRetention period
Account and profile dataUntil you delete your account, plus up to 30 days for backup purge
Contacts you savedUntil you delete them or delete your account
Analytics eventsUp to 24 months in aggregated form
Support emailsUp to 3 years for audit and dispute resolution
OCR imagesNot stored after processing unless you save the resulting contact

We may retain certain records longer when required by law, to resolve disputes, enforce agreements, or maintain security logs.

9. Security

We implement administrative, technical, and organizational safeguards designed to protect personal information, including HTTPS encryption in transit, access controls, row-level security on database tables, and industry-standard password hashing. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. International transfers

Cardigo may process and store information in the United States and other countries where our service providers operate. Where required, we use appropriate safeguards for cross-border transfers, such as standard contractual clauses or equivalent mechanisms.

11. Your privacy rights

Depending on your location, you may have the following rights regarding your personal information:

  • Access — request a copy of personal data we hold about you.
  • Correction — update inaccurate profile information in the app or by contacting us.
  • Deletion — delete your account in Profile → Delete account, or email us at the privacy address.
  • Portability — request an export of your profile data where technically feasible.
  • Restriction and objection — object to or request limitation of certain processing where applicable law provides these rights.
  • Withdraw consent — where processing is based on consent, such as optional permissions.
  • Complaint — lodge a complaint with your local data protection authority.

California residents (CCPA/CPRA)

We do not sell or share personal information for cross-context behavioral advertising as defined under California law. California residents may request access, correction, or deletion by emailing privacy@cardigoapp.com. We will not discriminate against you for exercising privacy rights.

12. Account deletion

You can delete your Cardigo account at any time from the mobile or web app: Profile → Delete account. Deletion removes your profile, authentication credentials, and associated personal data from active systems within a reasonable period.

  • Contacts you saved about other people may be deleted with your account.
  • Public caches or backups may take up to 30 days to fully purge.
  • If you cannot access the app, email privacy@cardigoapp.com from your registered address to request deletion.

13. Children’s privacy

Cardigo is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us data, contact us at privacy@cardigoapp.com and we will take steps to delete it.

14. Cookies and similar technologies

The web app uses essential cookies and local storage for authentication sessions and security. We do not use third-party advertising cookies on the web app. Mobile apps use local storage and secure tokens for session management.

15. Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. Material changes may be communicated by email or in-app notice where appropriate.

16. Contact us

Privacy requests and data subject rights: privacy@cardigoapp.com. General support: hello@cardigoapp.com. You may also use our contact page at https://cardigoapp.com/contact.