Privacy Policy
Last updated: September 2026. In plain English: you own your card, we don't sell your data, and we don't track you around the internet.
ReeCard is a digital business card and link-in-bio service. This policy explains what personal information we collect, how we use it, and the choices you have.
Information you provide
- Card details: your name, title, company, phone, email, website, address, bio, and the colours you pick.
- Photos: an optional portrait, logo, banner or featured poster, if you upload them.
- Links: your social handles (Instagram, TikTok, X, YouTube, LinkedIn, Facebook, WhatsApp, Telegram, Threads, GitHub) and any custom links you add.
- Account & billing: the email address and password you sign in with. If you subscribe to a paid plan, our payment processor Stripe collects your payment details — we never see or store your full card number.
- Team and event details: a team name and brand kit if you create a team, the email addresses of teammates you invite, and an optional event name, date and venue coordinates if you turn on event mode for your passes.
- Details visitors share with you: on cards with the contact form switched on, a visitor can send their name, email, phone, company and a message through the “Share your details back” form. They consent when they submit; the details are stored for you as the card owner, shown only in your dashboard and emailed to you. You are responsible for handling them lawfully and for deleting contacts you no longer need.
Information we collect automatically
- Engagement events: when someone opens a card, saves it, scans its QR or taps a link, we record the event type and time, a salted one-way hash of the visitor's IP address (to estimate unique visitors), the browser user-agent string, the referring page, the traffic source (for example a campaign code or NFC tag), the visitor's country as reported by our network edge, the device type and which button was tapped. These are shown to the card owner only as aggregated counts; we do not build individual visitor profiles, and the card owner never sees a visitor's IP address.
- Security logs: sign-in and form-submission attempts (IP address, the email entered and time) to protect accounts against brute-force attacks and abuse; entries are purged routinely after 30 days.
Cookies and trackers
We use only small, first-party cookies needed to sign you in. Your light/dark theme choice is kept in your browser's local storage, not in a cookie. We do not use ad networks, cross-site trackers, marketing pixels, session-replay tools or third-party analytics that profile you. Stripe Checkout, which is hosted by Stripe, sets its own cookies during payment.
How we use your information
- To build and display your public card page, QR code and wallet passes. Everything you put on your card is public by design: anyone with the link can view it, download the contact file or read it through our public JSON API, and search engines may index it. Hide your card under Public access in your dashboard to stop this.
- To open links you add when visitors tap them. Those destinations are third-party sites with their own privacy policies.
- To process payments for paid plans (via Stripe) and issue receipts.
- To show engagement stats on your dashboard and, if you keep it switched on, to send you a short weekly digest of them.
- To run the referral programme: when someone joins through your invite link we record the connection between the two accounts so the reward can be granted once.
- To answer your support questions and to protect the service against abuse.
Third-party services
- Apple Wallet & Google Wallet — when visitors save your card, the relevant wallet service receives the card fields needed to display the pass. So that saved passes can update, an iPhone that adds a pass registers with us using an anonymous device identifier and a push token; we store only those two values, use them solely to tell the device a new pass version exists, and delete them when the pass is removed. Google Wallet passes are updated through Google's pass API without any device identifier.
- Stripe — handles billing for paid plans (PCI-compliant). See the Stripe Privacy Policy.
- Email delivery — transactional emails (verification, password resets, billing notices, support replies) are delivered through our SMTP provider, Hostinger.
- Search engines — when you publish or rename a card we notify search engines that support the IndexNow protocol (such as Bing and Yandex) that the page changed.
We do not sell or rent your personal information to anyone.
Data retention & deletion
Your card, uploaded images, links, engagement events, contacts shared with you and campaign codes stay saved for as long as the card exists. When you delete a card from your dashboard, the card page, QR, images, links, contacts and engagement data are removed from the live database immediately, and any Google Wallet pass for the card is marked expired. Encrypted database snapshots are kept for up to 14 days for disaster recovery. Sign-in attempt logs are removed after 30 days.
Your choices & rights
- Edit, hide or delete your card any time from your dashboard.
- Delete your account yourself at any time, from the app or the website, as described on Delete your account. You can also request a copy of your account data, or its deletion, by emailing [email protected].
- We send transactional email (account, billing, team and support messages) plus an optional Monday digest of your card's numbers, which you can switch off under Settings. There is no marketing list.
Children
ReeCard is intended for people aged 16 and older. We don't knowingly collect information from children below that age. If you believe a child has provided us information, contact us and we'll delete it.
Changes to this policy
If we make material changes we'll update the date at the top and, for significant changes, notify you by email or a banner on your dashboard before they take effect.
Who we are
ReeCard is operated by the owner of the 1ree.com domain, who is the controller of the personal data described here. Reach us at [email protected].
Contact
Privacy questions, data-access requests and deletion requests: [email protected].