CardSnapCardSnap

Privacy & PDPA Notice

Effective: 14 September 2026

Trust summary

  • Your contacts are visible only to you. No other user or account can see them.
  • We never sell, rent, or share your contacts, and never use them for advertising.
  • Your data is never used to train AI models.
  • Practices in this notice are aligned with the Personal Data Protection Act (PDPA) principles of consent, purpose limitation, access, correction, and retention.
  • You can export everything, or delete everything, from Settings at any time.

This page is maintained by the owner of CardSnap to answer common security and privacy questions about the app. It describes our own practices. It is not an independent audit or certification.

CardSnap is designed to keep your contact data private. This notice explains what we collect, why, who processes it, how long we keep it, and the controls you have.

1. What we collect

  • Account data: your email address, name, and any profile details you choose to add (title, company, mobile, LinkedIn, website).
  • Contact data: the details you scan or enter from business cards and QR codes, such as names, titles, companies, phone numbers, email addresses, addresses and LinkedIn profiles, plus your own notes, groups, event tags, and reminders.
  • Card images: the photo of a scanned card, if you keep image retention switched on.
  • Voice notes and transcripts: when you record a note or speak a question, the audio is sent for transcription and the resulting text is saved to the contact or the question box. We do not keep the audio recording.
  • Relationship memory: short facts drawn from your own notes and messages, such as a stated priority or a follow-up commitment, so drafts and answers stay accurate.
  • Writing style data: messages you send or edit are kept as samples, and summarised into a style profile, so future drafts sound like you.
  • Calendar data: only if you connect a calendar. We store the events needed to tag a contact to the right meeting, plus the follow-up entries you ask us to create.
  • Connected account access: an access key for each account you connect, held encrypted. We do not store your Google password.
  • Notification registrations: the browser or device push registration you create by turning notifications on, plus a log of notifications we sent you.
  • Usage data: basic app activity needed to run the service and to see whether features work: which action happened, when, and which contact it related to. No message text or note content is recorded in these events.
  • AI usage metering: for each AI action, the model used, token counts and an estimated cost, so we can run the service sustainably. Your content is not stored in these records.

2. Purpose limitation: how we use it

We use your data only to operate CardSnap for you: reading cards, saving contacts, optional enrichment, generating summaries and message drafts you request, and sending the reminders you set. We do not sell your contacts, use them for advertising, aggregate them across accounts, or use them to train AI models.

3. Confidentiality and access control

CardSnap is single-tenant by design at the row level: every contact, note, group, and image is tagged to your account, and database row-level security plus per-user storage folders enforce that only your authenticated session can read or write them. Support staff do not browse contact records as part of normal operation.

4. Consent and lawful basis

You choose which cards to scan and which details to store. By scanning a card, you confirm that the person handed you their details for business contact purposes, and you remain responsible for how you use them. CardSnap processes contact data on your instruction, as your service provider.

5. Service providers we use

We keep the number of processors small and send each one only the minimum data needed:

  • Cloud hosting, database and file storage: stores your account, contacts and card images.
  • AI model provider: receives the card image or contact text to extract details, draft messages, and generate summaries. Data sent for these features is processed to return a result, not retained for model training.
  • Web search / enrichment provider: receives a name, company, and title to find a matching public professional profile. Used only while AI enrichment is switched on.
  • Google: only if you choose to sign in with Google, or to export or sync contacts and calendar events with your own Google account.

5a. Google user data

When you use a Google-connected feature, CardSnap requests the narrowest access needed for that feature:

  • Sign-in (openid, userinfo.email, userinfo.profile): to create and identify your CardSnap account. We store your email address and name only.
  • Contacts (contacts scope), only when you enable contact sync: to write the contacts you select into your own Google account. We do not read or index the rest of your Google contact list, and we do not use it for suggestions or analytics.
  • Calendar (calendar events scope), only when you enable calendar sync: to read the events you are attending so a scanned contact can be tagged to the right meeting, and to create the follow-up entries you explicitly ask for.

CardSnap's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer this data to others except as needed to provide or improve the feature you requested, to comply with applicable law, or as part of a merger or acquisition. We do not use it for advertising, and we do not allow humans to read it except with your explicit permission, for security purposes, to comply with applicable law, or where the data is aggregated and anonymised. We never use Google user data to train AI models. You can disconnect Google access at any time from Settings, or from your Google account permissions page.

6. Retention and deletion

We keep your data for as long as your account is open, because the contact list is the product. Card photos are kept only while you leave "Keep card photos" switched on; switching it off discards new photos as soon as details are extracted. Voice recordings are not kept: only the transcript is saved. Deleting a contact removes its notes, events and drafts.

Deleting your account removes your login, profile and digital card page, your contacts, notes, transcripts, timeline events, reminders and drafts, groups and tags, relationship memory, writing style data and message samples, stored card images, calendar entries we saved, notification registrations and history, product usage events, any team you own and your memberships, and your access to connected accounts. We revoke the connected access key with the connector service where we can, and delete it from our database either way; if revocation is not confirmed we tell you, so you can also remove CardSnap from your Google account permissions page.

Two things survive on purpose. AI usage and cost records are kept for accounting and abuse prevention with the account reference removed, so they no longer identify you and never contained your content. Our database provider also keeps short-term encrypted backups, which age out on its normal cycle and are not restored into the live app. Where the law requires us to keep a record, we keep only that, for only as long as required.

Full instructions, including how to request deletion if you cannot sign in, are on the account deletion page.

7. Your rights and controls

  • Access & portability: Settings → Data & privacy → "Download my data" gives you a complete machine-readable export.
  • Correction: edit any contact or your own profile at any time.
  • Withdraw consent: turn off AI enrichment, or turn off card-photo retention, in the same section.
  • Erasure: delete all contacts, or delete your entire account, with one-step confirmation.

8. Security incidents

If we become aware of a security incident affecting your data, we will notify affected account holders without undue delay and describe what happened and what to do next.

9. Shared responsibility

We are responsible for securing the CardSnap application, its database rules and its processors. You are responsible for keeping your login credentials safe, for having a legitimate business reason to store each contact, and for how you contact the people in your list.

10. Contact us

Privacy questions, access requests, and data protection matters: privacy@cardsnap.asia.

This notice is maintained by the app owner, describes current practices, and may be updated from time to time. It is not an independent certification and is not legal advice.