This Privacy Policy explains how Card IO ("we", "our", or "us") collects, uses, discloses, and protects your information when you use our mobile application (the "App") available on the Apple App Store and Google Play Store.
1. Information We Collect
We collect information necessary to create, manage, and share your digital business cards:
- Account & Authentication Information: When you register or sign in, authentication is handled securely via Amazon Web Services (AWS) Cognito. We collect credentials such as your email address and encrypted authentication tokens.
- Biometric Authentication (Face ID / Touch ID / Fingerprint): Card IO supports biometric lock features. All biometric processing is performed locally on your device via Apple’s LocalAuthentication or Android’s BiometricPrompt APIs. We never access, store, or transmit your biometric data or fingerprints to our servers.
- Contact Card Information (User Content): Information you voluntarily input to construct your digital cards, including:
- Full name, job title, company, and card color preferences
- Phone numbers, email addresses, and physical addresses
- Social and professional URLs (such as your LinkedIn profile)
- Private notes and custom interaction reminders
- Billing & Subscription Data: All in-app subscriptions, free trials, and recurring purchases are processed directly by Apple (StoreKit) and Google Play Billing. We do not collect, view, or store credit card numbers or banking information.
- Technical & Diagnostic Data: Basic device model, OS version, app version, and crash logs collected automatically to maintain app stability.
2. How We Use and Share Your Data
- Digital Card Creation & Management: To store, sync, and display your personalized digital cards across your sessions.
- QR Code Generation & Contact Sharing: When you present your on-screen QR code for scanning, the contact details you selected for that card are made accessible to the scanning device so the recipient can save your contact details.
- Account Security & Maintenance: To authenticate your account, safeguard app access, and diagnose technical errors.
We do not sell, rent, monetize, or trade your personal information, contact cards, or recipient data to third-party advertisers or data brokers.
3. Data Storage, Security, and Cloud Architecture
We employ industry-standard safeguards to protect your personal and professional data:
- Encrypted Cloud Storage: Your digital business card data and profiles are stored encrypted at rest and in transit in MongoDB Atlas (Cloud).
- Authentication Infrastructure: Identity management, password storage, and session security are managed by AWS Cognito.
- QR Transmission: Data encoded in your on-screen QR code is only transferred when you intentionally display it for another user to scan.
4. Data Retention and Account Deletion
You have full control over the contact details stored in Card IO:
- Editing/Removing Cards: You can edit or permanently delete individual digital cards directly within the App at any time.
- Full Account & Data Deletion:
In-App: Go to Settings > Account > Account Deletion to immediately purge your profile, cards, and associated credentials.
5. Your Rights (GDPR / CCPA / Global)
Depending on your location, you have statutory rights regarding your personal information, which you can exercise directly:
- Access and Rectification: You can view, export, and edit all of your contact cards, profile information, and notes directly inside the App at any time.
- Account Deletion ("Right to Erasure"): You can permanently delete your entire account and all stored card data via Settings > Account > Account Deletion
- Biometric Controls: You can enable or revoke Face ID/Touch ID access at any time via your device’s system settings.
- Additional Requests: If you need an export of system metadata, cannot access your account, or wish to exercise any additional statutory privacy rights, you can contact us at [email protected].
6. Children’s Privacy
Card IO is a professional networking tool and is not intended for individuals under 13 years of age (or under 16 in certain jurisdictions). We do not knowingly collect personal information from children.
7. Contact Us
If you have any questions or feedback regarding this Privacy Policy or Card IO’s security practices, please reach out to:
- Developer/Entity: dotMatters Limited
- Email: [email protected]

