1. Privacy Philosophy & Commitment
FliQCard operates on an explicit privacy-by-design architecture. Unlike traditional ad-supported social platforms that monetize user contact networks, FliQCard functions strictly as an identity orchestration software utility.
We never sell, lease, or monetize your personal contact information or the contact details captured from individuals who scan your digital card. Your address book data belongs entirely to you and your enterprise workspace.
2. Information We Collect
We collect only the essential data elements required to provide reliable digital business card hosting and bilateral contact exchange services:
- Account Credentials: Full name, verified work email address, and hashed authentication password.
- Card Profile Information: Display title, department, company name, bio, direct phone number, social media handles, website URLs, and avatar image uploaded by you.
- Contact Exchange Submissions: Information explicitly entered by recipients who choose to complete the "Share Your Contact" modal on your public card.
- Dynamic QR Configurations: Aesthetic preferences such as dot geometries, eye colors, and embedded logo graphics.
3. Cryptographic SHA-256 IP Hashing
To calculate unique card views without compromising visitor confidentiality, FliQCard employs one-way cryptographic SHA-256 hashing.
Raw Visitor IP + Secret Daily Salt → SHA-256 Hash Digest → Stored MetricBecause the salt is rotated daily and the hash is mathematically irreversible, raw IP addresses are never written to disk or stored in application databases. We cannot reconstruct a visitor's identity from our telemetry logs.
4. How We Use and Process Information
We use collected information solely for:
- Rendering and routing your public digital business card at
fliqcard.com/c/your-slug. - Generating RFC 6350 vCard downloads and wallet passbook files.
- Displaying lead records in your authenticated dashboard so you can follow up with new connections.
- Sending essential transactional notifications, including password resets and security alerts.
5. Storage & Encryption Protocols
All user and card data is encrypted in transit using TLS 1.3 and encrypted at rest using 256-bit AES encryption.
Our database infrastructure is housed in SOC 2 Type II certified cloud environments with multi-region redundancy and automated daily failover backups.
6. Retention & Permanent Deletion
You retain complete sovereignty over your data. When you request the deletion of your FliQCard account or delete an individual card profile:
- Public card routes are immediately disabled and return standard 404 responses.
- All profile avatars, uploaded logos, and card configurations are purged from hot storage within 48 hours.
- Residual backup snapshots are overwritten following our standard 30-day snapshot rotation window.
7. Your Rights Under GDPR & CCPA
Regardless of your country of residence, FliQCard extends comprehensive privacy rights to all registered users and public visitors:
9. Security Standards & Vulnerability Reporting
We maintain active continuous integration vulnerability scanning, automated dependency auditing, and strict Content Security Policies (CSP).
Security researchers who discover potential vulnerabilities are invited to practice responsible disclosure by contacting our security team directly at security@fliqcard.com.
10. Contacting the Data Protection Officer
For inquiries regarding this Privacy Policy, submitting data subject access requests (DSAR), or contacting our Data Protection Officer: