Cardtag

Privacy Policy

Last updated: March 15, 2026

Introduction

Welcome to Cardtag. We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By using Cardtag, you agree to the collection and use of information in accordance with this policy.

Information We Collect

Personal Information You Provide

  • Account information (name, email, password)
  • Profile information (company, title, professional details)
  • Business card data (contact information from scanned cards)
  • Voice notes and conversation context
  • Payment information (via Paystack)

Automatically Collected Information

  • Device information (type, OS, unique identifiers)
  • Usage data (features used, pages visited)
  • Location data (with permission, for events)
  • Log data (IP address, browser, access times)

How We Use Your Information

  • Provide and maintain the Service
  • Process business cards using OCR and AI
  • Generate AI insights and follow-up suggestions
  • Enable Arena networking events
  • Process payments via Paystack
  • Improve our Service and user experience
  • Send updates and security alerts
  • Ensure security and prevent fraud

Data Sharing

We Share With:

  • AI providers (OpenAI, Anthropic, Google) for processing
  • Paystack for payment processing
  • PostHog for analytics (EU-hosted, GDPR-compliant)
  • Firebase/Google Cloud for infrastructure

We Never:

  • Sell your personal information
  • Share contacts without permission
  • Use data to train AI models

Your Rights

You have the right to:

  • Access your personal information
  • Correct inaccurate data
  • Request deletion of your account
  • Export your data (CSV format)
  • Opt-out of marketing communications

Contact us at privacy@cardtag.io to exercise these rights.

Data Security

We protect your information with:

  • Encryption in transit (HTTPS/TLS) and at rest
  • Secure authentication via Firebase
  • Regular security audits
  • PCI-compliant payment processing

Contact Us

Questions about this Privacy Policy?

Compliance

We comply with the Kenya Data Protection Act, 2019 and GDPR where applicable. You can lodge complaints with the Office of the Data Protection Commissioner if needed.