Privacy policy
vQard · last updated 13 August 2026
This is the whole of it, in plain language. It covers the vqard.co website, the vQard apps for Android and iOS, and the public card pages we host for our users. It applies to card owners and to anyone who opens a card.
1. Who we are
vQard (vqard.co) lets people create a digital business card and share it by NFC tap, QR code or link. It is operated by jQode Technologies, based in India. In this policy “we” means jQode Technologies and “you” means either a card owner or a card viewer — we say which, because the two are treated differently.
Questions, corrections and deletion requests all go to hello@jqode.com. Section 18 has our grievance officer and how quickly we answer.
2. Your card is a public web page
Anything visible on your card can be read by anyone who has the link. There is no password on it.
A card lives at vqard.co/c/your-id and, if you set one, at vqard.co/your-name. Those addresses are printed on your physical cards and written to their NFC chips, so they are meant to be handed out. Search engines can index them. Your name, photo, title, company and every field you make visible are published to the open web the moment you publish the card.
You control what is on it. Profiles let you hide sections and fields from the public version and reveal them only to a viewer who verifies their phone number. Anything you delete stops being served straight away, but copies already saved, screenshotted, cached by a search engine or downloaded as a contact file are outside our reach. Do not put anything on a card that you would not put on a poster.
3. What we collect, and why
If you own a card
- Your phone number — this is your sign-in. We need it to create your account and to send you a one-time code.
- Your name, email, and everything you put on your card — title, company, links, addresses, text, and the images you upload. This is the product; we store it so we can serve it.
- People you meet — the names, phone numbers, emails, companies and private notes you save about the people you exchange cards with, plus anyone who verified themselves on your card.
- Contacts you pick from your phone — see section 5. Only the one contact you choose, and only when you choose it.
- Orders and shipping details — see section 4.
- Your card's activity — the visits described below, so we can show you who has been opening your card.
- A push notification token — if you allow notifications in our apps, so we can tell you when your card is opened.
If you open someone else's card
We record that a visit happened: which card, how it was opened (NFC tap, QR scan or plain link), roughly how long it stayed open, which items were tapped, a coarse device and browser label such as “iPhone · Safari”, and an approximate city and country. We store a random identifier in your browser so that your repeat visits count as one person rather than several. The card's owner sees all of this as their card's activity. They do not see who you are, and neither do we, unless you choose to verify.
If you do verify — to unlock a section the owner has locked, or to request an appointment — you enter your phone number and confirm a one-time code. The owner then sees your number, and your name if you give one, next to your visits. That verification is delivered by Google Firebase.
4. Payments, orders and shipping
vQard sells printed NFC cards. That is a physical product, shipped to you.
- Payment is taken by Razorpay. Their checkout opens inside our website and inside our apps, and your card, UPI or netbanking details are entered directly into it. Those details go to Razorpay, not to us — we never see or store your card number. What we keep is Razorpay's order and payment reference, the amount, the currency and whether it succeeded.
- Your shipping address — name, phone, address and PIN code — is stored with the order so we can print and post your cards. To check that a PIN code is serviceable we look it up against India Post's public PIN code directory; only the six digits are sent, never your address or your name.
- Delivery is arranged through Shiprocket, which passes the shipment to a courier. Shiprocket and the courier receive the name, phone number and full delivery address on the order, because a parcel cannot be delivered without them.
- Your order history and invoices stay in your account, and in our books for as long as Indian tax law requires (section 11).
There is nothing to buy inside the apps except printed cards. We do not sell subscriptions there.
5. Phone permissions in our apps
Our Android and iOS apps ask for a few permissions, each one only at the moment you use the feature that needs it. You can decline, and you can change your mind later in your phone's settings. This is exactly what happens to the data behind each one:
- Contacts — when you tap “fill from phone contacts”, your phone shows you its own contact picker and hands us the single contact you choose. That person's name, phone number and email are then saved to your vQard account, because the point is to remember who you met. So yes: a contact you pick does leave your phone. The rest of your address book does not. The app can also build a name-matching list from your contacts so that a number in your vQard contacts shows the name you have saved for it; that list is built on your phone, held in memory, and never sent to us. “Save to phone” writes in the other direction, into your address book.
- Calendar — only if you connect it for appointment booking. We read the start and end times of your events and send those times, and only those times, to our server, so that a stranger booking a slot cannot book one where you are already busy. Event titles, guests, locations and notes are never read and never sent. Each sync replaces the previous one entirely. Appointments you confirm are written back into your calendar, with the visitor's name.
- Camera and photos — only when you set a profile or cover picture. Only the image you pick is uploaded.
- Notifications — to tell you when your card is opened, when someone verifies, and when a booking is requested. Delivered by Firebase Cloud Messaging on Android and by Apple's push service on iOS.
We do not ask for your device's GPS location, your microphone, your SMS messages or your call log, and our apps contain no advertising or tracking SDK.
6. Analytics and approximate location
The analytics in vQard exist for one purpose: to show a card owner what is happening to their own card. We do not build profiles of viewers across cards, and we do not sell any of it.
The approximate location is worked out from the IP address your connection presents when you open a card. We send that IP address to MaxMind, a geolocation company in the United States, and it returns a city and country — for example “Hyderabad, India”. That city and country is what we store on the visit. Your IP address itself is never written to our database. A city is as precise as this ever gets: it is not GPS, it is often wrong by a city, and it can be avoided entirely by using a VPN.
7. Crash and error logs
When something breaks, our own software records the error so we can fix it: the error message, the technical stack trace, the page address it happened on, your browser and device string, and — if you were signed in — your account id. Nothing else from the page is captured. These logs are ours; no third-party crash-reporting service is used. If you delete your account, your account id is removed from any crash rows it appears in, leaving an anonymous bug report.
8. Cookies and local storage
We use a signed session cookie (vqard_session) to keep you signed in, a small amount of browser storage to remember your preferences and that you have seen this policy, and the random viewer identifier described in section 3. We run no third-party advertising or tracking cookies.
9. Companies that receive your data
We do not sell your data and we do not share it for anyone else's advertising. These companies process it on our behalf, for the one job listed against each:
- Google (Firebase) — sends the one-time codes that verify a phone number, and delivers push notifications to Android. Receives the phone number being verified and your device's push token.
- Apple — delivers push notifications to iPhones. Receives the device push token.
- MaxMind (United States) — turns a card viewer's IP address into a city and country. Receives the IP address.
- Razorpay — takes payment for card orders. Receives your payment details directly, plus the name, email and phone on the order.
- Shiprocket and the courier it assigns — deliver your parcel. Receive the delivery name, phone number and address.
- India Post — public PIN code directory, to check a PIN code is serviceable. Receives the PIN code only.
- Google Maps — address suggestions while you type, and the map shown on a card that has a map section. Receives the address text involved.
- Amazon Web Services — hosts the servers and the database (section 10).
We will also disclose data if the law genuinely requires it, and if the business is ever sold or merged your data would move with it — in which case this policy travels with it until you are told otherwise.
10. Where your data is stored
Our servers and our database run in Amazon Web Services' Mumbai region, in India. Uploaded images sit on the same servers. Backups stay in India.
Some of the companies in section 9 operate outside India, so a limited amount of data crosses a border: card viewers' IP addresses reach MaxMind in the United States, phone verification and Android push run through Google, and iOS push runs through Apple. Using vQard means accepting those transfers, which are made under each provider's own contractual terms.
11. How long we keep things
- Your account, cards, contacts and notes
- Until you delete your account
- Card visit history (views, taps, city label)
- 24 months, then deleted
- Crash and error logs
- 12 months
- Calendar busy times
- Replaced at every sync; ignored after 24 hours
- Push notification tokens
- Until you sign out, uninstall, or delete your account
- Orders, invoices and payment references
- 8 years, to meet Indian tax and company-law record-keeping
- Sign-in session cookie
- 14 days
- A record that you opted out of promotions
- Kept, so we do not message you again
The first three of those are enforced by a job that runs every night and deletes what has aged out — they are not a promise we keep by hand. The last row of the table is the deliberate exception: invoices and payment references are excluded from that job, because the law requires us to keep them.
Deleting your account short-circuits all of this: everything tied to it goes at once, except the records tax law obliges us to keep and the anonymised crash rows described in section 7.
12. Promotional messages on the free plan
vQard is free to use because the free plan carries promotions. If you are on a free account, we may show you promotional banners inside the app and contact you with offers from vQard and selected partners — in the app, by SMS or WhatsApp to your registered number, and by email if you have added one. We use your plan, your usage and your profile details to choose what to show you. We never use your contacts' details or your card visitors' details for this. Advertisers receive aggregate numbers only, never your identity.
To stop the messages, use the unsubscribe link or reply STOP on the message itself, or write to hello@jqode.com — we will action it within seven days and keep a note that you opted out so it sticks. Service messages (a one-time code, an order update, a booking request) are not promotions and continue either way. Paid plans get no promotional messages and no banners.
13. Deleting your account
In the app or on the website: Settings → Account → Delete account. The full explanation lives at vqard.co/delete-account, and you can use it without signing in.
Deletion is immediate and cannot be undone. It removes your cards, sections, fields and profiles; your contacts, exchanges and notes; your card's analytics and visit history; your orders and physical-card records; your calendar busy times; and your sign-in, access tokens and push registrations. Your account id is unlinked from any crash log it appears in. After that, anyone who taps or scans your printed cards sees an inactive card.
What survives: invoices and payment references we are legally required to keep, and aggregate counts that identify nobody. If you cannot sign in, email hello@jqode.com from the phone number or email address on the account and we will delete it for you.
14. Children
vQard is a business tool for adults. It is not intended for anyone under 18, we do not knowingly collect data from anyone under 18, and we do not direct any of it at children. If you believe a child has created an account or appears on a card, write to hello@jqode.com and we will remove it.
15. Security
Everything travels over HTTPS, on both the website and the apps, and our domains are on the browser's strict-transport list so a connection cannot be downgraded. Sign-in sessions are signed and expire. Access to production data is limited to the people who run the service.
We are a small team and we will not pretend otherwise: we hold no security certification and we make no claim to one. No service can promise perfect security. If you find a vulnerability, please tell us at hello@jqode.com before telling anyone else.
16. Your choices
- Edit or delete anything on your card at any time — including hiding it from the public entirely with profiles.
- Ask us for a copy of the data held about you, ask us to correct it, or ask us to delete it: hello@jqode.com.
- Turn off promotional messages (section 12).
- Withdraw a phone permission in your phone's settings; the feature behind it simply stops.
- View a card without telling anyone who you are — verification is always your decision, and declining it only hides content the owner chose to lock.
- If you are in a contact list belonging to a vQard user and want to be removed, ask them, or write to us and we will pass it on.
17. Changes to this policy
When we change this policy we update the date at the top. If a change materially affects what we collect or who receives it, we will tell you in the app or by message before it takes effect.
18. Contact us, and our grievance officer
For anything about your data — questions, access, correction, deletion, or a complaint — write to hello@jqode.com. The same address handles orders, delivery and product help, and +91 79815 80713 reaches us by phone.
In line with India's Information Technology Rules and the Digital Personal Data Protection Act 2023, complaints and data-principal requests can be addressed to our grievance officer:
- Officer
- Anil Kumar Gurram
- Entity
- jQode Technologies
- hello@jqode.com
- Address
- A1-1402, MyScape SanctuaryHafeezpet, Bikshapathi NagarHyderabad, Telangana 500049India
We acknowledge every complaint within 24 hours and resolve it within 15 days. Please write from the phone number or email address on your account, so we can be sure we are talking to you.
See also our terms of use and how to delete your account.