Back to Home

GDPR Privacy Policy

Last Updated:

1. Introduction

Custom Made Digital s. r. o. ("we", "us", or "our") is committed to protecting your personal data and respecting your privacy rights. This GDPR Privacy Policy explains how we collect, use, store, and protect your personal information in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

2. Our Data-Protection Roles

Custom Made Digital s. r. o. is the data controller for account registration, subscriptions, security, support, service communications, and other processing for which we determine the purposes and means. If you have any questions about this policy or our data practices, please contact us:

Company: Custom Made Digital s. r. o.

Registered office: Lermontovova 911/3, 811 05 Bratislava – mestská časť Staré Mesto, Slovakia

IČO: 57 618 810

DIČ: 2122847089

Registration: Obchodný register Mestského súdu Bratislava III, oddiel Sro, vložka 199324/B

Email:support@quickcard.digital

Where data-protection law applies and a user or their organisation decides which third-party business contacts to store and how to use them, that user or organisation generally acts as controller and QuickCard.Digital processes those contacts on its documented instructions solely to provide the Wallet. The allocation of roles depends on the actual processing circumstances.

3. Personal Data We Collect

We collect and process the following categories of personal data:

3.1 Account Information:

  • Email address
  • Password (securely hashed)
  • Account creation date
  • Product update and newsletter preferences

3.2 Contact Card Information:

  • Full name
  • Job title
  • Company name
  • Phone number
  • Email address
  • Website URL
  • Social media links
  • Profile photo or logo
  • Custom attributes (Enterprise plans only)

3.3 Subscription Information:

  • Subscription plan type
  • Billing information (processed by Stripe)
  • Payment history
  • Transaction records
  • Checkout legal declarations and versions, withdrawal or money-back request content, receipt reference, processing status, and confirmation-email delivery records

3.4 Team Information (Team and Enterprise plans):

  • Team member names and roles
  • Team invitations
  • Team branding settings

3.5 Usage and Technical Data:

  • Login timestamps and failed login attempts (used for account-lockout protection: 10 failures in 15 minutes trigger a temporary lockout)
  • IP address and user agent (used for security, fraud prevention, and error diagnostics)
  • SHA-256-hashed IP address (logged on public-form submissions — newsletter, contact-sales, and share-card forwarding — to enforce per-IP rate limits)
  • Browser type and version and, when you allow optional diagnostics, approximate geographic location derived from IP (used for error grouping in our monitoring tool)
  • Application error reports, including stack trace and browser context (collected only when an error occurs)
  • QR code scan counts (aggregate counts per card; we do not record who scanned)
  • Feature usage events while you are signed in

3.6 Business Contacts Saved by Users:

A user may enter a business contact manually or import it from a MECARD or vCard QR code. We store only fields the user reviews and saves: name, organisation, job title, business email address(es), phone number(s), website URL(s), source type, creation and update timestamps, and an internal deduplication fingerprint. The QR image and raw QR payload are processed in the browser and are not uploaded or retained.

4. Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Contract Performance: To provide our services as agreed in our Terms of Service
  • Consent: When you have given explicit consent for specific processing activities
  • Legitimate Interest: To improve our services, prevent fraud, and ensure security
  • Legal Obligation: To comply with applicable laws and regulations
  • Contacts Stored by Users: The user or organisation acting as controller is responsible for identifying and documenting an applicable Article 6 legal basis for its use of a saved contact and for providing any privacy information required by Articles 13 or 14. We process the contact only to provide the Wallet on the user's instructions.

5. How We Use Your Data

We use your personal data for the following purposes:

  • To create and manage your account
  • To provide and maintain the Service
  • To process payments and manage subscriptions
  • To prove purchase-specific declarations, receive and confirm statutory withdrawal notices, assess money-back requests, prevent unwanted renewals, resolve disputes, and comply with consumer and accounting obligations
  • To generate and display your digital business cards
  • To host, synchronise, display, edit, deduplicate, delete, and, when requested, create a vCard export or browser-local static QR code for business contacts saved by a user. We do not automatically publish or contact saved people, or use saved contact content for advertising, profiling, or marketing.
  • To enable team management features
  • To send service-related notifications
  • To send release notes and product updates when you opt in
  • To provide customer support
  • To improve and optimize our Service
  • To detect and prevent fraud and abuse
  • To comply with legal obligations

6. Data Sharing and Disclosure

We do not sell your personal data. We may share your data with:

6.1 Service Providers (processors):

We rely on the following providers to operate the Service. For transfers outside the European Economic Area, we use safeguards appropriate to the transfer, such as the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework.

  • Supabase Inc. (USA) — managed PostgreSQL database, authentication, file storage, and edge functions. Data is hosted in the EU region (Frankfurt, Germany).
  • Stripe Inc. (USA / Ireland) — payment processing. We never see your full card details; Stripe is PCI DSS Level 1 certified.
  • Resend Inc. (USA) — transactional email delivery, including sign-up confirmations, password resets, team invitations, and weekly digests.
  • Cloudflare Inc. (USA) — DNS, CDN, DDoS protection, and Turnstile bot mitigation on public forms. Cloudflare receives IP addresses and request headers and may set a bot-management cookie.
  • Functional Software Inc. dba Sentry (USA) — application error monitoring. QuickCard.Digital data is hosted in Sentry's EU region (Frankfurt). Stack traces and limited browser context are sent only when an error occurs. Sentry may also infer the request IP address only if you choose Allow diagnostics in Privacy settings.
  • Vercel Inc. (USA) — static hosting and CDN for the QuickCard.Digital frontend.
  • Google LLC (USA) — Google Sign-In identity provider. Used only if you choose Sign in with Google; we receive your Google email address and profile name.
  • Better Stack (Czech Republic / EU) — public-website uptime monitoring. It receives no user data, only HTTPS checks of our public homepage.

6.2 Team Members: With other members of your team (Team and Enterprise plans only)

6.3 Legal Requirements: When required by law or to protect our rights and safety

6.4 Business Transfers: In connection with a merger, acquisition, or sale of assets

6.5 User-Initiated Contact Sharing: Saved contacts are visible only to the account that stored them by default; they are not automatically shared with team members or made public. Share or Download creates a vCard in the browser and passes it to the app, device, or recipient selected by the user. Show QR encodes that same vCard locally in the browser; it does not publish the contact or create a public link.

7. Data Storage and Security

7.1 Storage Location: Account data, contact cards, uploaded files, and authentication records are stored in Supabase's EU region (Frankfurt, Germany) with automatic backups and redundancy. Application error reports are stored in Sentry's EU region (Frankfurt). Some supporting providers (Stripe, Resend, Cloudflare, Vercel, and Google) are headquartered in the United States and may process related metadata, such as payment records, email delivery logs, request IP addresses, and OAuth profile data, on US-based infrastructure using the safeguards described in section 10.

7.2 Security Measures:

  • Encryption in transit (TLS)
  • Passwords are securely hashed
  • Regular security audits and updates
  • Access controls and authentication
  • Automated backup systems

7.3 Retention Period: We retain personal data while your account is active or as needed to provide the Service. Newsletter and product-update preferences are retained until you unsubscribe or request deletion. When account deletion is completed, account content is removed from active application systems. Checkout declarations, payment, withdrawal, refund, confirmation-delivery, and related audit records may remain for the periods required to prove a contract or notice, meet consumer and accounting duties, establish or defend legal claims, and prevent repeated or fraudulent guarantee requests. Other limited records may be retained where necessary to resolve disputes, prevent fraud, or maintain security, and residual copies may remain temporarily in protected backups until they are overwritten under our providers' retention schedules.

7.4 User-Saved Contacts: A saved contact remains until the user deletes it or deletes the account, including after a paid-plan downgrade; read and delete access remains available after downgrade. Deleted contacts are removed from active systems, while residual protected backups are handled under section 7.3.

8. Your GDPR Rights

Under GDPR, you have the following rights:

8.1 Right to Access: Request a copy of your personal data

8.2 Right to Rectification: Correct inaccurate or incomplete data

8.3 Right to Erasure (Right to be Forgotten): Request deletion of your data

8.4 Right to Restrict Processing: Limit how we use your data

8.5 Right to Data Portability: Receive your data in a machine-readable format

8.6 Right to Object: Object to processing based on legitimate interests

8.7 Right to Withdraw Consent: Withdraw consent at any time

8.8 Right to Lodge a Complaint: You have the right to file a complaint with the Slovak supervisory authority:

Office for Personal Data Protection of the Slovak Republic
Galvaniho 7/B, 821 04 Bratislava, Slovak Republic
dataprotection.gov.sk

If a saved contact concerns you, contact the user or organisation that stored it when known. You may also contact us with enough information to identify the record. For processing we control, we handle the request directly. For contact data processed on a user's behalf, we verify the request as appropriate, securely route it to and assist the relevant controller, and do not unnecessarily disclose another user's account details.

To exercise any of these rights, please contact us at support@quickcard.digital

9. Cookies and Browser Storage

We use only essential cookies and browser storage:

  • Authentication tokens — stored in browser localStorage by Supabase Auth so that you stay signed in between visits
  • Cloudflare bot-management cookie (__cf_bm) — set by Cloudflare on requests to protect against automated abuse; it expires within 30 minutes of inactivity
  • Cloudflare Turnstile — may set a short-lived cookie during bot-detection challenges on public forms, including sign-up, login, password reset, contact-sales, and newsletter forms
  • Language preference — stored in browser localStorage to remember your selected interface language

We do not use third-party advertising cookies, behavioral tracking cookies, or product analytics cookies.

10. International Data Transfers

Your account data, contact cards, uploaded files, and application error reports are stored within the European Union (Supabase EU and Sentry Frankfurt). Several of our service providers — Stripe, Resend, Cloudflare, Vercel, and Google — are headquartered in the United States and may process related metadata, such as payment records, email delivery logs, request IP addresses, and OAuth profile data, on US-based infrastructure.

For transfers of personal data outside the European Economic Area, we use safeguards appropriate to the transfer, including the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework, to ensure your data receives an equivalent level of protection.

11. Children's Privacy

Our Service is not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information.

12. Personal Data Breach Notification

If a personal data breach is likely to result in a risk to individuals' rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of it. If the breach is likely to result in a high risk, we will also inform affected individuals without undue delay, unless an exception under GDPR applies.

13. Changes to This Policy

We will publish the updated version in our Service and notify you of significant changes by email or through a notice in the Service. If a change to the purpose or legal basis of processing requires your consent, we will ask for it separately.

14. Contact Us

If you have any questions about this GDPR Privacy Policy or how we handle your personal data, please contact us:

Company: Custom Made Digital s. r. o.

Registered office: Lermontovova 911/3, 811 05 Bratislava – mestská časť Staré Mesto, Slovakia

IČO: 57 618 810

DIČ: 2122847089

Registration: Obchodný register Mestského súdu Bratislava III, oddiel Sro, vložka 199324/B

Email:support@quickcard.digital