RencardBack to home

Privacy Policy

Last updated · August 27, 2026

Your business cards contain some of the most personal professional data you own. This policy explains, in plain language, what Rencard collects, why, and the control you have over it.

01What data we collect

Account data: your name and email address when you sign up with Google or a magic link.

Business card photos: the front and back images of cards you choose to scan.

Extracted contact data: names, titles, companies, emails, phone numbers, addresses, and notes that our AI extracts from your card scans and that you save to your Rencard.

Usage data: upload credit balance, referral activity, and basic product analytics used to operate and improve the service.

02How we use your data

To provide the service: storing your cards, making your contacts searchable, and rendering your public card profile if you choose to publish one.

AI scanning: card photos you upload are sent to our AI extraction pipeline so we can turn them into structured contacts.

To operate billing, referrals, and upload quotas, and to communicate essential service updates.

We do not sell your personal data, and we do not use your card images to train AI models.

03Who we share it with

Supabase: hosts our database and file storage. Your account data, card images, and contacts are stored on Supabase infrastructure with row-level security.

OpenAI: card images you scan are processed by OpenAI's GPT-4o Vision API solely to extract contact details. Images are transmitted for processing and are not used by us for any other purpose.

When you scan a third party business card, that card may contain personal information about a person who has not directly interacted with Rencard. By scanning a card, you confirm that you received it voluntarily from that person and have a legitimate reason to store their contact information. You are responsible for ensuring your use of their data complies with applicable laws.

Stripe: processes subscription payments (see Payment Information below).

We may disclose data if required by law or to protect the rights and safety of our users.

04Payment Information

Rencard does not collect, store, or process any payment information on our servers. All payments are handled securely by Stripe, a PCI-DSS Level 1 certified payment processor. When you upgrade to Rencard Pro, you are redirected to Stripe's secure hosted checkout page where your card details are entered directly. Rencard only stores a Stripe customer reference ID to manage your subscription status — we never see or store your card number, expiry date, CVV, or billing address. For more information on how Stripe handles your payment data, visit stripe.com/privacy.

05Your rights

Access: you can view all data we hold about you from your dashboard and settings at any time.

Delete: you can delete individual cards, or request full account deletion, which removes your profile, contacts, and card images from our systems.

Export: you can download individual contacts as vCard files directly from each contact's detail page. Full account data export is on our roadmap — in the meantime, you may request a copy of your data by emailing privacy@rencard.co and we will respond within 30 days.

To exercise any of these rights, contact privacy@rencard.co.

06Data retention

We retain your data for as long as your account is active. When you delete a card, its images and extracted data are removed from active storage. When you delete your account, we delete your personal data within 30 days, except where retention is required by law.

07GDPR and International Users

If you are located in the European Union or European Economic Area, you have additional rights under the General Data Protection Regulation including the right to data portability and the right to lodge a complaint with your local supervisory authority. Rencard processes EU user data under the lawful basis of contract performance and legitimate interest. EU users may request a Data Processing Agreement by contacting privacy@rencard.co. Our data processors Supabase and OpenAI maintain their own GDPR compliance programs.

08Cookies

We use a small number of essential cookies and local storage entries to keep you signed in and remember your theme preference. We do not use third-party advertising or tracking cookies.

09Contact us

Questions, requests, or concerns about this policy? Email us at privacy@rencard.co and we will respond within 24 hours.