Privacy Policy
Effective September 1, 2026
This Privacy Policy explains what personal information Vellcard ("Vellcard", "we") collects, why we collect it, and what we do with it. It applies to vellcard.com and any card page hosted there.
1. What we collect
Account information:
- The email address and display name you sign up with.
- A password, stored only as a bcrypt hash — we never see the plaintext.
- Your plan (Free or Pro) and, if you subscribe, a Stripe customer ID and subscription ID so we can look up your billing status.
Card content: whatever you put on your card — name, title, company, phone, email, links, and a photo if you upload one. This content is public because your card page is public.
Analytics: a running count of how many times each of your cards has been viewed and how many times a visitor saved it as a contact. We don't attach visitor identity to those counts.
Technical logs: our web server keeps short-term access logs (IP address, request path, timestamp, user agent) for security and debugging. These are rotated regularly and not linked to your account unless we're investigating a specific abuse or security incident.
Cookies: a single session cookie (vcard_session) so you stay logged in. It's HTTP-only, same-site, and set only after you sign in. We don't use tracking, advertising, or analytics cookies, and we don't load third-party trackers on our pages.
2. How we use it
- To run the service — render your card, generate your .vcf and QR code, count views and saves for your dashboard.
- To send transactional email — account verification, password reset, billing receipts, and security notices — via our email provider.
- To process subscriptions — via Stripe.
- To keep the service safe — investigate abuse, prevent fraud, enforce our Terms.
We don't sell your data, we don't rent it, we don't train AI models on it, and we don't use it for advertising.
3. Who we share it with
We only share information with the vendors we need to run the service:
- Stripe — for payment processing. When you subscribe, Stripe collects your card details directly (we never see them) and we store only the Stripe customer and subscription IDs. See Stripe's privacy policy.
- Resend — to deliver transactional email. See Resend's privacy policy.
- Cloudflare — as our domain registrar and DNS provider. Cloudflare does not proxy our traffic.
- Hostinger — as our server host. Your data lives on a server we rent from them.
We may also disclose information if we're required to by law (subpoena, court order) or to protect the rights, property, or safety of Vellcard, our users, or the public. If that happens and we're legally allowed to notify you, we will.
4. Where your data lives
Vellcard runs on a single Linux server hosted in the United States. Uploaded photos and the SQLite database are stored on that server. We take a compressed database snapshot every night and keep the last 14 days of backups on the same server. If you sign up from outside the U.S., note that your information will be transferred to and processed in the United States.
5. How long we keep it
We keep your account information for as long as your account is active. When you delete your account we remove your account and cards within 30 days from our live database, and the data ages out of our nightly backups within another 14 days.
Stripe keeps records of your payments independently — that's required for tax and financial regulation. See Stripe's policy for their retention terms.
6. Your rights
You can, at any time:
- Access — ask us for a copy of the data we hold about you.
- Correct — update your card content and profile yourself from your dashboard; email us for anything else.
- Delete — ask us to delete your account and card data.
- Export — ask us for your card content as JSON.
- Object — tell us to stop processing your data (in practice this means closing your account, because we only process what we need to run the service).
Email us at eliasrasta25@gmail.com and we'll handle any of these within 30 days. If you're in the EU, UK, or California, you have these rights under GDPR / UK GDPR / CCPA; you're welcome to invoke them by name.
7. Security
Vellcard is served over HTTPS. Passwords are hashed with bcrypt. Session cookies are HTTP-only and same-site. We keep the server patched and behind a firewall that allows only SSH, HTTP, and HTTPS. No system is perfectly secure — if we discover a breach that affects you we'll let you know by email as soon as we reasonably can.
8. Children
Vellcard is not directed to children under 13, and we don't knowingly collect information from them. If you believe a child has given us information, please contact us and we'll delete it.
9. Changes to this policy
We may update this Privacy Policy from time to time. If a change is material we'll notify you by email at least 30 days before it takes effect. The "Effective" date above tells you when the current version took effect.
10. Contact
Questions, or want to exercise any of the rights above? Email eliasrasta25@gmail.com.