Privacy Policy
Last updated
This policy explains what MyDBC collects, why, how long it is kept, and how to get a copy of it or have it deleted. It describes what the product actually does — not a generic template.
1. Who is responsible
MyDBC (“we”) operates the digital business card service at mydbc.ai. The data controller is [registered company name and address], and privacy questions go to [privacy contact email].
Two different roles. For your own account we are the controller. For the contacts you collect through your card we are a processor acting on your instructions — you decide what to collect and why, and you are responsible for having a lawful basis to do so.
2. What we collect
Your account. Email address, name, an optional profile photo, and a password stored only as an Argon2id hash — we never hold the password itself. If you sign in with Google we receive your email, name and profile picture from Google.
Your card content. Whatever you put on a card: job title, company, phone numbers, email addresses, links, photos, logos and any text blocks. A published card is public by design — anyone with the link can read it.
Contacts you capture. When someone fills in your card’s exchange form we store the name, email, phone, company, job title and message they submit, plus any notes and tags you add afterwards. This is personal data about them; see §7.
Billing. Handled by Stripe. We store your Stripe customer and subscription identifiers, plan tier and status. We never see or store your card number.
Card view statistics. Described in detail below, because how we do this is unusual.
3. Card statistics — and why there is no cookie banner
When someone views your card we record the event so you can see view counts. We do not use cookies or any other identifier stored on the visitor’s device, which is why this site shows no cookie consent banner: there is nothing to consent to.
To count returning visits within a day without identifying anyone, we compute a one-way hash of the visitor’s IP address, their browser’s user-agent string, the date, the card being viewed, and a secret key. The IP address itself is never written to our database. The hash changes every day and differs per card, so it cannot be used to follow anyone between cards or across days, and it cannot be reversed into an IP.
We also store a coarse device class (mobile, tablet, desktop) and how the visitor arrived (direct, social, search, other) — never the full referring URL.
4. Why we are allowed to use it
To provide the service (Art. 6(1)(b), contract) — your account, your cards, publishing them, taking payment.
Legitimate interests (Art. 6(1)(f)) — keeping the service secure, preventing abuse, and giving you aggregate statistics about your own cards. We consider this proportionate specifically because the statistics identify nobody.
Legal obligation (Art. 6(1)(c)) — retaining billing records for tax purposes.
6. How long we keep it
These windows are enforced by an automated job, not by policy alone:
- Account data — until you delete your account.
- Deleted cards and contacts — permanently destroyed 30 days after deletion, so a mistake stays recoverable for a month.
- Card statistics — 26 months, then deleted.
- Sign-in links and session tokens — deleted as soon as they expire.
- Billing records — kept as long as tax law requires. [state the period for your jurisdiction]
When you delete your account we erase your email, name and profile photo and destroy your password. An anonymous record is kept only to preserve the integrity of shared team history, and it contains nothing that identifies you.
7. If someone shared their details with a card owner
If you filled in a form on someone’s MyDBC card, they decide how your details are used — we only store the data for them. Contact the card owner directly to have it corrected or removed.
If you cannot reach them, write to [privacy contact email] and we will help identify the card owner and pass your request on.
8. Your rights
If you have a MyDBC account you can act on most of these yourself:
- Access and portability — download everything we hold about you as JSON from Settings → Account, or via
GET /v1/account/export. - Rectification — edit your details in Settings at any time.
- Erasure — delete your account from Settings. This is immediate and cannot be undone.
- Objection and restriction — write to us and we will stop the processing in question or explain why we cannot.
We answer within one month. You can also complain to your data protection authority — [name the supervisory authority for your establishment].
9. How it is protected
Passwords are hashed with Argon2id. Traffic is encrypted with TLS. Each customer’s data is isolated at the database level by row-level security, so one account’s queries cannot reach another’s rows. Uploaded HTML card templates are rendered inside a sandboxed frame that cannot execute scripts.
If a breach puts your rights at risk we will notify the supervisory authority within 72 hours and tell you directly where required. [confirm your incident response contact]
10. International transfers
Stripe and Google may process data outside your country under Standard Contractual Clauses or an adequacy decision. [confirm where your server is located and list the transfer safeguards]
11. Changes
If we change how we use personal data in a way that affects you, we will tell you before it takes effect rather than silently updating this page. The date at the top always reflects the last material change.
