Blog

Privacy and security of digital business cards: who sees what?

What is visible on the card page, what is not collected from visitors, where the data lives, the account door and roles, the leaver's card and nine questions to ask a supplier.

A digital business card means putting your contact details on a public page; it contains personal data. "Who sees what, what is stored, what happens to a leaver's card?" come up in every company purchase, and they should. This article walks through the places to look at in a digital business card platform from a privacy and security angle, separately for the card owner, the visitor and the company admin. No inflated promises; concrete items you can check.

What is visible on the card page, and what is not

The card page is public by design: anyone with the link sees the name, title, phone, email and the links added. That is why the card owner and the company decide together what goes on the card; a work line instead of a personal mobile and the office address instead of a home address are the common choices. When a card is deactivated, its link answers "gone" instead of showing old details, so a leaver's information does not stay in circulation.

What is collected from the visitor

The identity of the person opening the card page is not collected. The numbers on the analytics screen (views, link taps, country breakdown) say how much the card was shared, not who looked; the visitor gets the information without leaving a name, phone or account. If a visitor wants to talk to you, they do it themselves through the contact form on the card page; below the form it says the details are passed only to the card owner and used for nothing else, with a link to the privacy policy. That is the privacy notice the law asks for, in its card-page form. Details are in the lead capture article.

Where the data lives and how it travels

Ask two questions: where is the data kept and how does it travel? On our platform the data is kept on servers in Turkey; every request between browser and server goes over an encrypted connection (HTTPS), and unencrypted addresses are redirected to encrypted ones. Account passwords are not stored in plain text; they are kept as irreversible hashes. These are the first three items to ask a supplier, and a platform that cannot answer "yes" is not suitable for company use.

Account security

The panel where cards are managed is the door to the data. Items to check: temporary lock-out after repeated failed sign-ins (on the platform, fifteen minutes after five attempts), two-step verification that each user can switch on for their own account (make it a rule for admins), the ability to list sessions and end them remotely, and an audit log of every change made in the panel. The audit log answers "who changed what, and when"; when a card's phone number changes, it is visible who did it.

Roles: not everyone sees everything

A company account has three roles: admin (manages everything), editor (edits cards) and viewer (only looks). The sales manager edits the team's cards but does not touch subscription and payment settings; accounting sees the payment page but does not touch cards. Separating roles reduces accidental changes and unnecessary access. See the team management article for the team setup.

The leaver

This is the item most often skipped. When an employee leaves, the admin deactivates the card: the link and the QR code no longer show details, and the card slot is freed for the next hire. It does not matter that the card reached customers; when a customer opens it they see a closed card, not old details. The person's own LinkedIn profile goes with them; the card the company issued stays with the company. That separation removes the "collect it back" problem for business cards.

The list to ask a supplier

Where is the data kept? Is the connection encrypted? How are passwords stored? What is collected from visitors, and does the form carry a privacy notice? Is there a lock-out after failed sign-ins, and two-step verification? Are changes written to an audit log? Can roles be separated? What does the link show once a leaver's card is deactivated? Can the data be exported? Get the answers to these nine questions in writing; better still if the answers can be seen in the product itself (in the panel, on the card page). See the digital business card page for the whole product.

Summary

Security in a digital business card starts with what is written on the card page, continues with what is not collected from the visitor, is protected by the account door and the roles, and is completed by deactivating a leaver's card. Each of these can be checked; check them.