Legal
CardGoGo Privacy Policy
Version 1.1
Effective date: 13 September 2026
Last updated: 13 September 2026
This Privacy Policy explains how PWK Holdings Pte. Ltd. ("PWK Holdings", "CardGoGo", "we", "us" or "our") collects, uses, discloses, stores and otherwise processes personal data in connection with the CardGoGo website, accounts, digital business cards, company workspaces and related services. CardGoGo is a product of PWK Holdings Pte. Ltd.
1. Who we are
CardGoGo is operated by PWK Holdings Pte. Ltd., UEN 202003787W.
PWK Holdings Pte. Ltd.22 Sin Ming Lane
Midview City #06-76
Singapore 573969
Our Data Protection Officer may be contacted at support@cardgogo.com.
2. Scope of this Policy
This Policy applies to CardGoGo websites, accounts, personal digital business cards, company workspaces, employee and staff cards, invitations, QR and NFC sharing, and support communications.
External websites opened from user-provided links, map links or other third-party destinations are governed by their own privacy policies.
3. Information we collect
Account and authentication information
- Account email
- Authentication identity
- Authentication-provider and session-related metadata
- Account-avatar metadata
Password credentials are handled through CardGoGo's authentication provider. CardGoGo does not store passwords in readable form in its application database.
Personal-card information
- Name
- Job title
- Company
- Biography
- Phone or mobile number
- Website
- Address
- Profile image
- Company logo
- Social links
- Slug
- Theme
- Publishing status
Company and staff information
- Company identity and profile information
- Company registration number
- Company logo and branding
- Company website, email, phone and address
- Company roles and memberships
- Employee and invitation details
- Assigned templates and staff cards
- Invitation status and expiry
Uploaded content
We process images, logos and other files submitted through supported CardGoGo workflows.
Usage and interaction information
First-party card analytics may record card or staff-card identifiers, company identifiers where applicable, event type, link type, platform, label or URL where supplied, and created timestamp. CardGoGo's application analytics do not intentionally record IP addresses or browser user-agent information in its card-interaction event records. Infrastructure and hosting providers may separately process technical logs for hosting, security and operations.
Acquisition attribution information
If you allow first-party attribution, CardGoGo records opaque random visitor and session identifiers, the landing-page path, a source classification, the referring host where supplied by the browser, and allowlisted UTM values. It may record limited milestones such as a marketing CTA click or use of the free vCard tool. It does not record search keywords, arbitrary query parameters, IP-derived identity, fingerprints, or the contact details and QR/vCard payload entered in the generator.
Support communications
We collect information users voluntarily send to support@cardgogo.com.
4. How we collect information
- Directly from users
- From company administrators
- Through use of the service
- Through published-card interactions
- From authentication and infrastructure providers
- From invitation workflows
5. How we use information
- Creating and maintaining accounts
- Providing personal and staff digital business cards
- Publishing selected profile information
- Operating company workspaces
- Managing invitations and roles
- Providing QR and NFC redirects
- Providing card analytics
- Sending service and invitation emails
- Responding to support, privacy and security requests
- Protecting the service
- Diagnosing faults
- Complying with legal obligations
- Enforcing the Terms of Service
6. Published cards and public information
Published personal and staff cards are public to people with the relevant link. QR and NFC routes may open or redirect to the same published profile. Public information may include the fields chosen by the user or company.
Users and administrators should publish only information intended for professional sharing. Recipients may copy, download or save public information, and CardGoGo cannot recall information already copied or saved by another person.
Public links and physical QR/NFC items should not be treated as confidential access controls. CardGoGo currently instructs search engines not to index public-card pages. However, this does not guarantee that published information will never be indexed, cached, copied, shared or discovered through other means.
7. Company administrators and employees
Company owners and administrators may enter and manage employee information. They must have authority to provide and manage that information. Company-controlled fields remain managed by authorised company users.
Employees may edit only fields permitted under the workspace configuration. Permitted employee edits save according to the current workflow. Employees should contact their company administrator for company-controlled information.
8. First-party analytics
CardGoGo may record first-party interaction events for published cards, such as profile views, contact-save actions, call or email actions, website clicks, map clicks, share actions, copy-link actions, QR downloads and link clicks where implemented.
These analytics are used to operate and improve CardGoGo card and workspace features. We do not describe them as anonymous. CardGoGo does not currently use Google Analytics, Meta Pixel or equivalent third-party advertising analytics in the service.
If you allow acquisition attribution, CardGoGo also uses first-party visitor and session identifiers to understand which landing pages and broad sources lead to signups, published cards, company workspaces and paid subscriptions. Google Search Console query information remains aggregate and is not linked to individual users.
9. Cookies and similar technologies
CardGoGo uses essential cookies and browser storage for authentication, session management, security and user preferences. With your choice, CardGoGo may also set a first-party opaque attribution identifier for up to 180 days and a first-party acquisition-session identifier for 30 minutes. These identifiers are not used for authentication or authorisation.
Anonymous pre-auth attribution records are scheduled for a 90-day retention window; attribution linked to a user or Company may be retained for up to 24 months for aggregate business reporting. Version one documents this retention for operational cleanup and does not add a background tracking or deletion job.
CardGoGo does not use advertising cookies, device fingerprinting, cross-site tracking or third-party behavioural-marketing trackers. You can decline attribution without losing CardGoGo functionality and can reset the browser identifiers below.
Current first-party attribution preference: not selected.
10. How we disclose information
- To the user
- To company workspace owners, administrators or members as needed
- To recipients of published cards
- To service providers
- Where required by law
- During a legitimate corporate transaction
- To protect rights, security or the service
We do not sell personal data to advertisers.
11. Service providers
We use service providers to operate CardGoGo. These include Supabase for authentication, database and file storage; Vercel for hosting and deployment; Resend for invitation email delivery where configured; and Google Maps links where a user chooses an address action. Third-party providers process information according to their roles and applicable terms.
12. International processing and transfers
CardGoGo is operated from Singapore. Service providers may process or store information in Singapore or other countries. Where personal data is transferred outside Singapore, PWK Holdings seeks to use appropriate contractual, organisational or other measures required by applicable law to protect that data.
13. Retention
We retain personal data for as long as reasonably necessary to provide CardGoGo, maintain accounts and workspaces, meet legal and operational requirements, resolve disputes, prevent abuse and enforce agreements.
Active card and workspace data may remain while the account or workspace is active. Deleted or closed-account data may remain temporarily in backups, logs or residual systems. Company records may remain where a continuing company workspace still requires them. Legal, security, dispute and accounting records may be retained for longer where needed.
CardGoGo reviews retention needs and aims to remove or anonymise information when it is no longer required.
14. Data export and deletion
Users can use the existing account export function. Account deletion requires confirmation and may be blocked if the user is the sole owner of an active company. Core account, personal-card, membership and authentication information is removed through the current workflow.
Some uploaded files, analytics events, infrastructure logs, backups or information associated with a continuing company workspace may remain after account deletion where technically necessary, required for security, or connected to another continuing account or workspace.
Users may contact support@cardgogo.com to request review of residual personal data.
15. Your rights and choices
Access
A user may request access to personal data held by PWK Holdings, subject to identity verification and applicable legal exceptions.
Correction
Users may edit supported account and card information. Employees may ask their company administrator to correct company-controlled staff information.
Withdrawal of consent
You may withdraw consent where CardGoGo's processing relies on consent by contacting the Data Protection Officer with reasonable notice. Withdrawal may limit our ability to continue providing the affected account, card, workspace, communication or other feature.
Export and deletion
See the Data export and deletion section above for currently available export and account-deletion information.
Privacy complaints
You may contact the Data Protection Officer to raise a concern about how personal data has been handled.
We may request additional information to verify your identity, authority and the account, card or workspace concerned. We will respond within the period required by applicable law.
16. Security
PWK Holdings uses reasonable administrative, technical and organisational measures appropriate to the nature of CardGoGo and the information processed. No electronic system is completely secure.
17. Data breaches
PWK Holdings will assess suspected personal-data breaches and make notifications where required by applicable law.
18. Children
CardGoGo accounts are intended for users aged 18 and above. We do not knowingly provide accounts directly to children. If information about a child may have been submitted, contact support@cardgogo.com.
19. External links
Published cards may contain user-provided links. CardGoGo is not responsible for the privacy practices of external websites or services.
20. Changes to this Privacy Policy
Updated versions will be published at /privacy and the effective date will be updated. Material changes may also be communicated by email, in-product notice or website notice where appropriate.
21. Contact and DPO
PWK Holdings Pte. Ltd.
22 Sin Ming Lane
Midview City #06-76
Singapore 573969
Email: support@cardgogo.com
When contacting us, please describe the nature of the request or concern and provide enough information for us to identify the relevant account, card or company workspace. We may request additional information to verify identity or authority.
You may contact us about access, correction, withdrawal of consent, deletion, privacy enquiries or security concerns.