Security and privacy

Understand what is public, private and under your control

CardGoGo separates account and workspace management from information intentionally published through a digital business card.

Effective date: 15 July 2026

Last updated: 15 July 2026

Public versus authenticated areas

Authenticated workspace

  • Account controls
  • Draft management
  • Company administration
  • Staff invitations
  • Field permissions

Public card experience

  • Published profile
  • Public contact information
  • QR-code destination
  • NFC destination
  • Save, call, email and sharing actions

Draft and published cards

Personal cards

The public personal route displays only published personal cards.

Staff cards

The public staff-card route displays only published staff cards from active companies.

QR and NFC links

Active QR/NFC links refuse unavailable, unpublished or archived targets.

Draft cards are not displayed through CardGoGo's normal public personal-card or staff-card routes. Account holders may use authenticated preview functions to review a card before publishing.

Company roles and permissions

Company owners and administrators manage company-level information. Company-controlled fields remain locked to ordinary employees. Employees may edit permitted fields, and company workspace management requires authenticated access.

Company administrators are responsible for access removal and for ensuring they have authority to manage employee information.

QR and NFC visibility

A public QR or NFC item may be used by anyone who can scan or tap it. These methods do not provide confidential access control.

QR sharing

  • Test before printing
  • Confirm the destination
  • Treat the code as public

NFC sharing

  • Test before locking physical products
  • Confirm phone compatibility
  • Treat the tap destination as public

Published destination checks

  • Available published profiles may open
  • Unpublished profiles are refused
  • Archived or unavailable targets are refused

First-party analytics

CardGoGo may record interaction events for published cards. If a visitor explicitly allows first-party acquisition attribution, CardGoGo may also record opaque visitor/session IDs, landing paths, broad source classifications and limited CTA or tool milestones. Contact-generator values, fingerprinting and third-party advertising pixels are excluded.

CardGoGo's card-interaction event records do not intentionally record IP addresses or browser user-agent information. Hosting and infrastructure providers may separately process technical logs for security, delivery and operations.

Export and account deletion

Account export

  • Available through CardGoGo's account export function.
  • The export includes supported account information, preferences, personal cards and active workspace memberships.

Account deletion

  • Requires explicit confirmation
  • Sole owners of active companies must resolve ownership first
  • The current account-deletion process removes core account, personal-card, membership and authentication records

Limited residual files, analytics events, infrastructure logs, backups or information associated with a continuing company workspace may remain as explained in the Privacy Policy.

Service providers

Supabase

  • Authentication
  • Database
  • File storage

Vercel

  • Website hosting
  • Application deployment

Resend

  • Invitation email delivery
  • Service emails when enabled

Google Maps

  • External address and map links
  • Opened only when selected by the visitor
  • Subject to Google's applicable terms and policies

Practical security steps

Use a strong, unique password where password-based sign-in is available

Protect the registered email account

Sign out from shared devices

Review public-card information

Publish only professional information intended for sharing

Remove access when staff leave

Check company roles and permissions

Test QR and NFC destinations

Report suspicious behaviour

Contact CardGoGo about privacy or security

Data Protection Officer
PWK Holdings Pte. Ltd.
UEN 202003787W
22 Sin Ming Lane
Midview City #06-76
Singapore 573969
support@cardgogo.com

Security and privacy questions

The fields shown on a published card can be viewed by people with the public link, QR destination or NFC destination. This may include professional profile and contact information selected by the user or company.

Review your information before publishing

Check which details will be public and publish only professional information you intend to share.