Authenticated workspace
- Account controls
- Draft management
- Company administration
- Staff invitations
- Field permissions
Security and privacy
CardGoGo separates account and workspace management from information intentionally published through a digital business card.
Effective date: 15 July 2026
Last updated: 15 July 2026
The public personal route displays only published personal cards.
The public staff-card route displays only published staff cards from active companies.
Active QR/NFC links refuse unavailable, unpublished or archived targets.
Draft cards are not displayed through CardGoGo's normal public personal-card or staff-card routes. Account holders may use authenticated preview functions to review a card before publishing.
Company owners and administrators manage company-level information. Company-controlled fields remain locked to ordinary employees. Employees may edit permitted fields, and company workspace management requires authenticated access.
Company administrators are responsible for access removal and for ensuring they have authority to manage employee information.
A public QR or NFC item may be used by anyone who can scan or tap it. These methods do not provide confidential access control.
CardGoGo may record interaction events for published cards. If a visitor explicitly allows first-party acquisition attribution, CardGoGo may also record opaque visitor/session IDs, landing paths, broad source classifications and limited CTA or tool milestones. Contact-generator values, fingerprinting and third-party advertising pixels are excluded.
CardGoGo's card-interaction event records do not intentionally record IP addresses or browser user-agent information. Hosting and infrastructure providers may separately process technical logs for security, delivery and operations.
Limited residual files, analytics events, infrastructure logs, backups or information associated with a continuing company workspace may remain as explained in the Privacy Policy.
Use a strong, unique password where password-based sign-in is available
Protect the registered email account
Sign out from shared devices
Review public-card information
Publish only professional information intended for sharing
Remove access when staff leave
Check company roles and permissions
Test QR and NFC destinations
Report suspicious behaviour
The fields shown on a published card can be viewed by people with the public link, QR destination or NFC destination. This may include professional profile and contact information selected by the user or company.
No. Published personal cards and published staff cards are browser-based public card experiences.
No. Public cards display published profile information. Account controls, draft management, company administration, invitations and field permissions require authenticated workspace access.
Yes. Company owners and administrators can manage company-level information and configure which staff-card fields employees may edit.
No. A QR code or compatible NFC item is a sharing method, not confidential access control. Anyone who can scan or tap the item may be able to open the linked destination.
Yes. CardGoGo includes an account export function. The export includes supported account information, preferences, personal cards and active workspace memberships.
Account deletion requires explicit confirmation. It may be blocked if the user is the sole owner of an active company. The current account-deletion process removes core account, personal-card, membership and authentication records.
Some uploaded files, analytics events, infrastructure logs, backups or continuing company records may remain where technically necessary, required for security, or connected to another continuing account or workspace.
CardGoGo uses Supabase for authentication, database and file storage, Vercel for website hosting and application deployment, Resend for invitation email delivery and service emails when enabled, and Google Maps for external address and map links.
Contact the Data Protection Officer at support@cardgogo.com.
Check which details will be public and publish only professional information you intend to share.