Privacy Policy
Effective 30 August 2026
This replaces our previous Privacy Policy dated 27 August 2026.
Who we are
En Contacto is operated by Smart Digital Solutions LLC, a limited liability company registered in New Mexico, USA.
Correspondence address: 211 E 43rd St, 7th Flr #213, New York, NY 10017, USA
Email: support@encontacto.io
We have written this policy in plain language on purpose. If anything here is unclear, email us and we will explain it.
The two different roles we play
This is the most important thing to understand about how we handle information, so we have put it first.
When you are our customer, we are responsible for your information. Your account details, the content of your digital cards, your billing records and how you use the service — we decide how that information is handled, and this policy tells you what we do with it. In legal terms, we are the controller.
When someone gives their details to you, you are responsible for their information. If a person scans your card and fills in your contact form, or if you photograph their paper business card, that person's details belong to you, not to us. We simply store and process them on your behalf, following your instructions. In legal terms, you are the controller and we are your processor. We call this information Leads.
This matters because it decides who a person should contact about their information. If you are a Lead and you want your details corrected or deleted, the person or company whose card you interacted with is the right place to start. You can also contact us at support@encontacto.io and we will pass your request to them and help them act on it.
Business customers who need a formal data processing agreement covering Leads can find ours at our Data Processing Agreement.
Information we collect
Information you give us
- Account information: your name, email address, and password.
- Digital card content: anything you choose to put on a card — job title, employer, phone numbers, photograph, logo, social links, and similar. Remember that a published card is public by design.
- Payment information: handled entirely by Paddle, not by us. See Payments below.
- Support messages: what you write to us when you ask for help.
Information we collect automatically
- Usage and device information: IP address, browser and device type, pages visited, and time and date of access. This comes from our hosting provider's server logs.
- Error reports: technical details about what went wrong when something breaks.
- Product analytics: how people move through the app, including session recordings. This only runs if you accept analytics cookies. See Analytics and session recording below.
Information about other people
- Leads: contact details submitted through your digital card, or captured by you using our tools.
- Scanned business cards: see the next section.
Business card scanning
When you photograph someone's paper business card, the image is sent to OpenAI so that the text can be read and turned into contact fields. This is worth explaining carefully, because the person on that card has no relationship with us.
- The image is held in memory only for the length of the request. We do not store it. Once the details have been extracted, the image is gone from our systems.
- OpenAI retains the image for up to 30 days for abuse monitoring, then deletes it.
- OpenAI states that data sent through its API is not used to train its models. That is their commitment, described here so you know the position.
- We have a data processing agreement in place with OpenAI.
You are responsible for the cards you scan. The details belong to the person on the card. You need a lawful reason to capture and keep them, and you need to be able to answer that person if they ask you what you hold.
Why we use your information, and our legal basis
| What we do | Why | Legal basis |
|---|---|---|
| Create and run your account, publish your cards, store your Leads | To give you the service you signed up for | Performance of a contract |
| Take payment and issue invoices | To complete your purchase | Performance of a contract; legal obligation for tax records |
| Send service emails — verification, password resets, invitations, payment reminders | To operate your account | Performance of a contract |
| Keep the service secure, block bots and fraud | To protect you, us and other users | Legitimate interests |
| Fix bugs and understand how the product is used | To make the product work better | Legitimate interests, and your consent where analytics cookies are involved |
| Send marketing emails and newsletters | To tell you about the product | Consent, which you can withdraw at any time |
| Respond to legal requests and defend legal claims | Because we have to | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights. You can object at any time — see Your rights.
Analytics and session recording
We use Microsoft Clarity to understand how people use the app, which includes recording sessions. It only loads if you accept analytics cookies — if you refuse, or have not chosen yet, the script is never requested at all.
Clarity does not run on published Digital Cards or on connected custom domains. Card Visitors are not recorded.
Where it does run, masking is set to strict, and forms that handle personal information — sign-in, sign-up, lead capture and card scanning — carry additional explicit masking, so what someone types into them is not captured.
Advertising
We advertise on Google and on Meta (Facebook and Instagram), and we use their measurement tools to find out which advertisements lead to someone actually subscribing. Without that, the only way to judge an advertisement is to guess.
These load only if you accept advertising cookies. That is a separate choice from analytics in our cookie banner — accepting one does not accept the other — and if you refuse, or have not decided, neither script is requested at all.
When you complete a purchase we tell Google and Meta the amount, the currency and the transaction reference, so a sale can be matched to the advertisement that led to it. We do not send them your name or your email address.
Like our analytics, these do not run on published Digital Cards or on connected custom domains. Someone who opens a customer's card is never added to an advertising audience.
Google and Meta decide how they use what they receive for their own advertising purposes, so each acts as an independent controller rather than on our behalf. Their own privacy policies govern that.
Payments
Our payments are handled by Paddle, which acts as Merchant of Record. When you buy a subscription or a lifetime plan, your payment contract is with Paddle. Paddle collects and holds your payment details — we never see or store your card number. Paddle decides how it uses that information for its own fraud, tax and compliance purposes, so it acts as an independent controller, not on our behalf. Paddle's privacy policy governs that part of the transaction.
Who we share information with
We use the following companies to run En Contacto. Most act on our instructions; three make their own decisions about the data they receive, and we have marked those separately.
Acting on our instructions
| Company | What it handles | Where |
|---|---|---|
| NoCodeBackend | Database — accounts, cards, Leads, analytics records | USA (Austin, TX) and EU; provider based in India |
| Vercel | Hosting; processes IP addresses and server logs | USA |
| Cloudinary | Profile photos and company logos | USA |
| OpenAI | Business card scanning | USA |
| Zoho ZeptoMail | Service emails | USA |
| Cloudflare | Bot protection on sign-up and sign-in | USA |
| Microsoft Clarity | Product analytics and session recording | USA |
| Tiledesk | Live chat support | European Union (Italy) |
| GetTerms | Cookie consent banner and preferences | Australia and Singapore |
| KickoffLabs | Waitlist sign-ups and referrals | USA |
| tinyEmail | Waitlist emails | USA |
| Canny | Public feedback board | USA |
| Google Wallet pass generation | USA |
Making their own decisions
| Company | What it handles |
|---|---|
| Paddle | Payments, invoicing, tax |
| Sign in with Google | |
| Substack | Newsletter subscriptions |
| Google Ads | Advertising measurement — only with your consent |
| Meta | Advertising measurement — only with your consent |
We may also share information with professional advisers, or with courts and authorities where the law requires it. If our business is sold or merges, information may transfer as part of that — we will tell you if it happens.
We do not sell your information, and we do not sell Leads.
Sending information outside your country
We are based in the United States, and most of the companies above are too. Our database is hosted in the United States and the European Union. The company that provides it is established in India, and its staff may access data from there. India does not have an EU adequacy decision. Our cookie consent provider processes data in Australia and Singapore, neither of which has one either.
Where information moves out of the EEA, the UK or Switzerland, we rely on Standard Contractual Clauses with the company receiving it, or on their certification under the EU–US Data Privacy Framework where they hold one. You can ask us for details of the safeguards that apply to any specific transfer.
How long we keep information
- Account information and card content: for as long as your account is open.
- Leads: for as long as your account is open, subject to any limits in your plan, or until you delete them.
- Scanned card images: not kept by us at all.
- After you delete your account: deleted, including from backups, within 30 days.
- Billing records: kept as long as tax law requires.
Deleting your account takes your cards offline. Any QR code, NFC tag or printed link pointing to them stops working, and that cannot be undone.
Your rights
Wherever you live, you can ask us to:
- See what we hold about you
- Correct anything wrong or out of date
- Delete your information
- Limit how we use it
- Object to us using it, including for marketing
- Take it elsewhere in a portable format
- Withdraw consent at any time, where we relied on it
Email support@encontacto.io. We will reply within one month. We will not charge you, and we will not treat you differently for asking.
If you are unhappy with our answer, you can complain to a data protection authority — in Spain the AEPD, in the UK the ICO, and elsewhere in the EEA your national authority.
If you are a Lead
If your details were collected through someone's digital card or by them scanning your business card, that person or company decides what happens to your information. Contact them first. If you cannot reach them, email support@encontacto.io and we will forward your request and help them act on it.
Keeping information safe
Information is encrypted while it travels between your device and our systems. Backups are encrypted. Passwords are stored as scrambled hashes, never in readable form. Access is limited to those who need it. We use bot protection on sign-up and sign-in, and we support strong passwords and two-factor authentication.
No online service can promise perfect security. If a breach affects your information and puts you at risk, we will tell you and the relevant authority as the law requires.
Age
En Contacto is for people aged 18 and over. We do not knowingly collect information from anyone younger. If we learn that we have, we will delete it.
Cookies
See our Cookie Policy.
Changes to this policy
If we make a significant change, we will email registered users and post the new version here before it takes effect. The date at the top always tells you which version you are reading.