Privacy Policy
Effective 2026-09-21
CardWise is a business-card and contact app for Android (and, soon, iOS), with a companion website at cardwise.pt. This policy explains what personal data we collect, why, where it is stored, who else sees it, how long we keep it, and the choices you have. It is written to describe what the app actually does, feature by feature. If something here is unclear, email info@shwk.eu.
Controller. CardWise (contact: info@shwk.eu, +351 920 699 693). We are the controller of the personal data described below, except where you connect a third-party service (Google, Microsoft, HubSpot, Pipedrive), which remains a separate controller under its own policy.
1. Data you give us
Account
- Name; an email address and/or mobile number. Both are verified with a one-time code before they are used to sign in.
- A password, stored only as a salted hash. If you enable two-factor authentication, the authenticator secret is stored encrypted.
- Optional profile details: job title, company, website, address, and a profile photo.
- If you sign in with Google, Facebook or LinkedIn: your name, email address and that provider's account identifier, used only to create or sign in to your account. We do not post to those services or read anything else from them.
Contacts and cards
- Contacts you create, scan or import: name, title, company, phone numbers, emails, address, website, notes, groups, tags, follow-up dates, and the photo of the scanned card or signature if you keep it.
- Your own digital card and any card designs you create.
- Imports from your phone's address book, a CSV or JSON file, a Google Sheet, HubSpot or Pipedrive happen only when you start them. A HubSpot or Pipedrive API token you enter is kept on your device only, in the platform's secure storage, and never sent to our servers.
Messages and calls
- Chat messages with other CardWise users: text, images, videos, files, voice messages, polls and shared contacts, plus when they were sent, delivered and read.
- For audio and video calls made through the app: who called whom, when, and how long the call lasted. Call audio and video travel peer-to-peer over WebRTC and are never recorded or stored by us.
Bookings and calendar
- If you publish a booking page: your display name, timezone, working hours, available dates and slot length. When a guest books, we store their name, email address, chosen slot and any note they leave.
- If you book a slot with someone through their public page (with or without an account): the name, email and note you enter, which are shown to the host and used to email you a confirmation.
- If you connect Google Calendar or Microsoft Outlook: the access and refresh tokens that provider issues, and the calendar events needed to keep your CardWise calendar in sync. Tokens are stored on our servers and used only for that sync. You can disconnect at any time in the app or from the provider's account settings.
Caller ID contributions
The name and phone number of each contact you add or import into CardWise are contributed to a shared directory that lets other users see who is calling. Only those two fields are used — never photos, notes, emails, addresses, call logs or recordings. This is on by default; section 6 explains the controls, and the Caller ID page explains the feature in full.
2. Data collected automatically
- Push tokens (Firebase Cloud Messaging on Android; APNs and PushKit VoIP on iOS) so we can deliver message and call notifications and wake the app for an incoming call.
- Sync and session data: the times your device last synced, and short-lived session tokens (an access token valid for one hour; a refresh token valid for up to 60 days, revoked on sign-out).
- Server logs generated by our hosting provider when the app talks to our servers: request timestamps, endpoint, response codes and errors. These logs do not contain your contacts, messages or card contents.
- When you share your card and someone opens or saves it, we record that event so we can show it to you.
We do not use analytics, advertising or crash-reporting SDKs, and we do not collect your location. Some system permissions the app requests (camera, microphone, contacts, photos, NFC, Bluetooth, notifications, "display over other apps") are used strictly for the feature that asks for them, and only after you grant them.
3. How each feature uses your data
- Card scanning. When you are online, the photo of a paper business card is sent to OpenAI's API solely to extract the printed text into fields. The image is not used to train models and is not kept by us after extraction unless you choose to save it with the contact. Offline, recognition runs on your device (Google ML Kit) and nothing leaves the phone.
- Sharing your card. A share link or QR code points to a copy of your card that anyone with the link can open for 30 days, after which it expires. If the person who opens it has a CardWise account, they can save you in one tap and you are notified.
- Finding people you already know. When you add a contact, we check whether their phone number or email belongs to a CardWise account so the two of you can connect. Accounts that have turned off Profile Visibility are never matched or shown. A matched person may be notified that you saved their details, if they have that notification turned on.
- Follow-up reminders. If enabled, we email you when a follow-up you set is due.
- Account reminders. If you sign up without a verified phone number, we email you during a 7-day grace period; after that the account is deactivated until a number is verified.
- Blocking. Blocking a user stops their messages and calls from reaching you; the block list is stored on our servers.
- Spam reports. Reporting a number as spam in Caller ID records your account ID against that number so each person can report it once. Numbers reported by several people are shown as spam to others.
4. Legal bases (EEA/UK)
- Contract — providing the account, contacts, cards, chat, calls, bookings and sync you asked for.
- Consent — connecting a calendar or CRM, importing your phone contacts, granting device permissions, follow-up emails. You can withdraw consent at any time by disconnecting, revoking the permission, or switching the feature off.
- Legitimate interests — keeping the service secure and preventing abuse; the Caller ID directory (helping people identify unknown callers), balanced by the off switch, the withdrawal control and the public removal page described in section 6.
- Legal obligation — keeping records we are required to keep.
5. Who else sees your data
We do not sell personal data and we do not share it with advertisers or data brokers. We use these providers, each limited to one job:
- Amazon Web Services (Ireland, eu-west-1) — servers, database and file storage for everything in this policy.
- Firebase Cloud Messaging (Google) and Apple Push Notification service — delivering notifications.
- OpenAI — extracting text from card photos you scan while online.
- Resend — sending booking confirmations, follow-up reminders and account emails.
- Amazon SNS, and BulkSMSBD for Bangladeshi (+880) numbers — sending one-time verification codes by SMS.
- Google, Microsoft, HubSpot, Pipedrive — only if you connect them, and only for the sync or import you asked for.
- Other CardWise users — what you deliberately share with them: your card, messages, calls, booking slots, and a caller name via Caller ID.
- Anyone with a link — a share link you send, a booking link you publish, and files you upload (profile photos, card images, chat attachments) are stored at unguessable URLs that anyone holding the URL can open. Treat a share or booking link like the card itself.
We will disclose data if the law requires it, or to protect the rights and safety of users and the public.
6. Your controls
- Edit or delete any contact, card, design or message in the app at any time. Deleting a contact removes it from your account; the copy in someone else's account, if they saved it, is theirs.
- Profile Visibility (Settings) — off means no one can find you by phone or email, and Caller ID never names you.
- Caller ID (Settings › Caller ID) — the switch stops future contributions; Remove everything I shared withdraws every name and number your account contributed; Share phone contacts is the only way your whole address book is uploaded, and it is never automatic.
- Not a user? Anyone can check and permanently remove their own number at cardwise.pt/directory/opt-out, verified by SMS.
- Notifications — push, follow-up reminders and share notifications each have their own switch.
- Disconnect a calendar or CRM in the app; we delete the tokens we held.
- Export any contact as a vCard, and your designs as files, from the app.
- Delete your account — see Account & Data Deletion.
- GDPR / UK GDPR rights — access, rectification, erasure, restriction, portability and objection, and the right to complain to your supervisory authority (in Portugal, the CNPD). Email us to exercise any of them; we answer within one month.
7. How long we keep things
- Account, contacts, cards, designs, messages, bookings, calendar links: for as long as your account exists.
- One-time codes: 10 minutes. Sign-in exchange tokens: 60 seconds. Refresh tokens: 60 days or until sign-out.
- Card share links: 30 days. Call records (who, when, how long): 30 days.
- Caller ID directory entries: deleted 12 months after the last time anyone contributed that number. A number removed through the opt-out page stays on a permanent do-not-add list (the number only, so it cannot be re-added).
- Deactivated unverified accounts: kept so you can reactivate by verifying a number; deleted on request.
- After account deletion: removed within 30 days, except minimal records we must keep for legal or security reasons.
8. Where your data is stored
On Amazon Web Services in Ireland (EU). Providers in section 5 may process data outside the EEA (for example OpenAI and Resend in the United States); where they do, transfers rely on the EU Standard Contractual Clauses or an adequacy decision.
9. Security
All traffic is encrypted in transit. Passwords are hashed; two-factor secrets and Caller ID session data on the device are encrypted at rest; CRM tokens live only in your device's secure storage. Sessions expire and can be revoked by signing out. No system is perfectly secure — if you believe your account has been compromised, contact us immediately.
10. Children
CardWise is a professional networking tool and is not directed at children. You must be at least 16 to create an account. We delete accounts we learn belong to younger users.
11. This website
cardwise.pt sets no cookies and runs no analytics. The booking pages and the Caller ID removal page send only the details you type to our servers. Our hosting provider keeps standard server logs (IP address, time, page) for security.
12. Changes
When we change this policy in a way that matters, we'll show a notice in the app and update the effective date above. Continued use after that date means the updated policy applies.
13. Contact
Privacy questions, requests and complaints: info@shwk.eu or +351 920 699 693. Please write from the email on your account, or include the phone number on it, so we can verify it's you.