Privacy Policy
Last updated: 1 Maj 2026
1. Introduction
This Privacy Policy explains how AG Studio ("we", "us") collects, uses, shares, and protects information in connection with the myCard.al digital business card service. By using the Service, you consent to the practices described here.
2. Information We Collect
Account information: email address, password (hashed), display name, and optional profile data you provide (job title, company, bio, contact details, photos, links).
Usage data: when someone visits a public profile, we log the event (view, click, save), source (NFC, QR, direct, share), device type, operating system, IP address, and approximate country derived from the IP.
Technical data: browser type, language, screen size, and standard server logs (timestamps, request URLs).
3. How We Use Information
We use the data to: operate and improve the Service; provide analytics to profile owners about their cards; authenticate users; communicate with you about your account, renewals, security, and legal matters; comply with legal obligations; detect and prevent fraud or abuse.
4. Legal Basis (GDPR)
For users in the European Economic Area, we rely on the following legal bases: contract (to provide the Service you signed up for), legitimate interest (to improve the Service and prevent abuse), consent (when you explicitly accept the Terms and Privacy Policy at registration), and legal obligation(when required by law).
5. Cookies and Similar Technologies
We use a small number of essential cookies needed for authentication and session management. We do not use advertising or tracking cookies. Analytics events on public profiles are stored in our database and tied to the profile, not to a personal browser identity.
6. Sharing With Third Parties
We share data only with service providers necessary to operate the Service:
- Supabase (database and authentication, hosted in EU)
- Vercel (web hosting, with edge servers worldwide)
- Email provider (for account and renewal emails)
We do not sell your data. We do not share your data for advertising.
7. International Transfers
Some of our service providers (Vercel) may process data outside the EU. Where this happens, we rely on Standard Contractual Clauses or other legally approved mechanisms to ensure adequate protection.
8. Data Retention
Account data is kept for as long as your account is active. After account closure or 12 months of inactivity, we may delete or anonymize your data. Analytics events are retained for up to 24 months for statistical purposes. Backups are kept for 30 days.
9. Your Rights (GDPR)
You have the right to: access your data; correct inaccurate data; request deletion (right to be forgotten); restrict processing; receive your data in a portable format; object to processing; withdraw consent at any time; and lodge a complaint with a supervisory authority. To exercise any of these rights, contact us at info@mycard.al.
10. Security
We use industry-standard measures to protect your data: HTTPS encryption in transit, encryption at rest in our database, password hashing with bcrypt, optional two-factor authentication (TOTP), row-level security in the database, and rate limiting against brute-force attempts. No method is 100% secure; we cannot guarantee absolute security.
11. Children's Privacy
The Service is not intended for users under 18. We do not knowingly collect data from children. If we discover that a minor has registered, we will delete the account.
12. Public Profile Visibility
Information you put in your public profile (name, photo, contact, bio, portfolio, links) is visible to anyone who has the URL. Do not publish information you do not want to be public.
13. Changes to This Policy
We may update this Policy from time to time. The updated version will be posted at this page with a new "Last updated" date. Material changes will be communicated by email when reasonably possible.
14. Contact
For privacy questions, data requests, or complaints, contact us at info@mycard.al or by mail at Ish-Bllok, mbrapa kinema Agimi, Tirane, Shqiperi.
