1. Data controller
Reverdin Studio, Corso Vittorio Emanuele II 154, 00186 Rome, Italy, VAT number IT17458801002. Publication director: Marc Reverdin. Contact: privacy@getcardscan.com.
2. Data we collect
We collect the following data:
- Account data: email address, hashed password, account creation date.
- Connection data: IP address, date and time of connections, session identifier.
- Contact data: information extracted from scanned business cards (name, company, email, phone, address, etc.).
- Business card images: photos submitted for OCR processing.
We use Umami, a self-hosted, cookieless and anonymous audience-measurement tool. This measurement cannot identify individual users, is not cross-referenced with any third-party data, and serves no advertising or profiling purpose.
3. Legal basis for processing
- Performance of a contract (Art. 6.1.b GDPR): account management, image processing, contact storage.
- Legitimate interest (Art. 6.1.f GDPR): service security, abuse prevention, access logs, anonymous audience measurement.
- Consent (Art. 6.1.a GDPR): any marketing communications (can be disabled at any time).
4. Retention period
- Account and contact data: retained for as long as the account is active, then deleted within 30 days of closure.
- Connection logs: 12 months.
- Business card images: deleted after data extraction.
5. Your rights
In accordance with the GDPR, you have the following rights over your personal data:
- Right of access: obtain a copy of your data.
- Right of rectification: correct inaccurate data.
- Right to erasure: request the deletion of your data ("right to be forgotten").
- Right to portability: receive your data in a structured, interoperable format.
- Right to object: object to certain processing based on legitimate interest.
To exercise these rights: privacy@getcardscan.com. We will respond within 30 days. In the event of a dispute, you may contact the French data protection authority, the CNIL (cnil.fr), or your local supervisory authority.
6. Sub-processors
We use the following sub-processors, each limited to the purpose stated:
- Hetzner Online GmbH (Germany) — server and data hosting.
- Anthropic, via a self-hosted gateway — AI extraction of contact information; images are never used to train a model.
- Stripe — payment processing (EU/US, governed by Standard Contractual Clauses).
- Umami, self-hosted — anonymous, cookieless audience measurement.
- Self-hosted mail server — sending transactional emails (confirmation, password reset, etc.).
- GlitchTip, self-hosted — technical error tracking, with no personal content.
- Nextcloud / CardDAV — contact synchronization, only if you enable this integration.
- Google Contacts — contact synchronization, only if you connect this account.
- Microsoft Contacts — contact synchronization, only if you connect this account.
- Agora — contact synchronization to your Agora instance, only if you connect this service.
7. Cookies and audience measurement
CardScan only uses session cookies that are strictly necessary for authentication. No advertising, tracking or third-party cookies are used.
For audience measurement, we use Umami, a self-hosted, anonymous, cookieless tool. Under CNIL guidance, this kind of measurement is exempt from consent: it cannot identify individual users, is not shared with any third party, and serves no advertising purpose.