Last updated: June 4, 2026
KOCard is a digital business card service. KOCard is currently operated as a sole project and is not yet incorporated. This policy works alongside our Terms of Service. For privacy questions, email hello@ko-card.app.
When you create an account:
When your QR code is scanned or someone visits your /u/{slug} page:
We do not store IP addresses anywhere — not in our database, not in logs, not in error reports. Country and device kind are derived at the edge from request headers and the IP is discarded.
When someone fills out the “Reach out” form on a Pro profile, we collect what they type: name, an email or phone, and an optional note. This is shared with the profile owner (the lead recipient).
On the marketing site only, we use Plausible Analytics, which is cookieless and does not store IP addresses.
To operate KOCard: render your public page, log scans for your analytics, deliver leads to your inbox, send emails you've opted into (per-event notifications, weekly digest, drip, billing), prevent abuse, and process payments.
We use third-party processors to run the service:
| Processor | What | Where |
|---|---|---|
| Supabase | Database, authentication, file storage | United States |
| Stripe | Payment processing | United States |
| Resend | Outbound transactional email | United States |
| Vercel | Application hosting | United States |
| Upstash | Rate-limiting (Redis) | Multi-region |
| Sentry | Error tracking | United States |
| Axiom | Application logs | United States |
| Plausible | Marketing-site analytics (cookieless) | European Union |
| OAuth sign-in (only if you choose it) | United States |
We do not sell your data. We do not share it for advertising.
You can access your profile and data anytime in the dashboard, correct it by editing, delete it via Settings → Delete Account, and export your leads as CSV from /dashboard/leads. Residents of the EU/UK have rights under GDPR; residents of California have rights under CCPA. Email us to invoke either.
We use only the authentication session cookie (HttpOnly, Secure). We do not use analytics, advertising, or tracking cookies. The marketing site uses Plausible, which is cookieless.
We maintain reasonable administrative, technical, and physical safeguards designed to protect your information. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. If a security breach affecting your personal information occurs, we will notify affected users as required by applicable law.
Our infrastructure is primarily based in the United States. By using KOCard you consent to your data being processed in the United States.
KOCard is not intended for users under 13. We do not knowingly collect data from children under 13.
We may update this policy. The “Last updated” date at the top will change. We will email active users about material changes.