CardParse.
Legal

Privacy policy

What we hold, where, and for how long. Written to describe what the software actually does rather than to cover every eventuality.

Last updated 8 August 2026.

Who is responsible for your data

The data controller is CardParse Ltd, a company registered in England and Wales under number 17396101, whose address is Suite RA01, 195-197 Wood Street, London E17 3NU. We are registered with the Information Commissioner’s Office under ZC221379.

For anything about this policy, or to make any of the requests below, write to hello@cardparse.com.

Two kinds of people in this policy

The first is you, our customer. You signed up, you have an account, and you can see and change everything we hold about you.

The second is the person whose business card was photographed. They did not sign up to us and cannot log in. We hold their details because you collected them, and we treat that as your data held on your behalf. If they contact us we will tell them who collected the card and pass the request to you.

What we collect

  • Account details: your name, email address and a hash of your password. We never store the password itself.
  • Organisation details: your company name, plan, seat count and billing state.
  • Contact records: the fields parsed from each card, such as name, company, job title, email, phone and website, together with how confident the parser was about each one.
  • The raw text the OCR read from the card, which is kept so a parsing mistake can be diagnosed.
  • The card photograph, for seven days.
  • Security events: sign in attempts, API key use, and administrative actions, with the IP address and browser that made them.

What we do not do

  • We do not sell data to anybody, in any form.
  • We do not build a shared contact database across customers. Your records are visible only to your organisation, enforced by the database and not only by application code.
  • We do not use your contacts to train models.
  • We do not keep the GPS coordinates from card photographs. The app strips them before upload and the server strips them again on arrival.

Where it is held

In the United States. The database, the object storage holding card photographs, the text recognition service and the mail service are all configured to United States regions, and the application refuses to start if any of them is set to a region elsewhere.

Who else processes it

Only the services needed to run the product:

  • Amazon Web Services, for storage of card photographs and for text recognition.
  • Railway, for hosting the application and the database.
  • Stripe, for payments. Card numbers go to Stripe directly and never reach us.
  • Mailgun, for sending email such as verification and password resets.

How long we keep it

  • Card photographs: seven days from the scan, then deleted. This is automatic and is not something you have to ask for.
  • Contact records: until you delete them or close the account. They are yours and we do not expire them. A contact you delete is recoverable for 30 days and is then erased, along with its photograph if one is still held.
  • Security and audit logs: kept while the account is open, because they are how we answer the question of who changed what.
  • Billing records: kept as long as tax rules require, after the account closes.

What you can ask for

Export everything, correct anything, or delete the lot. Export and deletion are both available in the dashboard under account settings, and deletion removes the contacts, the photographs and the account itself. There is no recovery afterwards and no backup we can restore from, which is deliberate.

If you would rather ask a person, write to hello@cardparse.com. We do not charge for this and we do not ask why.

If we get something wrong and you are not satisfied with how we have handled it, you can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you came to us first so we can put it right, but you do not have to.

Cookies

Signing in sets one cookie, holding your session so you stay signed in. It is not readable by scripts, it is only sent over a secure connection, and it is removed when you sign out.

The public pages also run Google Analytics, which sets its own cookies to count visits and see which pages people read. It tells us how many people came and what they looked at. It is not used for advertising, we do not sell or share what it collects, and it never runs on the signed-in dashboard, so nothing about your contacts or your team reaches it.

There is no consent banner yet and there should be one, because analytics cookies are not strictly necessary and consent is the correct basis for them. It is being built. If you would rather not be counted in the meantime, a browser tracking blocker or Google’s own opt-out will stop it, and nothing on this site behaves differently when it is blocked.

Privacy Policy | CardParse · CardParse