Privacy
LAST UPDATED 27 August 2026
The short version
idTAG.app hosts contact pages. If you own a card, we store what you put on it. If you visit someone’s card, we count the visit without identifying you. If you choose to share your details back, those details go to that one person and nobody else. We do not sell data, and there are no third-party trackers on any page.
If you own a card
We store:
- Your email address, name and profile photo, so you can sign in and so your card has something to show.
- Everything you put on a card — title, organisation, phone numbers, bio, links, images, and your theme settings.
- The contacts people share with you through your card, until you delete them.
Fields you mark private are never rendered on the public page, never included in the downloadable contact file, and never appear in the link preview image.
If you visit a card
We record that a view happened, and whether a contact was saved or a link clicked. To tell repeat visits apart from new ones without knowing who you are, we take a one-way hash of your IP address and browser user-agent combined with a secret that changes every day.
That means the record of your visit cannot be linked back to you, and cannot even be linked to your own visit from yesterday. We do not store your IP address on those records, we do not set an analytics cookie, and we do not load any third-party script.
If you share your details
Using “Share your info” is entirely optional. When you do, we store what you typed along with the time, your browser user-agent, the page that referred you, and an approximate location no more precise than country and region. That information goes to the owner of that card, and to nobody else.
The card owner receives one email about it. If you tick the box asking for their contact card, you receive exactly one email in return. That is a one-time message, not a subscription — there is no list to unsubscribe from, and we will not email you again.
To have your details removed, ask the card owner directly, or contact us and we will remove them.
Cookies
One cookie, set only when you sign in as a card owner, which keeps you signed in. Visitors to a public card are not given a cookie at all.
How long we keep things
- Cards and contacts: until you delete them.
- Deleted cards and contacts: soft-deleted immediately (invisible everywhere) and purged afterwards.
- Analytics events: 13 months. The daily hashing secret is discarded after 35 days, after which the events are permanently anonymous.
Reporting a card
Every public card has a “Report this card” link. If someone is impersonating you or otherwise misusing the service, use it — a person reviews every report, and cards can be taken down.