Privacy
LAST UPDATED SEPTEMBER 1, 2026
This describes what we actually do, not what we might one day be entitled to do. Where it names a number — a retention window, a rotation schedule — that number is enforced by code that runs every night.
The short version
idTAG.apphosts contact pages. If you own a card, we store what you put on it. If you visit someone’s card, we count the visit without identifying you. If you choose to share your details back, those details go to that one person and nobody else. We do not sell data, we do not share it for advertising, and there are no third-party trackers on any page.
Who we are
idTAG.app is operated from Wesley Chapel, Florida. For anything on this page — a question, a request to see your data, a request to delete it — write to email@idtag.app.
There are two different relationships on this site, and they matter for who you ask about what:
- Account and card data. We decide how it is handled, so ask us.
- Contacts shared through someone’s card. The card owner decides how those are handled; we only store them on their behalf. Ask the card owner — or ask us and we will remove them and tell the owner.
If you own a card
We store:
- Your email address, name and profile photo, so you can sign in and so your card has something to show. If you sign in with Google or Apple, we receive your name and email address from them — nothing else, and never your password. Apple lets you hide your real email behind a private relay address; if you choose that, the relay address is what we store.
- If you subscribe to Pro: your plan, its renewal date, and a reference to your customer record at Stripe, our payment processor. Your card number goes directly to Stripe and never touches our servers — we cannot see it and do not store it.
- Everything you put on a card — title, organisation, phone numbers, bio, links, images, and your theme settings.
- The images you upload, and the resized copies we generate for the page, the link preview, and the downloadable contact file.
- The contacts people share with you through your card, until you delete them.
- The counts behind your dashboard: views, saves, and link clicks on your cards.
Fields you mark private are never rendered on the public page, never included in the downloadable contact file, and never appear in the link preview image.
If you visit a card
We record that a view happened, and whether a contact was saved or a link clicked. To tell repeat visits apart from new ones without knowing who you are, we take a one-way hash of your IP address and browser user-agent combined with a secret that changes every day.
That means the record of your visit cannot be linked back to you, and cannot even be linked to your own visit from yesterday. We do not store your IP address on those records, we do not set an analytics cookie, and we do not load any third-party analytics, advertising, or social script. The fonts are served from our own domain.
Separately, our hosting provider keeps short-lived server logs that include IP addresses, as every web server does. Those are operational — debugging, and blocking abuse — and they are not joined to the analytics above.
If you share your details
Using “Share your info” is entirely optional. When you do, we store what you typed along with the time, your browser user-agent, the page that referred you, and an approximate location no more precise than country and region. That information goes to the owner of that card, and to nobody else.
The card owner receives one email about it. If you tick the box asking for their contact card, you receive exactly one email in return. That is a one-time message, not a subscription — there is no list to unsubscribe from, and we will not email you again.
What the card owner does next is up to them, and it is their responsibility under our terms: the details are for the introduction you just made, not for a marketing list. To have your details removed, ask the card owner directly, or contact us and we will remove them.
Cookies
One cookie, set only when you sign in as a card owner, which keeps you signed in. Visitors to a public card are not given a cookie at all. No advertising cookies, no analytics cookies, no cross-site tracking — so there is no consent banner to click, because there is nothing to consent to.
Who else touches your data
We keep this list short on purpose. Each of these is a company we pay to do one job, bound to use the data only for that job:
- Vercel — hosting and delivery.
- Supabase — the database and the image storage behind it.
- Stripe — payment processing for Pro subscriptions. Stripe receives your payment details directly; we receive confirmation that you paid, never the card number.
- Resend — sending sign-in links, lead notifications, and the one-time contact email, and receiving mail sent to our support address.
- Google— only if you choose to sign in with Google, or add your card’s pass to Google Wallet.
- Apple— only if you choose to sign in with Apple, or add your card’s pass to Apple Wallet.
- Cloudflare — a bot check on the share form, where enabled. It sees the request in order to tell a human from a script; it does not profile you across sites.
Beyond that, we disclose data only when the law requires it — a valid subpoena, court order, or an urgent request to prevent serious harm. If we are ever bought or merged, your data moves with the service and this policy travels with it; you will be told before anything changes.
We have never sold personal information, we do not share it for cross-context behavioural advertising, and we have no plans to. If your browser sends a Global Privacy Control signal, there is nothing for it to switch off here.
Where it lives
Our servers and database are in the United States. If you are writing to us from outside the US, your information is processed there, under standard contractual clauses with our providers where those apply.
How long we keep things
- Cards and contacts: until you delete them.
- Deleted cards and contacts: soft-deleted immediately (invisible everywhere) and purged afterwards.
- Analytics events: 13 months. The daily hashing secret is discarded after 35 days, after which the events are permanently anonymous.
- Account records: for as long as you have an account. Ask us to close it and everything attached to it — cards, contacts, uploads — goes with it.
- Abuse reports: kept while the card they concern exists, so a pattern of behaviour is still visible the next time.
- Billing records: invoices and payment history are kept as long as tax and accounting law requires, even after an account closes.
- Support correspondence: email sent to email@idtag.app is stored in our help desk with your address, so we can answer you and see the history if you write again.
Email signatures
The signature studio builds email signatures from your own card. A signature can embed images we host — your photo, social icons, a QR code. When someone reads an email carrying your signature, their mail app fetches those images from our servers like any other image on the web. We serve them and count nothing: no open tracking, no per-message identifiers, nothing joined to the person reading.
Your rights, wherever you live
Rather than sort people by jurisdiction, we honour these requests from everyone:
- See what we hold about you.
- Get a copy of it in a portable form.
- Correct anything wrong — most of it you can edit yourself.
- Delete it.
- Object to a particular use, or ask us to restrict it while we sort something out.
- Never be discriminated against for asking. There is no worse tier of the service for people who exercise these rights.
Email email@idtag.app and we will respond within 30 days. We may need to confirm you control the account or the email address in question, which is protection for you, not an obstacle.
If you are in the UK or the EEA: our lawful bases are performance of a contract (running your account and your card), legitimate interests (keeping the service secure, and counting visits in a form that cannot identify you), consent (the details you choose to share through a card), and legal obligation. You can withdraw consent at any time, and you have the right to complain to your local supervisory authority.
Security
Everything travels over HTTPS. Sessions live in the database, so disabling an account takes effect on the very next request. There are no passwords to steal, because we don’t use any — you sign in with a one-time link, with Apple, or with Google. Access to production data is limited to the people who need it to run the service.
No service is perfectly secure, and we won’t claim otherwise. If a breach ever affects your data, we will tell you and the relevant regulators without undue delay, and we will tell you what actually happened.
Children
idTAG.app is a tool for working professionals and is not for anyone under 18. We do not knowingly collect information from children under 13. If you believe a child has given us information, write to email@idtag.app and we will delete it.
Reporting a card
Every public card has a “Report this card” link. If someone is impersonating you or otherwise misusing the service, use it — a person reviews every report, and cards can be taken down.
Changes to this policy
If we change how we handle your information, we will update the date at the top, and for anything material we will email account holders before it takes effect. We will not apply a materially different use to information we already hold without asking you first.
Questions about any of this go to email@idtag.app. A person reads that inbox.
