Trust, Security & Privacy

We take protecting your account and the people you share your card with seriously. This page summarizes the controls we have in place today.

Encryption

All traffic to Take Mi Card is served over HTTPS/TLS. Data at rest in our managed database and storage is encrypted by our infrastructure provider.

Access controls

Row-level security policies enforce that only members of an account can read or modify that account's cards, analytics, and billing data.

Data minimization

We only store what's needed to render your digital card and run your account. Public cards intentionally expose the contact details you choose to share.

Analytics

Card views and scans are recorded as anonymized events tied to the card, never to the visitor. We don't sell your data or your visitors' data.

Authentication

Passwords are checked against the Have I Been Pwned database during signup and reset to block known-leaked credentials. Google sign-in is available.

Reporting an issue

Found a vulnerability or have a privacy question? Email security@takemicard.com and we'll respond within one business day.

This page describes our current practices and is not a certification or third-party audit statement.