Trust, Security & Privacy
We take protecting your account and the people you share your card with seriously. This page summarizes the controls we have in place today.
Encryption
All traffic to Take Mi Card is served over HTTPS/TLS. Data at rest in our managed database and storage is encrypted by our infrastructure provider.
Access controls
Row-level security policies enforce that only members of an account can read or modify that account's cards, analytics, and billing data.
Data minimization
We only store what's needed to render your digital card and run your account. Public cards intentionally expose the contact details you choose to share.
Analytics
Card views and scans are recorded as anonymized events tied to the card, never to the visitor. We don't sell your data or your visitors' data.
Authentication
Passwords are checked against the Have I Been Pwned database during signup and reset to block known-leaked credentials. Google sign-in is available.
Reporting an issue
Found a vulnerability or have a privacy question? Email security@takemicard.com and we'll respond within one business day.
This page describes our current practices and is not a certification or third-party audit statement.