We believe your privacy is fundamental. This policy details how EasyID collects, uses, safeguards, and respects personal data across our software, NFC cards, and smart networking services.
At EasyID, we recognize that digital networking relies on mutual trust. We do not sell your personal data or your contacts to third-party data brokers. Our platform is engineered to give you complete sovereignty over what you share, who sees your contact details, and how your data is retained.
01
1. Data Controller & Scope of this Policy
Plain-Language Summary:
EasyID is the Data Controller responsible for your personal account information. This policy covers all interactions on our website, mobile interfaces, and NFC hardware.
This Privacy Policy ("Policy") describes the policies and practices of EasyID ("EasyID", "we", "us", or "our") regarding the collection, processing, storage, sharing, and protection of personal data gathered through our websites, mobile portals, digital business card pages, and contactless NFC hardware products.
For the purposes of the General Data Protection Regulation (GDPR), UK GDPR, and other international data privacy regimes, EasyID acts as the Data Controller regarding information you submit to register and manage your account. When visitors submit lead inquiries or contact information through your personal smart profile, you act as the primary Data Controller for those leads, and EasyID serves as your trusted Data Processor.
02
2. Information We Collect
Plain-Language Summary:
We collect only the information necessary to provide our services: your account credentials, your public business profile content, orders for custom NFC cards, and analytics on card taps.
We collect data across the following specific categories:
Account & Authentication Credentials: When you register, we collect your name, email address, password hash, and optional social sign-in IDs (Google authentication tokens).
Digital Profile & Business Card Content: Job title, company name, professional biography, phone numbers, website links, social media profile handles, profile photos, cover artwork, and portfolio attachments that you deliberately upload to your digital card.
Lead Generation & Form Submissions: Contact information (name, email, phone, personal message, or virtual business card exchange) submitted by individuals who tap your NFC card or scan your profile QR code.
Physical NFC Hardware Orders: Recipient name, physical delivery address, billing address, telephone number for couriers, and customized artwork files for laser engraving or UV print manufacturing.
Lost & Found Asset Reporting: Optional finder email, message, and device-prompted approximate GPS coordinates submitted voluntarily by a finder scanning a tag marked in "Lost Mode".
Automated Device & Tap Analytics: When an NFC card is tapped or a profile URL is viewed, our servers log device operating system (iOS, Android, Windows), browser user-agent, timestamp, referral source, and IP-derived approximate geolocation. Raw IP addresses are truncated or anonymized in compliance with data minimization standards.
Payment & Billing Data: Payments are processed directly through PCI-DSS compliant gateways (Stripe). EasyID never receives, processes, or stores raw credit card numbers or security CVVs; we only retain transaction receipts, plan statuses, and billing IDs.
03
3. Public Nature of Digital Profiles
Important Transparency Notice:
The fundamental purpose of EasyID is to share your contact information with networking partners. Any data you configure as "public" on your digital profile is visible to anyone who taps your card or visits your URL.
By design, an EasyID digital profile functions as a modern electronic business card. Any information you choose to display on your profile (including your phone number, email address, social links, and bio) is publicly accessible to any individual who taps your physical NFC device or accesses your unique URL slug.
You have full autonomy inside your dashboard to toggle profile visibility, password-protect your card, disable specific contact fields, or temporarily deactivate public access to your profile at any time.
04
4. How We Use Collected Information
We process personal data strictly for legitimate operational purposes:
Service Provision: To host, render, and update your smart digital profiles, dynamic QR codes, and .vcf contact downloads.
Hardware Fulfillment: To manufacture, customize, QA test, and ship physical NFC cards and accessories.
Lead Facilitation: To deliver real-time notifications to your account when a connection submits their details through your profile lead form.
Platform Analytics: To display engagement metrics (such as total taps, unique views, top clicked links, and geographic reach) in your personal dashboard.
Security & Abuse Prevention: To prevent fraud, malicious redirects, unauthorized tag cloning, and violations of our Terms of Use.
Customer Support: To troubleshoot issues, answer inquiries, and deliver service-related alerts.
05
5. Legal Bases for Processing (GDPR Art. 6)
Plain-Language Summary:
Under European law, we process your information on four legal grounds: performing our contract with you, our legitimate business interests, statutory legal requirements, or your explicit consent.
If you reside in the European Economic Area (EEA), the United Kingdom, or Switzerland, our processing of personal data is anchored on the following lawful bases:
Contractual Necessity (Art. 6(1)(b)): Processing necessary to fulfill our service contract with you.
Legitimate Interests (Art. 6(1)(f)): Processing necessary to secure our infrastructure, prevent fraudulent transactions, and improve product performance.
Consent (Art. 6(1)(a)): Where you provide explicit opt-in consent.
Legal Obligations (Art. 6(1)(c)): Compliance with statutory tax, corporate accounting, and law enforcement obligations.
06
6. Information Sharing & Third-Party Sub-processors
Plain-Language Summary:
We do not sell personal data. We only share information with vetted infrastructure vendors (hosting, payment processing, shipping couriers) necessary to keep the service running.
EasyID never monetizes personal data. We disclose information solely to the following trusted third-party service providers:
Payment Gateways: Stripe, Inc. for secure tokenized card processing and recurring subscription management.
Cloud Infrastructure: AWS / DigitalOcean / cloud hosting partners providing encrypted database storage and server uptime.
Hardware Manufacturers & Couriers: Print shops and postal carriers (such as DHL, FedEx, UPS) receiving shipping details strictly to deliver your physical NFC cards.
Transactional Communications: Email infrastructure providers for sending verification emails and lead notifications.
Legal Compliance: When compelled by subpoena, court order, or binding judicial request from competent regulatory authorities.
07
7. Data Retention & Erasure
We retain your personal data only for as long as your account remains active or as needed to provide our services. You can delete your account at any time through your dashboard settings. Upon account deletion, your public profile is immediately unpublished, and your personal data is purged from our production databases within thirty (30) days.
08
8. International Data Transfers
EasyID operates globally. If you access our platform from outside the server hosting region, your data may be transferred and processed internationally under the European Commission's Standard Contractual Clauses (SCCs).
09
9. Your Privacy Rights (GDPR & CCPA/CPRA)
Plain-Language Summary:
You have full rights to inspect, download, update, or permanently delete all data EasyID holds about you. We will never discriminate against you for exercising your privacy rights.
Depending on your geographic location, you enjoy the following enforceable rights:
Right of Access & Portability: You may request a machine-readable export of all personal data held under your profile.
Right to Rectification: You can edit and update any inaccurate or obsolete information at any time directly in your account dashboard.
Right to Erasure ("Right to be Forgotten"): You may demand the permanent deletion of your profile, leads, and account records.
Right to Restrict or Object: You can restrict or object to the processing of your data for analytical or marketing purposes.
California Privacy Rights (CCPA/CPRA): California residents have the right to know what personal information is collected, request deletion, opt-out of any sharing/sale (EasyID does not sell data), and be free from discrimination.
10
10. Cookies & Tracking Technologies
EasyID employs minimal cookies and local storage items strictly necessary to operate the platform:
Essential Session Cookies: Required to keep you authenticated and verify CSRF security tokens.
Preference Cookies: Used to store language selections, theme choices, and display modes.
Performance & Analytics: First-party analytics scripts to count profile taps and unique visits without employing intrusive cross-site advertising trackers.
11
11. Information Security Safeguards
Plain-Language Summary:
All data in transit is encrypted using modern TLS/SSL encryption, passwords are salted and hashed, and databases are protected behind firewalls with role-based access restrictions.
We deploy robust enterprise-grade administrative, technical, and physical security measures to safeguard your personal data. All data transmissions between your browser or NFC device and our cloud servers are encrypted using Transport Layer Security (TLS 1.3). Passwords are never stored in plaintext and are protected using high-iteration cryptographic hashing.
12
12. Children's Online Privacy Protection
EasyID is designed for adult business professionals and enterprise organizations. Our services are not directed to children under sixteen (16) years of age. We do not knowingly solicit or collect personal information from children.
13
13. Data Protection Officer & Privacy Inquiries
If you have any questions regarding this Privacy Policy, wish to file a data access request, or have concerns about our privacy practices, please contact our designated Data Protection Officer:
Data Controller: EasyID Technologies
Attention: Privacy Compliance & Data Protection Office