← Back to Digital Business Card

Privacy Notice

Digital Business Card · Effective 2026-07-16 · Japan (APPI) baseline

This notice explains what personal data Digital Business Card processes, why, and who to contact about it. It covers the app as it currently operates. It does not yet address obligations that would apply to visitors or testers based in the EU/EEA — those are being worked through separately and are not yet complete (see "Scope" below).

Who operates this service

Controller
Recontra
Contact for privacy questions or requests: info@recontra.jp

Scope

This notice is written to the Act on the Protection of Personal Information (APPI) baseline that applies to this service regardless of where a user is located. It has not yet been reviewed by counsel and should not be treated as a final or complete legal document. It does not cover EU/UK data protection obligations; if you are accessing this service from the EU/EEA or UK, please contact us before providing any personal data.

What data we collect, and why

Your account
When you sign in with Google, we receive your email address and name from Google to create and identify your account. We do not receive your Google password.
Your own business card(s)
The card details you enter (name, title, organisation, contact fields) and any card photos you upload are stored so the app can display and share your card. Card photos are backed up to a Google Drive folder in your own Google account (not a Digital Business Card-operated store) once you grant Drive access during sign-in.
Contacts you connect with (other Digital Business Card users)
When you exchange cards with another Digital Business Card user via tap or QR code, both people's card details are saved to each other's Contacts list, and card photos are backed up to each person's own Drive the same way as above. This only happens when the other party is also a registered Digital Business Card user who has taken an action (tapping/scanning) to initiate the exchange.
Contacts you scan or type in who are not Digital Business Card users
If you photograph or manually enter someone's business card and that person does not have a Digital Business Card account, that record is kept only on your own device. It is never uploaded to our servers, never backed up to Drive, and text recognition (OCR) for these scans runs entirely on your device — the image and text never leave your phone or browser. We have no way to access, correct, or delete this data on your behalf, because we never receive it. If you asked us to remove such a record, we could not act on it since we don't have it; deleting it locally on your device is the only mechanism, and that is entirely in your control.
Technical & security data
We keep short-lived records to prevent abuse (e.g. rate-limiting repeated requests) and a log of failed sign-in attempts with unverified email addresses, for security purposes. These are not used for advertising, profiling, or any purpose beyond operating the service securely.

Who else processes this data

We use Google Cloud Platform (Firebase Authentication, Firestore database, Cloud Functions, App Check) to run the service, and Google Identity Services for sign-in. Servers are located in the United States (Google Cloud us-central1), meaning data described above as stored on our servers is transferred outside Japan to Google's infrastructure. We do not use any third-party analytics, advertising, or crash-reporting SDKs.

How long we keep it

Your cards and contacts are kept until you delete them in the app, or until you delete your account entirely from Settings. Account deletion removes your cards, your contacts, your Drive backup connection, and your account itself, permanently and immediately. Rate-limiting and abuse-prevention records expire automatically, typically within 24 hours to 30 days depending on the record.

One limit worth being upfront about: if you've exchanged cards with another user, they now hold their own copy of your card in their own Contacts — the same way keeping a physical business card someone handed you doesn't depend on that person's continued cooperation. Deleting your account doesn't reach into another user's own contact list and remove what you already gave them; it does disconnect the live link, so nothing further syncs between your (now deleted) account and theirs.

Your rights

You can review and edit your own card and contact data directly in the app at any time. You may request access to, correction of, or deletion of your personal data, or ask us to stop processing it, by contacting info@recontra.jp.

Changes to this notice

We may update this notice as the service changes. Material changes will be reflected here with an updated effective date.