Privacy Policy for ScanCard

1. Introduction and Scope

Software Programming Group LLC (“SPG,” “Company,” “we,” “our,” or “us”) is committed to protecting the privacy and security of individuals who use ScanCard. This Privacy Policy explains how we collect, use, disclose, store, transfer, and protect personal information when you access or use the ScanCard website, mobile application, web application, application programming interfaces, software, subscriptions, integrations, and related support services (collectively, the “Service” or “ScanCard”).

ScanCard is intended for professional and business use. Because the Service helps users scan, organize, store, share, and synchronize business contact information, it may process personal information relating both to ScanCard account holders and to individuals whose business cards or contact details are scanned, uploaded, imported, synchronized, exported, shared, or otherwise managed through the Service.

By accessing or using ScanCard, you acknowledge that you have read this Privacy Policy and understand our practices. Where consent is required by applicable law, your use of the Service or selection of relevant preferences constitutes your consent to the processing described in this Privacy Policy. If you do not agree with this Privacy Policy, you should not access or use the Service.

This Privacy Policy should be read together with the ScanCard Terms of Service, the ScanCard Cookie Policy, and any order form, subscription agreement, data processing agreement, enterprise agreement, or product-specific notice that applies to your use of ScanCard.

2. About ScanCard

ScanCard is an AI-powered business card management application that enables professionals and organizations to scan, organize, manage, and share business contacts. The Service may include AI-powered OCR scanning, instant business card scanning, automatic contact information extraction, intelligent field detection, secure contact storage, search, editing, grouping, professional digital business card creation, QR-code-based sharing, Google Sheets export, Microsoft Excel/OneDrive export, CRM integration, API-based synchronization, enterprise CRM support, offline contact access, offline scanning, and automatic synchronization when connectivity resumes.

The Service is designed to simplify networking workflows, but users remain responsible for ensuring that they have a lawful basis, consent, notice, or other permission required to scan, upload, process, share, export, or synchronize business card and contact information, especially where such information relates to another person.

3. Definitions

  • “Account Information” means information used to create, authenticate, administer, and secure a ScanCard account, such as name, email address, password, organization, role, plan, billing identifiers, and user preferences.
  • “Business Card Data” means information appearing on, derived from, or associated with a scanned or uploaded business card, including names, job titles, company names, departments, postal addresses, phone numbers, email addresses, websites, social or professional profile links, logos, photographs, notes, tags, group labels, card images, and OCR-extracted fields.
  • “Contact Data” means Business Card Data and any other contact information imported, edited, enriched, synchronized, exported, or stored through ScanCard.
  • “Digital Business Card” means a digital profile, template, QR code, link, or shareable contact record created or managed through ScanCard.
  • “Personal Information” or “Personal Data” means information that identifies, relates to, describes, can reasonably be associated with, or could reasonably be linked to an identified or identifiable individual, as defined by applicable data protection law.
  • “Processing” means any operation performed on Personal Information, including collection, recording, scanning, extraction, structuring, storage, editing, retrieval, use, disclosure, transmission, synchronization, export, deletion, or anonymization.
  • “Third-Party Services” means external platforms, systems, applications, APIs, CRMs, cloud storage providers, analytics providers, payment processors, identity providers, and other vendors integrated with or used to support ScanCard.

4. Information We Collect

We collect information depending on how you use ScanCard, the features enabled in your account, the integrations you authorize, the settings selected by you or your organization, and the laws that apply to your location.

4.1 Information You Provide Directly
  • Account registration details, including name, business email address, phone number, password, role, company name, department, subscription plan, and administrative preferences.
  • Profile and digital business card information, including professional title, company logo, profile image, business address, business website, social profile links, QR code settings, template choices, brand preferences, and shareable contact details.
  • Business card images and uploaded files that you scan or import, including the original image, OCR output, manually corrected fields, notes, tags, contact groups, favorites, reminders, labels, and other metadata associated with the card.
  • Contact records that you create, edit, import, merge, group, synchronize, export, or share through ScanCard.
  • Communication information you provide when you contact customer support, submit feedback, request demos, participate in onboarding, complete forms, or communicate with us by email, chat, phone, or other channels.
  • Billing and transaction information if you purchase a paid plan, which may include billing address, tax details, invoice records, subscription history, and payment status. Payment card information may be processed by our third-party payment processors and may not be stored directly by us.
4.2 Information Collected Through Scanning and OCR

When you use ScanCard to scan a physical or digital business card, the Service may capture or process the card image, extract text using OCR and AI-based field detection, classify the extracted information into contact fields, and associate the extracted data with your account, organization, groups, CRM mappings, and synchronization settings. Depending on the card, extracted information may include personal information of the cardholder and other individuals named on the card.

OCR output may not always be accurate. You are responsible for reviewing and correcting extracted information before relying on it, exporting it, synchronizing it with external systems, or contacting individuals using the data.

4.3 Information We Collect Automatically
  • Technical identifiers, such as IP address, device type, operating system, browser type, app version, device identifiers, language settings, and approximate location derived from IP address.
  • Usage data, such as pages or screens viewed, features used, scan counts, export counts, sync status, error logs, performance data, session duration, navigation paths, and interaction events.
  • Security data, such as authentication logs, failed login attempts, account recovery activity, fraud signals, API access logs, device association data, and audit trails.
  • Cookie and similar technology data collected through the ScanCard website and related online services, as described in the ScanCard Cookie Policy.
  • Offline usage data generated when you use ScanCard without internet access, which may be synchronized to our systems when your device reconnects, depending on your account and device settings.
4.4 Information from Third Parties and Integrations
  • Information received when you authorize integrations with Google Sheets, Microsoft Excel, OneDrive, CRM systems, identity providers, calendar systems, business productivity tools, or other Third-Party Services.
  • Information imported from authorized CRM systems or enterprise directories, including contact fields, organization metadata, account mappings, owner assignments, tags, and synchronization identifiers.
  • Information from business partners, resellers, implementation partners, or enterprise administrators that provision or manage your ScanCard account.
  • Information from publicly available sources, if used to verify, enrich, deduplicate, or improve contact records, only where permitted by applicable law and your account settings.
4.5 Sensitive Information

ScanCard is not designed for processing sensitive personal information such as government identification numbers, financial account credentials, health information, precise geolocation, biometric identifiers, children’s data, or special category data under GDPR. Users should not upload, store, or synchronize sensitive information in ScanCard unless they have a lawful basis to do so and the relevant ScanCard plan, security controls, and contractual terms expressly support such processing. Business cards may occasionally contain information that is sensitive in a particular context; users are responsible for reviewing such information and complying with applicable law.

5. How We Collect Information

We collect information directly from you, from your device, from scanned or uploaded materials, from your organization or account administrator, from integrations you authorize, from service providers, and from business partners. We may collect information through automated means when you use our website, app, APIs, integrations, or support channels. We may also generate information from the data you provide, such as OCR-extracted fields, duplicate detection results, contact group suggestions, synchronization logs, and quality metrics.

6. How We Use Information

We use information for the purposes described below, depending on the features you use and the settings configured for your account or organization.

  • To provide, operate, maintain, authenticate, secure, and administer ScanCard.
  • To scan business cards, process card images, perform OCR, detect fields, extract contact information, structure contact records, identify duplicates, and allow users to edit and manage contacts.
  • To provide digital business card templates, logo customization, QR-code sharing, contact sharing, and related networking functionality.
  • To provide contact search, contact grouping, contact organization, notes, tags, favorites, and account-level or enterprise-level contact management tools.
  • To enable Google Sheets export, Microsoft Excel/OneDrive export, CRM integration, API synchronization, enterprise CRM support, offline access, offline scanning, automatic synchronization, and related workflow features.
  • To process payments, subscriptions, invoices, taxes, renewals, upgrades, downgrades, cancellations, credits, and account administration.
  • To provide customer support, respond to inquiries, troubleshoot errors, deliver onboarding, and communicate about service updates, security alerts, product changes, and administrative matters.
  • To monitor performance, analyze usage trends, debug errors, prevent abuse, enforce rate limits, detect fraud, protect account security, and maintain the integrity of the Service.
  • To develop, improve, test, and enhance ScanCard, including improving OCR accuracy, field detection, duplicate detection, synchronization reliability, and user experience. Where feasible and appropriate, we use aggregated, de-identified, or pseudonymized data for improvement and analytics.
  • To comply with legal obligations, respond to lawful requests, enforce agreements, protect rights and safety, and establish, exercise, or defend legal claims.
  • To send marketing communications where permitted by law and your preferences, including product announcements, newsletters, demos, events, offers, and educational content. You may opt out of marketing emails as described below.

7. Legal Bases for Processing

Where GDPR, UK GDPR, or similar laws apply, we rely on one or more legal bases to process Personal Data. These may include:

  • Performance of a contract: where processing is necessary to provide ScanCard, administer accounts, deliver requested features, process subscriptions, or provide support.
  • Legitimate interests: where processing is necessary for product security, service improvement, fraud prevention, analytics, customer communications, business administration, or enforcing our rights, provided those interests are not overridden by the rights and freedoms of individuals.
  • Consent: where required for optional cookies, marketing communications, certain integrations, mobile permissions, or other processing that requires consent under applicable law.
  • Legal obligation: where processing is necessary to comply with tax, accounting, security, consumer protection, data protection, law enforcement, or other legal requirements.
  • Vital interests or public interest: only where applicable and permitted by law.

Enterprise customers and account administrators may act as independent controllers or businesses for certain Contact Data they upload, scan, store, export, or synchronize. In those cases, ScanCard may act as a processor or service provider under a separate data processing agreement or enterprise contract.

8. AI OCR and Contact Data Processing

ScanCard uses OCR and AI-assisted field detection to convert business card images into structured contact records. This process may include image preprocessing, text recognition, field classification, confidence scoring, language detection, duplicate detection, error correction suggestions, and synchronization mapping. AI features are intended to support user productivity and are not a substitute for human review.

The accuracy of AI OCR depends on factors such as image quality, lighting, card design, language, fonts, card damage, handwriting, abbreviations, uncommon formats, and OCR model limitations. We do not guarantee that extracted information will be complete, accurate, current, or suitable for any particular purpose.

Users must review and correct extracted information before using it for outreach, importing it into CRM systems, exporting it to spreadsheets, sharing it with others, or making business decisions based on it. Users are also responsible for complying with applicable laws governing business communications, marketing, anti-spam, data protection, and contact management.

Unless otherwise stated in a separate enterprise agreement, we may use aggregated, de-identified, pseudonymized, or security-filtered data to improve OCR performance, scan reliability, error handling, and product quality. Enterprise customers may request additional restrictions through a data processing agreement or written contract where available.

9. Sharing and Disclosure

We do not sell your Contact Data as a standalone product. We may disclose information as described below and as permitted by applicable law.

  • At your direction, when you share a digital business card, share contact information, export data, synchronize with a CRM, connect to Google Sheets or Microsoft Excel/OneDrive, invite users, or otherwise instruct ScanCard to disclose information.
  • With service providers that perform services on our behalf, such as cloud hosting, storage, database operations, OCR infrastructure, analytics, customer support, email delivery, payment processing, security monitoring, logging, and fraud prevention.
  • With Third-Party Services that you or your organization authorize, such as CRM systems, cloud storage tools, productivity suites, identity providers, or API-connected applications. Their use of information is governed by their own terms and privacy policies unless otherwise stated in a separate agreement.
  • With enterprise administrators, account owners, or authorized organization users, where the account is managed by an organization and the information relates to that organization’s subscription, users, settings, audit logs, shared contacts, or business workflows.
  • With professional advisors, auditors, insurers, lawyers, accountants, and consultants as necessary for legitimate business purposes.
  • With law enforcement, regulators, courts, public authorities, or other third parties if we reasonably believe disclosure is required by law, legal process, or to protect rights, safety, security, property, users, the public, or the integrity of the Service.
  • In connection with a business transaction, such as a merger, acquisition, financing, restructuring, reorganization, bankruptcy, sale of assets, or transfer of all or part of our business.
  • In aggregated, de-identified, or anonymized form that cannot reasonably be used to identify an individual.

10. Third-Party Integrations and Exports

ScanCard may allow you to export or synchronize Contact Data with Google Sheets, Microsoft Excel, OneDrive, CRM platforms, enterprise systems, and other Third-Party Services. When you enable an integration, you authorize ScanCard to access, transmit, receive, store, update, and synchronize information as necessary to operate that integration.

Once Contact Data is exported, shared, downloaded, or synchronized outside ScanCard, we may no longer control its use, security, retention, deletion, correction, or onward disclosure. You and your organization are responsible for configuring integrations appropriately, managing third-party permissions, reviewing third-party privacy terms, and ensuring that exports and synchronizations comply with applicable law and internal policies.

If an integration is disconnected, certain data previously exported to the third-party system may remain in that system. You may need to delete or update such data directly through the third-party service.

11. Data Retention

We retain information for as long as necessary to provide ScanCard, maintain your account, comply with legal obligations, resolve disputes, enforce agreements, secure the Service, and fulfill the purposes described in this Privacy Policy. Retention periods may vary depending on the type of data, account settings, enterprise configurations, legal requirements, backup schedules, and contractual commitments.

Data Category General Retention Approach
Account Information Retained while the account is active and for a reasonable period after closure for security, legal, audit, and business administration purposes.
Business Card Images and OCR Output Retained according to your account settings, plan limits, enterprise policies, deletion requests, and backup cycles. Users may delete individual cards or contact records where the feature is available.
Contact Data Retained while stored by the user or organization, unless deleted, exported, synchronized elsewhere, retained under enterprise settings, or required for legal or security purposes.
Integration Logs and API Logs Retained for troubleshooting, audit, security, and compliance purposes for a reasonable period depending on account type and system requirements.
Billing Records Retained as required for accounting, tax, compliance, audit, and payment dispute purposes.
Usage and Analytics Data May be retained in identifiable form for a limited period and in aggregated or de-identified form for longer periods.
Backups Deleted or overwritten according to backup cycles. Information deleted from active systems may remain in backups for a limited period before routine deletion.

If you request deletion of Personal Information, we will process the request in accordance with applicable law and may retain information where permitted or required for legal obligations, security, fraud prevention, dispute resolution, compliance, backup integrity, or legitimate business purposes.

12. Data Security

We implement reasonable technical, administrative, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, loss, misuse, or destruction. These safeguards may include encryption in transit, encryption at rest where appropriate, access controls, authentication requirements, role-based permissions, logging, monitoring, vulnerability management, backups, incident response procedures, and employee or contractor confidentiality obligations.

No method of transmission over the internet, mobile network, or electronic storage is completely secure. We cannot guarantee absolute security. You are responsible for using strong passwords, protecting account credentials, managing device security, limiting user access, reviewing integration permissions, and promptly notifying us of suspected unauthorized access.

13. International Data Transfers

Your information may be transferred to, stored in, or processed in countries other than the country where you reside or where the information was collected. These countries may have data protection laws different from those in your jurisdiction. Where required, we use appropriate safeguards for international transfers, which may include standard contractual clauses, data processing agreements, transfer impact assessments, contractual protections, and other legally recognized transfer mechanisms.

14. Your Privacy Rights and Choices

Depending on your location and the laws that apply, you may have rights regarding your Personal Information. These may include rights to access, confirm processing, correct, delete, obtain a copy, port, restrict processing, object to processing, withdraw consent, opt out of targeted advertising, opt out of sale or sharing, limit the use of sensitive information, and appeal a denied request.

To exercise your rights, contact us at the email address in the Contact Us section. We may need to verify your identity or authority before responding. Authorized agents may submit requests where permitted by law, subject to verification. We will respond within the time required by applicable law. We will not discriminate against you for exercising privacy rights.

You may also manage certain information directly through your account settings, including profile details, digital business card content, contact records, group information, export settings, integration permissions, notification preferences, and marketing choices where available.

15. US State Privacy Disclosures

Certain US state privacy laws, including California privacy laws and other comprehensive state privacy laws, may require additional disclosures regarding the categories of information collected, the purposes of processing, the categories of sources, categories of recipients, retention practices, and rights available to residents. The following chart summarizes our practices for the preceding twelve months and our current practices.

Category Examples Sources Purposes Recipient Categories
Identifiers Name, email address, phone number, account ID, business address, IP address, device identifiers, digital business card identifiers, QR/share link identifiers. User, organization, scanned cards, integrations, device. Provide Service, account administration, contact management, security, support, integrations, communications. Service providers, integrations at user direction, enterprise administrators, legal recipients.
Professional or Employment-Related Information Job title, company, department, professional profile links, business card content, CRM fields. User, scanned cards, imported contacts, integrations. Contact management, OCR extraction, digital business cards, CRM sync, networking workflows. Service providers, user-directed recipients, integrations, enterprise administrators.
Commercial Information Subscription plan, billing status, invoices, transaction records, product usage. User, payment processors, organization. Billing, account management, customer support, compliance. Payment processors, service providers, professional advisors.
Internet or Network Activity Log data, session information, feature usage, app events, API calls, cookie data. Device, website, app, APIs. Security, analytics, debugging, product improvement, fraud prevention. Analytics providers, hosting providers, security providers.
Geolocation Data Approximate location derived from IP address; precise location only if enabled and required for a feature. Device, IP address, user permission. Security, localization, fraud prevention, feature support. Service providers as necessary.
Audio, Visual, or Similar Information Business card images, profile photos, logos, uploaded visual assets. User, scanned cards, uploads. OCR, digital business cards, contact records, user profile, support. Service providers, integrations at user direction.
Inferences Duplicate detection, field confidence scores, usage preferences, product analytics. Derived from Service usage and card processing. Improve functionality, support, recommendations, security, account administration. Service providers; generally not disclosed as standalone personal profiles.

We do not knowingly sell Contact Data. If we use cookies or similar technologies for targeted advertising or analytics in a way that constitutes “sale,” “sharing,” or targeted advertising under applicable law, we will provide applicable notice and opt-out controls, such as a “Do Not Sell or Share My Personal Information” or similar mechanism, where required.

California residents may have the right to know, access, correct, delete, opt out of sale or sharing, limit certain uses of sensitive personal information, and not be discriminated against for exercising rights. Residents of other states may have similar rights, including rights to opt out of targeted advertising, sale, and certain profiling, and the right to appeal decisions. To exercise rights, contact us using the details below.

16. EEA, UK, and Swiss User Disclosures

If you are located in the European Economic Area, United Kingdom, or Switzerland, you may have rights under applicable data protection law, including the right to access, rectify, erase, restrict, object, port, withdraw consent, and lodge a complaint with a supervisory authority. Where we act as a controller, you may contact us using the details below. Where we process Contact Data on behalf of an enterprise customer, you may need to contact that customer directly as the controller of the relevant data.

If you believe our processing of your Personal Data violates applicable law, you may have the right to lodge a complaint with your local data protection authority. We encourage you to contact us first so that we can attempt to address your concern.

17. Children’s Privacy

ScanCard is intended for professional and business users who are at least 18 years old or the age of majority in their jurisdiction. We do not knowingly collect Personal Information from children under 18 through ScanCard. If you believe a child has provided us with Personal Information, please contact us and we will take appropriate steps to delete such information where required by law.

18. Cookies and Similar Technologies

We use cookies, pixels, web beacons, local storage, SDKs, and similar technologies to operate our website, maintain sessions, remember preferences, analyze performance, secure the Service, and, where permitted, support marketing or advertising. For more information, please review the ScanCard Cookie Policy. You can manage cookie preferences through available cookie controls and browser settings. Essential cookies may be required for the Service to function.

19. Third-Party Links

The Service may contain links to third-party websites, applications, integrations, app stores, CRMs, productivity tools, or services that we do not own or control. This Privacy Policy does not apply to third-party services. We encourage you to review their privacy policies and terms before using them or authorizing an integration.

20. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we update it, we will revise the “Last Updated” date and may provide additional notice where required by law or where changes are material. Your continued use of ScanCard after an updated Privacy Policy becomes effective means you acknowledge the updated policy, except where additional consent is required by law.

21. Contact Us

If you have questions about this Privacy Policy, our data practices, or your privacy rights, please contact us at:

Software Programming Group LLC

295 Durham Avenue, Suite D
South Plainfield, NJ 07080
United States

Privacy Email: info@spgamerica.com

Website: https://www.scancard.ai

Data Protection Officer / Privacy Contact: Please use the Privacy Email above unless a separate Data Protection Officer contact is published on the ScanCard website or provided in an enterprise agreement.