Privacy Policy
ZapCard (operated by Konquer Media Pty Ltd, ABN 15 685 811 492, “we”, “us”, “our”) respects your privacy. This policy explains what personal information we collect when you use zapcard.com.au, company workspaces or our NFC business cards, how we use it, and the rights you have under the Australian Privacy Act 1988.
1. Information we collect
We collect only what we need to deliver the service. That includes:
- Profile data you give us, name, role, company, email, phone, social and website links, profile photo, and banner image. You provide this through our signup form or by scanning your existing business card.
- Account email, used for sign-in and order receipts. Password sign-in uses a stored password hash and salt, not your plaintext password.
- Order details, shipping address, billing details (processed by Stripe; we never see your full card number), order quantity.
- Card-scan images, the photos you upload during onboarding are sent to Google Gemini for extraction. You can enter your details manually instead of using the scan feature.
- Lead capture data, when a visitor opens your profile and uses the “Send them yours” button on your profile, they choose to share their name, email, phone, and an optional message. This data is delivered to you (the card owner) and stored in your dashboard. Shared profiles can also make information available to authorised company workspace users.
- Profile-open analytics, opens can include physical-card taps and shared-link visits. Totals do not distinguish these sources or identify unique people.
- Product analytics, we use PostHog to understand how visitors use zapcard.com.au (page views, feature usage) so we can improve the product. Analytics run by default unless you decline. Session replay only starts if you accept the cookie banner; input masking is configured for session recordings.
- Technical data, IP address (for rate-limiting and abuse prevention), browser type and usage events.
1.1 Company workspaces
We handle membership, roles, shared profiles, editing permissions and information entered into company CRM features, including notes, assignments and follow-ups. Sharing a profile and allowing company edits are separate permissions. Information available to workspace users depends on their role and permissions.
2. How we use your information
- To create and maintain your digital profile and the URL your physical card points at.
- To deliver, replace, or re-program your physical ZapCard.
- To send order receipts, shipping updates, and account-related emails (e.g. login links).
- To provide company workspaces, permissions and shared CRM features.
- To respond to your support requests.
- To detect and prevent abuse, fraud, and spam.
- To understand product usage and improve zapcard.com.au.
We do not sell your information. We use analytics and, when configured, advertising measurement tools described below. You can decline analytics and advertising tracking using the cookie banner. We share information with service providers as described in this policy.
3. Third-party processors
We use a small number of vetted service providers to run the product:
- Vercel, application hosting. Our application servers run in Sydney, Australia. Uploaded profile photos and banners are stored in Vercel Blob in the United States.
- Neon, Postgres database for accounts, profiles, company workspaces and orders, hosted in Sydney, Australia.
- Stripe Payments Australia Pty Ltd, payment processing under PCI-DSS. We never see or store full card details. Stripe is the data controller for payment information per its own privacy policy at stripe.com/privacy.
- Resend, transactional email delivery (welcome emails, login links, order receipts, lead notifications), sent through servers in Japan.
- Google Gemini, processes images you submit for card scanning to extract profile details.
- Google, Google sign-in and Google Wallet passes if you use them, and our support inbox.
- PostHog, product analytics and session recording for zapcard.com.au, sent to PostHog’s United States endpoint.
- Cloudflare, domain name services and routing of email sent to zapcard.com.au addresses.
- Telegram, order notifications to our team, containing the order number, number of cards, amount paid, the card links to write and the delivery suburb only.
When configured, Meta Pixel and the Meta Conversions API (United States) measure advertising activity and conversions. These tools can receive website event information. The cookie banner provides a choice to decline analytics and advertising tracking. A list of which data each processor receives is available on request at support@zapcard.com.au.
3.1 Disclosure of information to overseas recipients
We store your account, profile, company workspace and order information in Australia (Sydney), and our application servers run in Sydney.
Some of our service providers handle information outside Australia. We have taken reasonable steps to ensure they handle it in a way consistent with the Australian Privacy Principles. The countries include the United States and Japan, and some providers operate globally:
- Payments: Stripe processes your payment details under its own privacy policy.
- Email: Resend delivers our emails through servers in Japan.
- Uploaded images: profile photos and banners are stored with Vercel in the United States.
- Card scanning: if you scan a business card, the photo is processed by Google Gemini. You can type your details instead.
- Analytics and advertising: PostHog and Meta, both in the United States, measure site use and ads unless you choose Decline on the cookie banner.
- Sign-in, wallet and support: Google handles Google sign-in, Google Wallet passes and emails sent to our support inbox.
- Domain and email routing: Cloudflare operates a global network.
- Order notifications: Telegram carries the order number, number of cards, amount paid, the card links to write and the delivery suburb to our team.
If you want the least overseas handling possible, email support@zapcard.com.au. We will turn off analytics and advertising measurement for your account and confirm within 5 business days. We cannot avoid Stripe for payments or our email provider for account emails.
4. Your public profile
Anything you choose to put on your ZapCard profile (your name, role, contact details) is public by design, that’s the whole point of the product. Your profile URL is shareable to anyone you tap your card with, and is indexable by search engines unless you specifically request otherwise.
5. How long we keep it
We keep your account and profile data while your account is active. If you delete your account, we remove your profile within 30 days. Order records are retained for 7 years for tax and warranty purposes, per Australian law.
6. Security
Account, profile and workspace data is stored through a Neon/Postgres adapter. Authentication supports password sign-in and signed, single-use magic links (15-minute expiry) and 7-day session tokens. Login attempts are rate-limited per IP. We store password hashes and salts, not plaintext passwords. If a data breach occurs that is likely to cause serious harm, we will notify affected users and the Office of the Australian Information Commissioner per the Notifiable Data Breaches scheme.
7. Your rights
Under the Australian Privacy Act you have the right to:
- Access the personal information we hold about you.
- Correct any information that is inaccurate or out of date.
- Request deletion of your account and associated profile data.
- Complain about how we have handled your information.
To exercise any of these, email support@zapcard.com.au. We respond within 30 days.
8. Cookies and tracking
We use cookies and browser localStorage in the following categories:
Essential (always on)
- Sign-in token (localStorage), the application stores a session token in your browser to keep you signed in.
- Theme preference (localStorage), remembers the colour theme you picked.
- Rate-limit counters (server-side), prevent abuse on signup and scan endpoints.
- Cart state (localStorage), remembers what you’ve added to the order.
Analytics and advertising choices
- Profile-open counters, aggregate recorded taps and shared-link visits for your dashboard.
- PostHog, page-view and feature-usage tracking runs by default until you decline. Input masking is configured for session recordings, not a guarantee that all analytics events are anonymous. See Section 3.
- Meta, when configured, advertising measurement runs by default until you decline.
Session replay (only after you accept)
- On your first visit we show a cookie banner. Choosing “Accept” turns on PostHog session replay for that browser; choosing “Decline” opts analytics out of capture. You can change your mind at any time by clearing your browser’s site data for zapcard.com.au, which re-shows the banner.
To request that PostHog stop tracking your visits entirely, email support@zapcard.com.au from the browser/device in question and we’ll add an opt-out on our end.
9. Changes to this policy
We update this policy when we materially change how we collect or use information. When that happens we update the “Last updated” date at the top of this page and send an email to active account holders 14 days before the change takes effect. The current version is always available at zapcard.com.au/privacy.
10. Children’s privacy
ZapCard is not intended for users under 18. We do not knowingly collect personal information from anyone under 18. If you believe a child has created an account or had personal information shared via a card tap, contact us at support@zapcard.com.au and we’ll remove the data within 14 days of verification.
11. Notifiable Data Breaches
Under the Privacy Amendment (Notifiable Data Breaches) Act 2017, we are required to notify you and the Office of the Australian Information Commissioner (OAIC) of any data breach that is likely to result in serious harm to affected individuals. Our breach-response process:
- Detection, via service-provider security alerts, or via direct customer report.
- Assessment within 30 days, we determine whether serious harm is likely.
- If serious harm is likely, we notify affected users by email within 7 days of the assessment conclusion, and lodge a notification with the OAIC.
- Public notification, if we cannot directly contact all affected users, we will publish a notice on our website.
12. Contact
Konquer Media Pty Ltd
ABN 15 685 811 492
Cranbourne North VIC, Australia
Email: support@zapcard.com.au
Complaints unresolved within 30 days may be referred to the Office of the Australian Information Commissioner at oaic.gov.au.