DRAFT FOR PRE-LAUNCH REVIEW

Privacy at Facet Cards

This page describes the current product implementation. It needs review and a published business contact before a public launch.

What we hold

Account name and email, a password hash, login sessions, card content, sharing settings, and basic page view counts. Card content may include contact details and social links you choose to enter.

What other people can see

Anyone with an active card’s public link or QR code can see fields that you marked as shared. The public contact file contains those shared fields; the recipient can remove individual details before opening it. Pausing or deleting the card stops its public page. A direct contact QR already saved or photographed by someone cannot be recalled.

Recipients

Recipients do not need an account. A scan does not collect their contact details. The current product records a page view count for the card, not a recipient identity.

Your choices

You can edit, pause, or delete each card in your account. You can sign out to end your current session. Account settings let you download your data or delete your account.

Security and retention

Passwords are stored as salted hashes. Login sessions expire after 30 days. Public hosting must use HTTPS, backups, restricted database access and a defined retention schedule before launch.