Privacy Policy
Last updated 17 September 2026
What Deehvine Connect collects, why, who else touches it and how long we keep it. Written to be checkable against the software rather than to cover every eventuality.
1. Two different relationships
This policy covers two kinds of people, and the difference matters.
Customers hold an account with us. For their data, Deehvine Marketing LLC is the controller — we decide what is collected and why, and this policy describes it.
Visitors tap or scan somebody’s card. If a visitor shares their contact details, those details belong to the cardholder, who is the controller of them. We only process them on that cardholder’s behalf. If you gave your details to someone’s card and want them removed, ask that person first; if you cannot reach them, write to us and we will help.
2. What we collect from customers
- Account: email address, name, and optionally an avatar, timezone, language and your notification preferences.
- Profile content: whatever you choose to publish — job title, company, bio, phone, links, photo, logo. This is public by design.
- Sign-in records: your active sessions, each with the device’s IP address and browser user agent, so you can see where you are signed in and end a session you do not recognise. If you enable two-factor authentication, the authenticator secret is held by our authentication provider and never by us.
- Billing: your plan, invoices, payments and orders. Card numbers are entered directly with Stripe and never reach our servers; we store only Stripe’s identifier and display-safe details such as the last four digits and card brand.
- Support and audit: a record of significant account actions — plan changes, card assignments, closures — so that we can answer “what happened to my account?” accurately.
3. What is collected when somebody taps a card
A tap, scan or view is recorded so the cardholder can see how their card is performing. Each event stores the profile, which card or QR code was used, the type of event, a randomly generated session identifier, a coarse device type (mobile, tablet or desktop), the referring website’s hostname, and an approximate country and region.
We do not store the visitor’s IP address. There is no column for it. The IP address is used momentarily, hashed with SHA-256 and truncated, to rate-limit abuse — that hash is a counter key and is never kept as analytics data or linked to a person.
There is no advertising network, no cross-site tracking and no cookie used for analytics on a public card. The session identifier is a random value that lets us count one visit as one visit.
If a visitor fills in the contact form, we store what they typed — name, email, phone, company, message — and whether they ticked the marketing consent box. That record belongs to the cardholder.
A cardholder on a plan that allows it may add their own Google Analytics measurement ID to their card. When they do, Google Analytics runs on that card’s public page and Google receives what it normally would. That is a choice the cardholder makes, and their relationship with Google, not ours.
4. Why we process it
- To run the service — performing the contract you entered when you subscribed.
- To take payment — performing that contract, and meeting our tax and accounting duties.
- To keep it working and stop abuse — our legitimate interest in a service that stays up.
- To email you about your account — performing the contract. Marketing email, if we ever send any, is separate and opt-in.
5. Who else touches it
We do not sell personal data, and we do not share it for advertising. These are the processors that handle it on our behalf, and what each one is given:
- Supabase
- Database, authentication and file storage. Everything the product stores: accounts, profiles, leads, analytics and billing records.
- Vercel
- Application hosting and content delivery. Requests to the site, including IP address and user agent, as any web host receives them.
- Stripe — when enabled
- Payments and subscriptions. Name, email and payment details, which are entered on Stripe and never pass through our servers.
- Resend — when enabled
- Transactional email. The recipient's address and the contents of the message being sent.
- Apple, Google — when enabled
- Wallet passes. The name, title and contact details printed on the pass, when a cardholder chooses to add one.
- Google Analytics — only if you switch it on
- A cardholder's own visitor analytics. Page views on that cardholder's public card only, and only while they have supplied their own measurement ID.
We will also disclose data where the law requires it, and we will tell you unless we are forbidden from doing so.
6. Where it is held
Our database and files are hosted in the United States. The application is served from a global content network, so a request is answered near the person making it while the data itself stays in the database region.
7. How long we keep it
- Analytics events: thirteen months. A weekly job deletes anything older, automatically. The daily totals that remain are counts, not events about a person.
- Account and profile data: for as long as you have an account, and then as described below.
- Leads: until the cardholder deletes them, or their account is erased.
- Invoices, payments and orders: kept even after erasure. They are accounting records we are obliged to retain.
8. Your rights over your data
You can see and change most of it yourself: profile content, contact settings, notification preferences and your active sessions are all in the dashboard. Beyond that you can ask us to correct anything wrong, to give you a copy, or to delete it.
Closing your account is something you do yourself in Settings. Your cards stop resolving at once and the records are kept, so the decision is reversible.
Erasure is permanent and we run it for you on request. It deletes profiles, links, leads, analytics and team memberships, returns any physical cards to inventory with their codes intact, and anonymises your sign-in record. Invoices, payments and orders survive with the identity anonymised, for the reason given above.
Depending on where you live you may also have the right to object to processing, to restrict it, or to complain to a data protection authority. Write to us and we will help rather than make you find the form.
9. Security
Access to data is enforced in the database itself through row-level security, so a customer’s account can only read its own rows even if the application asked for more. Traffic is encrypted in transit. Passwords are hashed by our authentication provider and are never visible to us. Two-factor authentication is available to every account.
No system is perfect. If a breach affects you we will tell you and the relevant regulator, promptly and without waiting to have a tidy story.
10. Children
The service is for business use and is not directed at children under 13. If we learn that we hold a child’s data, we delete it.
11. Changes
When this policy changes, the date at the top changes with it. For a change that materially affects how we use your data we will tell you directly rather than relying on you to re-read the page.
12. Contact
Privacy questions and requests go to hello@deehvinemarketing.com. The Terms of Service cover the rest of the relationship.