Privacy
Your work stays under your control.
This policy explains what CardToClose processes when your organisation uses the web and mobile service, why it is needed, and the choices available to you.
Last updated 28 August 2026
Who this policy covers
CardToClose is a business service used by organisations and their authorised team members. Your organisation controls who can access its workspace and may also be the controller of business-contact information entered by its team. Questions can be sent to info@cardtoclose.com.
Information we process
- Account information, including name, work email, role, organisation, authentication and security status.
- Event and contact information entered or captured by an authorised user, such as names, business details, contact details, notes, QR or NFC content, card or badge images, and voice notes.
- Generated and reviewed work, including extracted contact fields, transcripts, meeting context, follow-up drafts, corrections, approvals, export and sync status.
- Operational information needed to secure and run the service, such as device and session identifiers, timestamps, queue state, error diagnostics, IP address and server logs.
- Website campaign information you choose to submit, such as your first name and work email, plus information about how you use the campaign pages collected through Google Analytics.
- Information you send when requesting support or account deletion.
How we use information
We use this information to authenticate users, keep business workspaces separated, save and synchronise captures, extract and organise contact details, transcribe user-requested voice notes, prepare follow-up drafts, support exports selected by the organisation, prevent abuse, troubleshoot problems, and meet legal or security obligations. CardToClose does not sell personal information and does not use it for third-party advertising or cross-app tracking.
Device permissions
The mobile app asks only when a feature needs access: camera for cards, badges and QR codes; microphone for a voice note you choose to record; the system photo picker for an image you choose to attach; and NFC for a tag you choose to scan. CardToClose does not read or upload your device address book and does not request location. You can refuse a permission and use manual entry, pasted content, or another available capture method. Local captures may stay on the device until they can synchronise.
Sharing and service providers
Information may be available to authorised administrators and team members in your organisation. Production uses Microsoft Azure for hosting and file storage, OpenAI for requested image extraction and AI-assisted contact, meeting-context and follow-up processing, Brave Search, Microsoft Bing or DuckDuckGo for public-profile web searches, public LinkedIn profile pages to retrieve a profile image when available, local faster-whisper models for voice transcription, and Titan for transactional email. Website campaign forms use Kit's official form handler. Kit receives the first name and work email you submit and may process technical request data, referrer or source attribution, and anti-abuse signals to validate the signup, apply campaign automation, and contact you about access. When you create a product account, CardToClose also synchronises your name, email, company details and saved product-email preference with Kit; refusing marketing does not block essential verification, security or trial notices. Separately, the campaign pages use Google Analytics to understand page usage. Loading the welcome page records a signup_complete event for campaign conversion reporting. Access to these functions is restricted through server-side credentials, account scoping and encrypted connections; CardToClose has no advertising or cross-app tracking integration. We require service providers to handle transferred information with the same or equivalent privacy protection described in this policy and only for the service purposes we instruct. When you choose an export or handoff, information is sent to the email, WhatsApp, file-sharing or other app you select, under that provider's terms. We disclose information when legally required or when necessary to protect users and the service.
AI and public-search processing permission
Before CardToClose sends information to OpenAI, a public web search provider, or a public LinkedIn profile page, the app names OpenAI, Brave Search, Microsoft Bing, DuckDuckGo and LinkedIn, explains the purposes, identifies the information categories, links to this policy, and asks the signed-in user to agree. The categories are: names, job titles, organisations and business contact details; contact identity and organisation details used to search the public web and request a likely public LinkedIn profile; selected business-card or badge images and QR or NFC content; voice recordings and voice-note transcripts, meeting notes and context; follow-up instructions; account-approved business context; public business-website content selected for profile enrichment; and the generated work returned to CardToClose. Processing is used only to extract and organise contact details, create meeting summaries and context, prepare follow-up suggestions and drafts, search the public web for a likely professional profile and business context, retrieve a public LinkedIn profile image when available, and analyse selected public business-website content to propose profile details and collateral links.
You can decline before any transfer to these providers or withdraw permission later from Profile. Withdrawal stops new information from being sent to them. Because these functions are the core of CardToClose, capture and follow-up features are unavailable while permission is off; privacy, support, sign-out and account-deletion controls remain available. Withdrawal does not itself delete information processed earlier. You can use the in-app deletion control or the account deletion page to request deletion, subject to the retention obligations explained below.
Security and retention
CardToClose uses encrypted network connections, access controls, tenant separation and protected credential storage. Information is retained while the relevant business account is active and as needed to provide the service. Raw capture images, audio and files are removed according to the business account's configured retention period; the default is 90 days. When an authorised deletion is completed, owner-scoped capture and export files are queued for verified deletion from active storage as well as removal from the active database. Limited backup, fraud-prevention, audit or legal records may remain until their applicable retention period expires.
Your choices and deletion
You can review and correct captured contact information in the product, clear your account's local mobile cache, and ask your organisation's administrator about workspace access or server-held data. To request deletion or ask a privacy question, use the account deletion page. Clearing the mobile cache does not delete information that has already synchronised to the service.
Children and changes
CardToClose is a business service and is not directed to children. We may update this policy when the service or legal requirements change. The date above identifies the current version.
