1. Controller and contact
SalesCard is operated by Mark Gerban / SalesCard, Fuhlsbüttler Strasse 312, 22307 Hamburg, Germany. Privacy and legal requests can be sent to info@sales-card.com.
2. Our data-protection roles
SalesCard acts as controller for account registration, authentication, service administration, support, security and product-operation data.
Where a business customer enters or imports information about its own contacts, leads, clients or employees, that customer may act as controller and SalesCard may act as processor. The customer remains responsible for having a lawful basis and giving any required notices to the people whose information it manages.
3. Data we process
- Account and profile details, login method and consent records.
- People, company, lead, pipeline and collaboration records.
- Business-card images, scans, imports and uploaded context files.
- Notes, reminders, tasks, meetings and activity history.
- Calendar, email and integration data authorised by the user.
- Device, app-version, security, diagnostic and support information.
- Subscription or store-purchase status where paid features apply.
4. Purposes and legal bases
We process data to provide accounts and requested app features, synchronise and secure information, support users, prevent misuse, maintain reliability, meet legal obligations and administer subscriptions.
Depending on the activity, processing is based on contract performance, legal obligation, legitimate interests, or consent for optional permissions and integrations.
5. Google API data
When a user connects Google, SalesCard uses Google user data only for user-facing features the user requests, such as sign-in, calendar availability, meeting creation and supported email workflows.
SalesCard’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not sold, used for advertising, or used to train general-purpose AI models.
6. Microsoft data
Microsoft account and Microsoft Graph data are used only for authorised user-facing features such as sign-in, calendar, meeting and supported productivity workflows. Access can be revoked through SalesCard where supported or through the user’s Microsoft account.
7. Service providers and international transfers
SalesCard uses service providers for infrastructure, authentication, integrations, app distribution and related service operation. Confirmed providers are described on the Subprocessors page.
Where information is processed outside the EEA, appropriate contractual and legal transfer safeguards are used where required.
8. Retention
Account and CRM information is generally retained while an account remains active. Information is deleted or anonymised when it is no longer needed, subject to legitimate legal, security, accounting, fraud-prevention, backup and dispute-resolution requirements.
Backup copies and security logs may remain for a limited period before routine deletion.
9. Security
SalesCard uses technical and organisational measures including authentication, access controls, encrypted transport, limited production access, secure session handling and operational safeguards. More information is available on the Security page.
10. Your rights
Depending on applicable law, users may request access, correction, deletion, restriction, portability, objection, or withdrawal of consent. Users may also complain to a competent supervisory authority.
Requests can be submitted through the Account Deletion page or by emailing info@sales-card.com.
11. Children, changes and questions
SalesCard is intended for professional and business use and is not directed to children. This policy may be updated when the product, providers or legal requirements change. Material changes will be reflected by a new version and updated date.