Privacy
Privacy Policy
Last updated 26 September 2026
Mereka Cards is a digital business card: you share a card, people you meet can save it and, if they choose, share their details back. This page says exactly what that involves.
Who we are
Mereka Cards (the iPhone app, cards.mereka.io and the console at admin.cards.mereka.io) is a Mereka service. Mereka is responsible for the personal data described here. Questions, requests and complaints go to hello@mereka.io.
What we collect
Your account
Your name and email address, whether you have verified that email, and either a password (stored only as a one-way hash) or the identifier Apple or Google gives us when you choose to sign in with them. If you use Sign in with Apple and hide your email, we only ever see Apple’s relay address. We keep a record of your signed-in sessions — when each started and expires, and technical details of the request that created it such as the IP address and device type — so you can review and end them and so we can protect your account.
Your cards
What you choose to put on a card: name, title, organisation, bio, email, phone, website, address, links, a photo link, and its design. Each card has switches for showing your email, phone, title, organisation and address; a hidden field is never shown publicly.
Connections people share with you
When someone opens your public card and chooses to share their details, we store the name (optional) and email address they enter, together with their explicit consent: which wording they agreed to and when. These details are encrypted at rest.
Organisations
If you belong to an organisation, we store your membership and role, and which cards the organisation issued or assigned to you (including the programme or cohort a card was issued under).
Device and app diagnostics
The app can send diagnostics when something goes wrong — for example an NFC write that failed, an app error or a request the server refused. A report holds the app version, iOS version, device model, the outcome and a short, filtered error description. It is linked to your account and organisation so we can fix your problem without asking you for details. Reports never contain card contents, contact details, NFC tag identifiers or your IP address, and text that looks like an email, phone number, link or token is rejected. You can turn this off at any time in the app under Settings → Share diagnostics with Mereka.
Notifications
If you allow notifications, we store your device’s push token, an installation identifier, the app version and platform so we can tell you about new connections, card activity and new sign-ins. Notification messages never include a connection’s name or email.
NFC cards
An NFC card programmed by the app holds only a link to your card with a random secret in it. We store a keyed fingerprint of that secret, never the secret itself, and we do not read or store the tag’s hardware identifier.
What we do not do
- No advertising, no ad identifiers, no cross-app tracking and no analytics SDKs, in the app or on our websites.
- We do not sell or rent personal data.
- Public card pages ask search engines not to index them, and load no third-party scripts, fonts or trackers.
How we use it
- To run the service you asked for: your account, your cards, the public card page, NFC cards and contact exchange.
- To send the email the service needs: verifying your address, resetting a password, security notices about new sign-ins, invitations and the notifications you choose.
- To keep it secure and working: preventing abuse, rate-limiting, and diagnosing and fixing faults.
- For billing, when your organisation is on a paid plan.
What is public
A card you publish can be seen by anyone who has its link, scans its QR code or taps its NFC card, and they can save it to their contacts. Only the fields you have switched on are shown. Unpublishing or deleting the card takes it down, and an NFC card can be revoked from the app.
If you share your details on someone’s card
Your name and email go to that card’s owner so they can contact you, and to nobody else. After sharing you receive a private withdrawal link: opening it removes your details immediately. We keep only a fingerprint of that link, so if you lose it, email hello@mereka.io and we will verify the request and erase your details. Your details are also erased if the card owner deletes their account.
Organisations and programmes
When an organisation issues you a card, its administrators can see and manage that card and its design rules, and see whether it is assigned, approved and published. If you leave or are removed from an organisation, the cards it assigned to you are unpublished and their NFC cards stop working; a later holder of the card cannot see your connections. A programme sponsor or partner organisation does not get access to your contacts or connections.
Who processes it for us
We use a small number of service providers, each only for the job below and under their own data-protection terms:
- Our hosting provider runs the servers and database behind the app and console.
- Cloudflare serves cards.mereka.io and carries traffic to our servers.
- Backblaze stores our database backups.
- Resend delivers our email.
- Expo relays push notifications to Apple’s push notification service.
- Apple and Google authenticate you when you choose to sign in with them.
- Stripe handles payments when an organisation subscribes to a paid plan; we never see card numbers.
Some of these providers operate outside your country. Where data is transferred internationally, it is protected by the provider’s contractual safeguards.
How long we keep it
- Account and card data: for as long as you have an account.
- Connections: until the person who shared them withdraws, until they are erased on request, or until the card owner deletes their account.
- Diagnostics: 30 days, then deleted automatically.
- Backups: up to 30 days, so deleted data can remain in a backup for up to 30 days before it is gone for good.
- Records of what happened (for example that an erasure was carried out or who changed an organisation’s settings) are kept without personal details, so the service stays accountable.
Deleting your account and your other rights
You can delete your account from Settings in the app, or from Account in the console. Your cards go offline and your NFC cards stop working straight away; you then have 7 days to change your mind. After that your cards, links, connections, devices, notifications, sessions, sign-in methods and memberships are deleted, and your account record is reduced to an anonymous identifier with no name or email. If you are the only owner of an organisation that has other members, hand ownership to someone else first.
You can also download your data from Account in the console, correct anything in the app, and ask us to access, correct, erase or stop using your personal data by emailing hello@mereka.io. You may complain to your local data-protection authority.
Security
Traffic is encrypted in transit. Shared contact details are encrypted at rest, passwords are hashed, and every database read is limited to the account and organisation it belongs to. No system is perfectly secure; if something goes wrong we will tell affected people as the law requires.
Children
Mereka Cards is not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.
Changes
If we change this policy we will update the date above, and tell you in the app or by email before a material change takes effect.