Privacy Policy
Last updated: September 2, 2026
This policy explains how CardAction (the mobile app and this website) handles your data. CardAction is built by KRAFTPIXEL DIGITAL SOLUTIONS PRIVATE LIMITED under its consumer brand KraftPixel Labs ("we", "us"), a company incorporated in India. The company-wide KraftPixel Privacy Policy also applies; where this document is more specific about CardAction, this document governs.
The short version: CardAction is on-device first. Cards you scan are processed on your phone, your contact library lives on your phone, and we run no accounts and no contact database. Our servers only touch your data for the specific features described below.
1. What stays on your device
- Scanned cards and contacts. Card images are captured with your camera and read using on-device text recognition. The resulting contacts, tags, folders, notes, and card photos are stored locally on your phone. We never upload your contact library.
- Your "My QR" card. The digital business card you create for yourself is stored on your device.
- Settings and templates. Preferences, shortcuts, and message templates are stored locally.
2. Permissions we ask for
- Camera — to scan business cards. Frames are processed on-device; nothing is sent to us.
- Contacts — only to save a scanned contact to your phone's address book, or to build your QR card from a contact you pick. We do not read or upload your contact list.
- Photos — only when you save a QR image to your gallery or import a card photo.
- Notifications — for local reminders you enable; scheduled on-device.
3. What our servers see
3.1 Wallet passes (Apple Wallet / Google Wallet)
If you add your My QR card to Apple Wallet or Google Wallet, the card details you chose to include (name, title, company, phone numbers, emails, website, social links, address, notes) are sent to our pass server (wallet.cardaction.app, hosted on Cloudflare, Inc.) to generate and cryptographically sign the pass.
Passes that support automatic updates additionally store on that server: the most recent version of your card, a random pass serial number, and anonymous Wallet device registration tokens. This is what lets a pass update itself in every Wallet that holds it when you edit your card. The stored data is limited to the card content you yourself created; the only data about pass holders is an anonymous push token, and everything stored for a pass is deleted automatically when the pass is removed from the last registered device. We use the Apple Push Notification service and the Google Wallet API solely to deliver passes and update signals. Cards you scan from other people are never sent to the pass server.
3.2 Google Sheets export
If you connect Google Sheets, you sign in with Google using the minimal drive.file scope — CardAction can only access spreadsheets it created or that you explicitly connected, and it cannot see the rest of your Drive. Exported contact rows go directly from your device to Google's APIs; they do not pass through our servers. Sign-in tokens are stored on your device. CardAction's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3.3 Webhooks
If you configure a webhook (e.g., Zapier or Make), scanned-contact data is sent from your device directly to the URL you chose. You control that endpoint and its handling of the data.
3.4 Subscriptions
Purchases are processed by Apple's App Store or Google Play and managed through RevenueCat. We receive entitlement status and anonymized purchase/transaction records — never your card details. We do not store payment card numbers.
3.5 Tester access codes
If you redeem a tester code, the code is validated against our server; no personal data is attached to it beyond the code and platform.
4. Analytics and advertising
- In the app: we use the Meta (Facebook) SDK for install attribution and, only with your consent through Apple's App Tracking Transparency prompt, ad-performance measurement. You can decline; the app works identically.
- On this website: we use Google Analytics and the Meta Pixel to understand traffic and measure campaigns. These set cookies governed by their respective policies.
- Crash and diagnostic reports may be collected by the app platforms (Apple/Google) per your OS settings.
5. Retention and deletion
- On-device data lives until you delete it or uninstall the app.
- Wallet pass data is retained only while at least one Wallet device holds the pass, and is deleted automatically when the last pass is removed. Deleting the pass from Wallet is the delete button.
- Subscription records follow the app stores' and RevenueCat's retention rules.
- For any other request, email us — see section 8.
6. Security
Wallet passes are signed with industry-standard certificates; traffic to our servers uses TLS; server-side card data is stored with Cloudflare's encrypted storage. No method is 100% secure, but we keep the server-side surface deliberately tiny.
7. Children
CardAction is a business tool and is not directed at children under 13 (or the applicable age in your region). We do not knowingly collect data from children.
8. Contact & your rights
Depending on your region you may have rights to access, correct, export, or delete personal data. For any privacy request, contact [email protected]. We answer within 30 days.
9. Changes
We'll update this page when the app's data practices change and revise the date at the top. Material changes will be highlighted in the app or release notes.