vCard

U-site · vCard

Privacy Policy

Last updated: September 23, 2026

This explains what information we process when you use vCard, why, who we share it with and how you can control it.

1. Data controller

U-site, operator of vcard.u-site.app. Privacy contact: [email protected].

2. Data we collect

  • Required at sign-up: email, password (hashed) and country, to create your account and show prices and payment methods for your region.
  • Optional: name, company, phone, city and whatever you decide to put on your cards (role, description, social links, photos, logo, links, AI agent).
  • Payments: reference, amount, plan, date and status of each payment. Card details are handled by the gateway and never reach our servers.
  • Technical: IP address (to detect your country), browser, language, access date and time, and session cookies needed for the platform to work.
  • Card usage: we count visits and clicks (phone, WhatsApp, email, social links, QR and VCF downloads) to show you statistics. We do not identify who visits your card.
  • If you sign in with Google we receive the name, email and profile photo of that account.

3. Why we use the data

  • To create and manage your account, cards, mini-websites and collaborators.
  • To process payments, activate plans, send billing notifications and calculate referral commissions.
  • To send service emails: verification, access recovery, magic links, expiry notices and changes to these terms.
  • To show you statistics about your cards and improve the platform.
  • To prevent fraud and abuse (attempt limits, API call logs).

4. Legal basis

We process your data to perform the contract (providing the service), with your consent (optional data, public directory, Google sign-in) and on our legitimate interest in security and service improvement, in accordance with Colombian Law 1581 of 2012 and Decree 1377 of 2013 and, where applicable, the GDPR.

5. Who we share data with

  • Payment gateways (dLocal, PayPal, Bold): they receive email, amount and reference to process the charge, under their own policies.
  • admin.u-site.app: U-site internal system that handles payments and plans.
  • Google (Gemini) when you use the dashboard AI assistant: your messages to the assistant and basic account and card data are sent to answer. They are not used to train models under Google API terms.
  • Infrastructure and email providers (hosting, email delivery).
  • Integrations you connect with your API key (for example uMind): they access your account on your behalf.
  • Authorities, when required by law.

We do not sell your data or hand it to third parties for advertising.

6. Public cards and directory

  • Every card has a unique URL and is visible to anyone with the link. You decide what to include and who to share it with.
  • If you enable "show in directory", your name, role, company, city and photo appear in the public search and may be indexed by Google. You can disable it at any time; removal from search engines may take a while.
  • You can hide phone and email on the card from the editor.

7. Retention

  • We keep your data while your account exists. When you delete it, we erase your profile and cards within 30 days; payment records are kept as long as accounting and tax law requires.
  • Technical and security logs are kept for up to 12 months.

8. Your rights

You can access, correct, update and delete your data from your profile and cards, or request it at [email protected]. You can also withdraw consent, object to processing, request a copy of your data and file a complaint with the Superintendencia de Industria y Comercio (Colombia) or your local authority. We answer within 15 business days.

9. Security

  • Encryption in transit (HTTPS) and hashed passwords.
  • Protected dashboard routes, login attempt limits and per-user API keys you can regenerate.
  • Unique identifiers on every card so it cannot be discovered without the link.
  • Server access restricted by credentials, with audit logs.

10. Cookies

We use strictly necessary cookies (session, CSRF security, language) and one cookie to remember who referred you. We do not use advertising cookies. You can block them in your browser, although the dashboard may stop working.

11. Minors

vCard is not intended for children under 14. If you believe a minor gave us data without authorization, write to us and we will delete it.

12. Changes to this policy

If we change this policy we will notify you by email and with a notice in the platform. The date above indicates the current version.