Last updated: 9 June 2026. This Privacy Policy explains how TrustKard collects, uses, shares and protects personal information. It is intended to align with the Protection of Personal Information Act, 2013 (POPIA). Please read it together with our Terms & Conditions.
1. Who We Are
TrustKard operates a multi-tenant digital business card platform that enables companies to create branded digital cards and profile pages for their team members, share them via short links and QR codes, capture leads, and collect reviews. For the personal information you provide about yourself and your account, we act as the responsible party. For information that a company collects through its cards, links and contact forms (for example, leads and reviews), that company is the responsible party and we act as an operator (processor) on its behalf.
2. Personal Information We Collect
- Account and company data: your name, email address, phone number, password (hashed), role, company details, billing address, VAT number, and profile information such as job title, photo, logos and custom fields.
- Card and usage data: the content of the digital cards and profiles you create, short links, QR codes, and information about how cards and links are viewed and scanned.
- Captured leads and reviews: information submitted by visitors through contact forms and review pages, such as names, contact details, messages and ratings.
- Payment data: payments are processed by PayFast. We do not store full card numbers; we hold tokenised payment references in encrypted form, together with limited details such as card brand, last four digits and expiry, and transaction records.
- Analytics and technical data: IP address, device, browser, operating system, referrer, UTM and other attribution parameters, and approximate geolocation derived from these signals, recorded against page views, link scans, contacts and review submissions.
- Custom domain and integration data: domain configuration you provide, and data exchanged with third-party services you choose to connect through our integrations engine.
- Communications: correspondence with our support team and related records.
3. How and Why We Use Personal Information
We use personal information to create and manage accounts and companies; to render and serve public cards, links, QR codes and wallet passes; to capture and deliver leads and reviews to the relevant company; to calculate and collect fees and process payments and store orders; to provide analytics and attribution reporting; to operate integrations you configure; to provide support; to maintain security and prevent abuse; and to comply with our legal obligations.
4. Lawful Basis for Processing
We process personal information where it is necessary to perform our contract with you, to pursue our or a company's legitimate interests (such as operating, securing and improving the platform), to comply with a legal obligation, or on the basis of consent where required. Where we rely on consent (for example, certain non-essential cookies), you may withdraw it at any time.
5. How We Share Personal Information
We do not sell your personal information. We share it only as needed to operate the Service, including with:
- Companies and their users: leads, reviews and analytics captured through a company's cards and links are made available to that company.
- PayFast: our payment gateway, for processing payments and recurring or ad-hoc charges.
- Hosting and infrastructure providers: including cloud storage and hosting used to run the platform and store files.
- Service providers (operators): for geolocation enrichment, error monitoring, email delivery, wallet pass generation and similar functions, bound to process data only on our instructions.
- Resellers: where your company is provisioned or managed through an authorised reseller, that reseller may access the company data necessary for its administrative and billing role.
- Authorities and advisors: where required by law, to enforce our terms, or to protect rights, safety and property.
6. Your Rights Under POPIA
Subject to applicable law, you have the right to be notified about the processing of your personal information; to request access to it; to request correction, updating or deletion of inaccurate, irrelevant, excessive or unlawfully obtained information; to object to processing on reasonable grounds; and to lodge a complaint with the Information Regulator. To exercise these rights, contact our Information Officer using the details below. If you are a lead or reviewer whose information was captured through a company's card, please contact that company, as it is the responsible party; we will assist it in responding to your request.
7. Data Retention
We retain personal information for as long as your account or company is active and as needed to provide the Service, and thereafter for as long as necessary to meet legal, accounting, tax and dispute-resolution requirements. Captured leads, reviews and analytics are retained for the company that controls them until deleted by that company or removed in accordance with our retention practices. When information is no longer required, we will delete or de-identify it.
8. Security
We maintain reasonable technical and organisational safeguards to protect personal information, including encryption of sensitive credentials and payment tokens, access controls and activity logging. No method of transmission or storage is completely secure, and you are responsible for keeping your login credentials and API keys confidential. We will notify affected parties and the Information Regulator of a security compromise where required by POPIA.
9. Cross-Border Transfers
Some of our service providers may process or store personal information outside the Republic of South Africa. Where we transfer personal information across borders, we take steps to ensure it receives a level of protection consistent with POPIA, for example through appropriate contractual safeguards or because the recipient is subject to comparable data-protection laws.
10. Cookies and Similar Technologies
We use cookies and similar technologies to keep you signed in, remember your active company context, secure the Service, and measure usage and link attribution. Some cookies are essential for the platform to function; others help us understand and improve it. You can control non-essential cookies through your browser settings, though disabling certain cookies may affect functionality.
11. Children
The Service is intended for business use by adults and is not directed at children. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can address it.
12. Changes to this Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
13. Contact and Information Officer
For privacy-related enquiries or to exercise your rights, please contact our Information Officer using the support details published on our website. You also have the right to lodge a complaint with the Information Regulator of South Africa.
