← Back

Privacy Policy

Last updated June 10, 2026

Last updated: 9 June 2026. This Privacy Policy explains how TrustKard collects, uses, shares and protects personal information. It is intended to align with the Protection of Personal Information Act, 2013 (POPIA). Please read it together with our Terms & Conditions.

1. Who We Are

TrustKard operates a multi-tenant digital business card platform that enables companies to create branded digital cards and profile pages for their team members, share them via short links and QR codes, capture leads, and collect reviews. For the personal information you provide about yourself and your account, we act as the responsible party. For information that a company collects through its cards, links and contact forms (for example, leads and reviews), that company is the responsible party and we act as an operator (processor) on its behalf.

2. Personal Information We Collect

3. How and Why We Use Personal Information

We use personal information to create and manage accounts and companies; to render and serve public cards, links, QR codes and wallet passes; to capture and deliver leads and reviews to the relevant company; to calculate and collect fees and process payments and store orders; to provide analytics and attribution reporting; to operate integrations you configure; to provide support; to maintain security and prevent abuse; and to comply with our legal obligations.

4. Lawful Basis for Processing

We process personal information where it is necessary to perform our contract with you, to pursue our or a company's legitimate interests (such as operating, securing and improving the platform), to comply with a legal obligation, or on the basis of consent where required. Where we rely on consent (for example, certain non-essential cookies), you may withdraw it at any time.

5. How We Share Personal Information

We do not sell your personal information. We share it only as needed to operate the Service, including with:

6. Your Rights Under POPIA

Subject to applicable law, you have the right to be notified about the processing of your personal information; to request access to it; to request correction, updating or deletion of inaccurate, irrelevant, excessive or unlawfully obtained information; to object to processing on reasonable grounds; and to lodge a complaint with the Information Regulator. To exercise these rights, contact our Information Officer using the details below. If you are a lead or reviewer whose information was captured through a company's card, please contact that company, as it is the responsible party; we will assist it in responding to your request.

7. Data Retention

We retain personal information for as long as your account or company is active and as needed to provide the Service, and thereafter for as long as necessary to meet legal, accounting, tax and dispute-resolution requirements. Captured leads, reviews and analytics are retained for the company that controls them until deleted by that company or removed in accordance with our retention practices. When information is no longer required, we will delete or de-identify it.

8. Security

We maintain reasonable technical and organisational safeguards to protect personal information, including encryption of sensitive credentials and payment tokens, access controls and activity logging. No method of transmission or storage is completely secure, and you are responsible for keeping your login credentials and API keys confidential. We will notify affected parties and the Information Regulator of a security compromise where required by POPIA.

9. Cross-Border Transfers

Some of our service providers may process or store personal information outside the Republic of South Africa. Where we transfer personal information across borders, we take steps to ensure it receives a level of protection consistent with POPIA, for example through appropriate contractual safeguards or because the recipient is subject to comparable data-protection laws.

10. Cookies and Similar Technologies

We use cookies and similar technologies to keep you signed in, remember your active company context, secure the Service, and measure usage and link attribution. Some cookies are essential for the platform to function; others help us understand and improve it. You can control non-essential cookies through your browser settings, though disabling certain cookies may affect functionality.

11. Children

The Service is intended for business use by adults and is not directed at children. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can address it.

12. Changes to this Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

13. Contact and Information Officer

For privacy-related enquiries or to exercise your rights, please contact our Information Officer using the support details published on our website. You also have the right to lodge a complaint with the Information Regulator of South Africa.