1.Who we are
Cardly.ae is a digital business card service operated by Meta Pro Solutions, a company registered in the Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates (“Cardly.ae”, “we”, “us”).
For the personal data described in this policy we are the controller — the party that decides why and how the data is processed — except for leads collected on a card, where the card owner is the controller and we act as their processor (see Card owners, visitors and leads).
- Operator
- Meta Pro Solutions
- Address
- Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates
- hello@cardly.ae
- Phone
- +971 4 430 1882
This policy is aligned with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “PDPL”). At the date of this policy, the PDPL's Executive Regulations have not yet been issued; we will review and update this policy when they are.
2.What this policy covers
This policy applies to:
- the Cardly.ae website and dashboard at cardly.ae;
- public card pages hosted on Cardly.ae (for example cardly.ae/your-name), and the NFC tap and QR code links that open them;
- physical NFC products bought from our online shop;
- emails, support conversations and other communications with us.
It doesn't cover third-party websites or apps that a card links to, such as LinkedIn, WhatsApp or a company website — their own privacy policies apply. How we use cookies and similar technologies is explained in more detail in our Cookie Policy.
3.The personal data we collect
What we collect depends on how you use Cardly.ae. We don't ask for sensitive personal data (such as health information, religious beliefs or biometric data), and we ask you not to add it to your cards.
Your account
- Name, email address and password. Your password is stored only as a salted, one-way hash — we never see or store the password itself.
- Preferred language and, if you add it, a phone number.
- If you sign in with Google: your Google account identifier, name, email address and profile picture, as shared by Google.
- If you turn on two-factor authentication: your authenticator secret and backup codes, stored encrypted.
- If you joined through a referral link: who referred you.
Your cards and content
- Everything you add to a card: names, job title, company, phone and WhatsApp numbers, email addresses, website and social media links, addresses, bios in English and Arabic, photos, logos, cover images and video or map links.
- Card settings, such as the theme and whether a card is published, password-protected or hidden from search engines.
- Photos you upload are re-encoded on our servers, which removes hidden metadata such as camera details and GPS location.
Published cards are public
Anyone with the link, QR code or NFC card can view a published card and save the details on it. Only add information you're comfortable sharing publicly.
Teams
- Organisation name and logo, and the names, email addresses and roles of members.
- Invitations, including the email address of the person invited.
Leads — people who share their details on a card
- When a visitor uses a card's “Exchange contact” button or lead form, we collect what they enter — name, email address and/or phone number, and optionally company, job title and a message — together with their consent, the date and time, and how they reached the card (NFC, QR code or link).
Card visits (analytics)
- When a card is viewed or used, we record the event (view, button click, contact saved, share, NFC tap or lead), how the visitor arrived (NFC, QR code or link), which button was used, the country (derived by Cloudflare from the IP address), device type, operating system, browser and the domain of the referring website.
- To count unique visitors without cookies, we create a daily visitor code: a one-way cryptographic hash (HMAC) of the date, IP address and browser user-agent. The code changes every day and can't be reversed, and the IP address itself is not stored with analytics.
Orders and payments
- Products ordered and personalisation details — for example the name, title and logo printed on a card, and the link its NFC chip opens.
- Delivery name, mobile number and address, contact email and any delivery notes; order status, courier and tracking number.
- Payments are processed by Stripe. Your full card number, security code and Apple Pay or Google Pay credentials go directly to Stripe and never reach our servers. Stripe tells us the payment status and limited details (such as card brand and last four digits) so we can manage orders, subscriptions, refunds and fraud checks.
Subscriptions
- Plan, billing interval, number of seats, subscription status, trial and renewal dates, and the Stripe customer and subscription identifiers. The billing name, address and any tax details you enter at checkout are held by Stripe.
Support, contact and newsletter
- Messages you send us through the contact form or by email: name, email, phone, company, topic, message and language.
- If you subscribe to our newsletter: your email address, language, where you signed up and whether you confirmed your subscription.
Security and technical data
- Sign-in sessions: a session identifier, IP address, browser user-agent and expiry time, used to keep your account secure and detect suspicious sign-ins.
- Audit logs of security-relevant and administrative actions, such as password or plan changes.
- IP addresses held briefly in memory to enforce rate limits (these are not written to our database).
- Web server and network logs, including IP addresses, kept by our hosting and network providers for security and troubleshooting.
- Bot-protection signals processed by Cloudflare Turnstile when you submit a protected form.
- For NFC products: the chip's code, the card it opens, the number of taps and the time of the last tap.
4.How we use your data and our lawful basis
Under the PDPL we may process personal data with your consent, or without consent where the law allows it — for example where processing is necessary to perform a contract with you, to comply with a legal obligation, or to establish, exercise or defend legal claims. The table shows each purpose and the basis we rely on.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Create and run your account, cards, team and dashboard | Account, card and team data | Performance of our contract with you (Terms of Service) |
| Show your public card and let visitors save your contact, message you or share their details with you | Card content; lead data | Contract with the card owner; the visitor's consent for leads |
| Provide card analytics to card owners | Analytics events and the daily visitor code | Contract with the card owner |
| Process payments, subscriptions, orders, delivery and refunds | Order, subscription and payment data | Performance of a contract; legal obligations under consumer protection and tax law |
| Send service emails — verification, password resets, receipts, lead alerts, order updates and renewal reminders | Name, email address, language | Performance of a contract |
| Keep Cardly.ae secure and prevent spam, fraud, abuse and unauthorised access | Security data, sessions, rate-limit data, Turnstile signals | Performance of a contract and our legal duty under the PDPL to secure personal data |
| Answer your questions and support requests | Contact and support data | Steps you ask us to take; performance of a contract |
| Send newsletters and product news | Email address, language | Your consent (opt-in), which you can withdraw at any time |
| Keep financial records, respond to lawful requests from authorities and enforce our terms | Orders, invoices, audit logs | Legal obligations; establishing, exercising or defending legal claims |
| Understand how Cardly.ae is used so we can improve it | Aggregated or anonymised statistics only | Not personal data once it can no longer identify anyone |
Create and run your account, cards, team and dashboard
- Data used
- Account, card and team data
- Lawful basis
- Performance of our contract with you (Terms of Service)
Show your public card and let visitors save your contact, message you or share their details with you
- Data used
- Card content; lead data
- Lawful basis
- Contract with the card owner; the visitor's consent for leads
Provide card analytics to card owners
- Data used
- Analytics events and the daily visitor code
- Lawful basis
- Contract with the card owner
Process payments, subscriptions, orders, delivery and refunds
- Data used
- Order, subscription and payment data
- Lawful basis
- Performance of a contract; legal obligations under consumer protection and tax law
Send service emails — verification, password resets, receipts, lead alerts, order updates and renewal reminders
- Data used
- Name, email address, language
- Lawful basis
- Performance of a contract
Keep Cardly.ae secure and prevent spam, fraud, abuse and unauthorised access
- Data used
- Security data, sessions, rate-limit data, Turnstile signals
- Lawful basis
- Performance of a contract and our legal duty under the PDPL to secure personal data
Answer your questions and support requests
- Data used
- Contact and support data
- Lawful basis
- Steps you ask us to take; performance of a contract
Send newsletters and product news
- Data used
- Email address, language
- Lawful basis
- Your consent (opt-in), which you can withdraw at any time
Keep financial records, respond to lawful requests from authorities and enforce our terms
- Data used
- Orders, invoices, audit logs
- Lawful basis
- Legal obligations; establishing, exercising or defending legal claims
Understand how Cardly.ae is used so we can improve it
- Data used
- Aggregated or anonymised statistics only
- Lawful basis
- Not personal data once it can no longer identify anyone
We don't make decisions about you based solely on automated processing that have legal or similarly significant effects, we don't build advertising profiles, and we don't sell personal data.
5.Card owners, visitors and leads
Our role depends on who is using Cardly.ae and how:
- Card owners
- People and teams who create cards. We are the controller of their account data. Card owners decide what to publish and are responsible for having the right to share any information about other people that they add.
- Card visitors
- People who open a card. We process limited technical data to display the card, protect it from abuse and give its owner cookieless statistics.
- Leads
- Details a visitor chooses to share with a card owner through a lead form. The card owner is the controller of leads, and Cardly.ae acts as their processor.
How we handle leads as a processor
- A lead is only submitted after the visitor ticks a consent box confirming that their details will be shared with the card owner.
- We process leads only to provide the service to the card owner — storing them in their dashboard, notifying them by email and letting them export leads — never for our own marketing.
- We don't email visitors on a card owner's behalf.
- Leads are kept until the card owner deletes them or closes their account. For team cards, leads may be visible to the team's admins.
If you shared your details with a card owner and want them corrected or deleted, please contact that card owner directly. If you can't reach them, email hello@cardly.ae with the card link — we'll pass your request on and help where we can.
Card owners: your responsibilities
Use leads only for the purpose the visitor expected — usually following up on your conversation. Get separate consent before adding anyone to a marketing list, act promptly on opt-out requests, and keep exported leads secure.
8.International data transfers
Cardly.ae is operated by a UAE company, but our servers and service providers are located outside the UAE. Our application servers, database and uploaded files are hosted on a virtual private server operated by Hostinger in a data centre outside the UAE, and Stripe, Resend, Cloudflare and Google process data in other countries, including the United States and member states of the European Union. This means your personal data is transferred outside the UAE.
We transfer personal data abroad only as permitted by the PDPL (Articles 22 and 23) — in particular where the transfer is necessary to perform our contract with you — and we protect it with:
- data processing terms with our providers that require confidentiality, appropriate security and use of the data only to provide their services to us;
- encryption in transit (HTTPS/TLS) for all connections;
- strict access controls and data minimisation — for example, we never store raw IP addresses for analytics, and we never store payment card numbers at all.
We do not claim that your data is stored in the UAE. If we change where data is hosted, we'll update this policy.
9.How long we keep data
| Data | Retention period |
|---|---|
| Account and profile | While your account is open; deleted within 30 days after you delete your account. |
| Cards, uploaded images and team content | Until you delete them or your account; then permanently deleted within 30 days. |
| Leads | Until the card owner deletes them or closes their account (then within 30 days). |
| Card analytics events | 25 months from the event, then deleted or reduced to anonymous totals. |
| Sign-in sessions | Until the session ends (at most 30 days), plus up to 30 days for security. |
| Orders, invoices and payment records | At least 5 years after the end of the relevant tax period, as required by UAE tax law — even if you delete your account. |
| Contact and support messages | Up to 24 months after the conversation ends. |
| Newsletter subscription | Until you unsubscribe. We keep a minimal record of the opt-out so we don't email you again. |
| Security and audit logs | Up to 24 months. |
| Rate-limit data | In memory only, for no more than one hour. |
| Backups | Deleted data is removed from backups on a rolling basis, within 30 days of its deletion from our live systems. |
Account and profile
- Retention period
- While your account is open; deleted within 30 days after you delete your account.
Cards, uploaded images and team content
- Retention period
- Until you delete them or your account; then permanently deleted within 30 days.
Leads
- Retention period
- Until the card owner deletes them or closes their account (then within 30 days).
Card analytics events
- Retention period
- 25 months from the event, then deleted or reduced to anonymous totals.
Sign-in sessions
- Retention period
- Until the session ends (at most 30 days), plus up to 30 days for security.
Orders, invoices and payment records
- Retention period
- At least 5 years after the end of the relevant tax period, as required by UAE tax law — even if you delete your account.
Contact and support messages
- Retention period
- Up to 24 months after the conversation ends.
Newsletter subscription
- Retention period
- Until you unsubscribe. We keep a minimal record of the opt-out so we don't email you again.
Security and audit logs
- Retention period
- Up to 24 months.
Rate-limit data
- Retention period
- In memory only, for no more than one hour.
Backups
- Retention period
- Deleted data is removed from backups on a rolling basis, within 30 days of its deletion from our live systems.
We may keep specific data for longer where we need it to resolve a dispute, comply with a legal obligation or a request from a competent authority, or enforce our terms — and only for as long as that need lasts.
10.How we protect your data
- HTTPS/TLS encryption on every connection, with HTTP Strict Transport Security.
- Passwords stored only as strong, salted one-way hashes; mandatory email verification for new accounts; optional two-factor authentication.
- Bot protection (Cloudflare Turnstile), rate limits and hidden spam traps on public forms.
- A strict Content Security Policy and other browser security headers.
- Uploaded images re-encoded to remove hidden metadata and potentially malicious content.
- Access to personal data limited to authorised people who need it, with audit logs of administrative actions.
- Payment card data handled only by Stripe, a PCI DSS Level 1 certified payment provider.
No online service can be completely secure. If a personal data breach is likely to affect the privacy, confidentiality or security of your data, we will notify the UAE Data Office and affected users as required by the PDPL, and tell you what we are doing about it.
11.Your rights
Subject to the conditions set by the PDPL, you have the right to:
- Access — obtain information about the personal data we hold about you, how we use it and who we share it with, and a copy of it;
- Portability — receive your data in a structured, machine-readable format and, where technically feasible, have it sent to another controller;
- Correction — have inaccurate or incomplete data corrected;
- Erasure — have your data deleted, for example when it's no longer needed or you withdraw your consent;
- Restriction — ask us to restrict processing in certain cases, for example while we check a complaint about accuracy;
- Objection — object to or ask us to stop processing, including for direct marketing;
- Withdraw consent at any time, without affecting processing carried out before you withdrew it;
- Object to automated decisions that have legal consequences or seriously affect you (we don't make any).
Do it yourself in seconds
- Edit your profile and cards at any time from the dashboard.
- Export your account data as a JSON file from Settings.
- Delete your account from Settings — your cards are unpublished immediately and your data is deleted within 30 days, except records we must keep by law, such as invoices.
- Unsubscribe from marketing emails using the link in any newsletter.
Or ask us
Email hello@cardly.ae, ideally from the email address linked to your account. We may need to verify your identity before acting on a request. We'll respond within 30 days; if a request is complex and we need more time, we'll tell you why. Requests are free of charge unless they are clearly unfounded or excessive.
If you're not satisfied with our response, you have the right to complain to the UAE Data Office, the federal authority responsible for personal data protection.
12.Marketing communications
We send newsletters and product news only if you opt in — for example by subscribing and confirming your email address. Every marketing email includes an unsubscribe link. We don't send marketing messages by SMS or WhatsApp without your prior consent.
We'll still send essential service messages — such as security alerts, receipts, renewal reminders and notices of changes to our terms — because they're part of the service you use.
13.Children
Cardly.ae is a professional service for adults. You must be at least 18 years old to create an account or buy from our shop. We don't knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we'll delete it.
14.Changes to this policy
We may update this policy when our service, our providers or the law change — including when the PDPL Executive Regulations are issued. We'll update the “Last updated” date and version at the top of this page.
If a change materially affects how we use your personal data, we'll notify you by email or in your dashboard before it takes effect, and where a change requires your consent, we'll ask for it. Previous versions are available on request.
15.Contact us
For any privacy question or request, contact Meta Pro Solutions:
- hello@cardly.ae
- Phone
- +971 4 430 1882
- Post
- Meta Pro Solutions, Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates