Privacy policy
Last updated
This policy explains how Shard handles information when you use our website, contact cards, and related features. In this policy, “we” and “us” refer to the operator of Shard.
Shard operates from the United States.
Information you provide
Shard lets you create and share contact profiles. We store the information you add to your account and cards, such as your name, role, company, biography, images, contact details, links, and appearance preferences. This includes details you choose to import from a contact file. We also store which cards you publish, your saved connections, and your account settings.
When you sign in with Google or Apple, we receive a provider account identifier and the name and email address that the provider makes available. Apple may provide a private relay email address. Shard does not receive your Google or Apple password.
For passkeys, we store a credential identifier, public key, device label, and verification and usage records. Your passkey private key is managed by your device or passkey provider. Shard does not receive your fingerprint, face scan, or device PIN.
Connections and optional location
When you exchange cards, we record the connection, the cards shared, and when the connection was created. If you choose to share your meeting location and permit browser location access, we store the location with that connection so both participants can view it. You can decline location access and still exchange cards.
How we use information
We use information to create and authenticate accounts, display and update your cards, manage connections, provide requested features, and respond to requests. We also use security records to prevent abuse, enforce access controls, investigate problems, and maintain the service.
Where applicable data protection law requires a legal basis, we process information as needed to provide the service you request, for legitimate interests in operating and securing it, to meet legal obligations, or with consent where required. Optional location sharing can be stopped through your browser or device settings; doing so does not remove locations already saved with a connection.
What other people can see
Published cards are public. Anyone with their URL, QR code, or NFC link may access and share them, and public pages may be indexed by search engines. Only publish details you are comfortable making public. Private account details are not automatically published unless you include them in a published card.
People can save contact files, Wallet passes, screenshots, or other copies of information you share. Unpublishing or deleting a card stops access through Shard but cannot remove copies already saved by others or held in external caches.
Cookies, browser storage, and technical records
We use cookies for sign-in sessions, security checks, and temporary invitation and card-sharing flows. Browser storage keeps interface preferences on your device. Clearing cookies signs you out; clearing browser storage resets those preferences.
The service and its infrastructure providers may process IP addresses, request times, browser information, and error or access logs to deliver and protect the service. Rate limiting uses account identifiers or derived network identifiers to detect excessive requests.
Service providers and disclosures
Shard uses Vercel for application hosting and Amazon Web Services for its database infrastructure. Google and Apple process sign-in requests when you choose their services. Your device or passkey provider may sync passkeys under its own policies. Infrastructure providers process information needed to operate their services, potentially in countries other than your own.
Authorized administrators can access account information when needed to operate, support, or protect Shard. Information may also be disclosed when required by law or necessary to address fraud, abuse, or threats to people's safety. Links on cards lead to independent websites whose privacy practices are their own.
Retention and deletion
We keep account and card information while your account is active and as needed to provide the service. Temporary authentication challenges expire after five minutes. Security records, backups, and records required for legal obligations may remain for longer according to their purpose and the systems that hold them.
You can edit your details, unpublish or delete cards, remove connections, and manage passkeys in your workspace. Account settings → Advanced includes account deletion, which removes your account and associated cards, connections, and credentials from the active application database. Limited invitation records may remain to prevent reuse. Deletion does not erase copies held by recipients, external sign-in providers, or existing backups immediately.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, restrict or object to certain processing, and withdraw consent where processing relies on it. These rights are subject to applicable law. Use the contact address below to make a request. You may also raise a complaint with your local data protection authority. We may need to verify your identity before handling a request.
Children and policy changes
Shard is not intended for children under 13. Do not create an account or submit personal information if you are under 13. If a higher minimum age applies where you live, that minimum applies.
We may update this policy as the service changes. The date above identifies the current version. Where required, we will provide additional notice or obtain consent before making material changes to how we use personal information.
Contact
For questions, privacy requests, or reports about the service, email daiganberger@gmail.com.