1. Who we are
1Card ("we", "our", "us") is operated from Kuala Lumpur, Malaysia. We provide digital business cards and NFC-enabled physical cards at 1card.space. This policy explains what data we collect, why, and your rights under the Malaysian Personal Data Protection Act 2010 (PDPA).
2. Data we collect
When you create a 1Card account, we collect:
- Account info: name, email, phone (optional), company, job title, username, password (hashed with bcrypt).
- Card content: any photo, button, link, product or PDF you choose to upload to your card.
- Payment info: we never see or store your card details. All payments are processed by Stripe — we only receive a transaction reference.
- Analytics: aggregated visitor data for Pro users (page views, device OS, country). No personally identifying information about your card visitors.
- Leads: if visitors fill your lead form, we store the data they submit so you can see it in your dashboard.
3. How we use your data
We use your data to:
- Render your card at
1card.space/your-username.
- Process subscription payments and send receipts.
- Send transactional emails (payment confirmations, password resets, lead notifications).
- Improve product quality through aggregate, anonymised usage patterns.
We do not sell your data. Ever. We do not share it with advertisers or third parties for marketing.
4. Who we share data with
We share strictly the minimum needed with these processors:
- Stripe — payment processing (Stripe Singapore Pte Ltd, PCI-DSS compliant).
- Email provider — for transactional emails only.
- Hosting provider — server hosting in Singapore.
We do not transfer your data outside ASEAN unless required by law.
5. How long we keep your data
We keep your account data for as long as your subscription is active, plus 90 days after cancellation (in case you want to reactivate). After that, we purge all personal data permanently. Anonymised analytics may be retained indefinitely for product research.
6. Your rights under PDPA
You can at any time:
- Access a copy of all data we hold on you — Dashboard → Privacy → Export Data.
- Correct any inaccurate data — Dashboard → Profile.
- Delete your account and all associated data — Dashboard → Profile → Delete Account.
- Withdraw consent for marketing emails — unsubscribe link in every email.
- Complain to the Personal Data Protection Department of Malaysia if you believe we're mishandling your data.
7. Cookies
We use a minimal set of cookies — see our Cookie Policy for details. Authentication uses session cookies; we do not run third-party trackers like Facebook Pixel or Google Ads.
8. Security
We protect your data with:
- HTTPS-only connections (TLS 1.2+).
- Bcrypt password hashing (cost factor 12).
- CSRF tokens on all forms.
- Rate-limited authentication endpoints.
- Regular security audits and dependency updates.
9. Children
1Card is not directed at children under 13. If we discover an account belongs to a child, we will delete it.
10. Changes to this policy
If we make material changes to this policy, we'll email you 30 days before they take effect. Minor clarifications may be made anytime — the "Last updated" date at the top reflects the most recent change.
11. Contact
Privacy questions? Email privacy@1card.space or write to:
1Card Privacy Officer
Kuala Lumpur, Malaysia