Privacy Policy
Last updated: July 29, 2026
This Privacy Policy explains how the Idently team ("Idently", "we", "us") collects, uses, shares and protects personal data when you use our website and services (the "Service"). We are the controller of that data. If you have any questions, email us using the details at the end.
Idently is a platform for publishing digital identity cards. Content you choose to publish (your public cards, directory entries and anything you add to them) is, by design, visible to anyone with the link — please don't put anything on a public card you wouldn't want to be public.
1. Data we collect
- Account & profile — name, email, password (hashed), and the profile details you add (title, company, bio, links, photo).
- Content — cards, uploaded images, and the contacts/leads captured through your forms.
- Usage & analytics — page views, device type, approximate country and referrer for your public cards; product usage and diagnostics.
- Payment data — processed by our payment provider (Stripe). We receive limited billing metadata (plan, status, last-4) and never store full card numbers.
- Communications — messages you send us (e.g. the contact form) and support correspondence.
- Technical — IP address, authentication cookies, and security/rate-limiting signals.
2. How we use data
- provide, maintain, secure and improve the Service;
- render your public cards and deliver the features you enable (lead webhooks, email alerts, digests);
- process payments and manage subscriptions;
- communicate about your account, respond to support, and (with consent where required) send product updates;
- prevent fraud, abuse and violations of our Terms, and comply with law.
3. Legal bases (EEA/UK)
Where GDPR/UK GDPR applies, we rely on: contract (to provide the Service you sign up for), legitimate interests (to secure and improve the Service and prevent abuse), consent (for optional marketing), and legal obligation (e.g. tax and accounting).
4. Sharing & sub-processors
We do not sell your personal data. We share it with service providers who process it on our behalf under appropriate contracts, including categories such as: cloud hosting and object storage (e.g. Google Cloud), payments (Stripe), transactional email (Brevo), and error monitoring (Sentry). We also disclose data where required by law or to protect rights and safety, and in connection with a merger or acquisition (with notice where required).
5. Cookies
We use strictly necessary cookies for authentication, security and rate-limiting. Public-card analytics are collected in aggregate to measure performance. If we add non-essential/marketing cookies, we'll request consent where required.
6. Retention
We keep personal data while your account is active and as needed to provide the Service. After account deletion we remove or anonymise personal data within a reasonable period, except where retention is required for legal, tax, security or dispute-resolution purposes. You can delete individual cards or your whole account at any time.
7. International transfers
We may process data in countries other than yours, including the United States. Where required, we use appropriate safeguards such as the EU Standard Contractual Clauses for such transfers.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, export (portability), and to object to or restrict certain processing, plus the right to withdraw consent and to lodge a complaint with your supervisory authority. California residents (CCPA/CPRA) may request access and deletion and to opt out of "sale"/"sharing" — we do not sell or share personal data as defined there. To exercise any right, contact us below; we may need to verify your identity.
9. Security
We use industry-standard measures including encryption in transit, hashed passwords, access controls and monitoring. No method of transmission or storage is perfectly secure, but we work to protect your data and will notify affected users and regulators of a breach where required by law.
10. Children
The Service is not directed to children under 16 (or the age of digital consent in your country), and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we'll delete it.
11. Changes
We may update this policy; material changes will be posted here with a new "last updated" date and, where appropriate, additional notice.
12. Contact
For privacy questions or to exercise your rights, email hello@idently.com (attn: Privacy). We aim to respond within 30 days.