NFC Security: What Can Actually Be Read
An NFC business-card tag holds only a public link and reads nothing from your phone. Here is what can be read, what cannot, and where risk really sits.

An NFC tag used for a business card or a shop page holds exactly one thing: a text link — the same link you would share over WhatsApp without a second thought. The tag reads nothing from the phone that touches it, cannot reach contacts, photos or payment methods on that device, and does nothing without consent: the phone displays the link and waits for a tap. Data moves in one direction only, from tag to phone. Which means the real risks here are not in the technology but in what the link leads to, an entirely separate question.
What technically happens on a tap
Understanding the mechanism removes most of the worry. The phone generates a short-range magnetic field. The tag — an inert object with no battery — draws enough energy from that field to power its small chip, which transmits what it holds.
What it holds is rarely more than a single line: a web address.
The phone receives that address and shows it in a notification. Up to this point nothing else has occurred: nothing opened, nothing sent, nothing read from the device. The next step belongs entirely to the user.
One direction only
Most inaccurate reporting on this turns on the idea that a tag "pulls" data from a phone. That is not possible by the structure of the technology in this use.
Photo by Dan Nelson on Unsplash
A tag is a passive storage chip with no processor and no software capable of requesting anything. It cannot ask the phone for contacts, cannot request a permission, cannot open an app. The only thing it does is get read.
The accurate analogy is a piece of paper with an address written on it. The paper does not know who read it, and takes nothing from them.
Where the real risks are
It would be wrong to claim there are no risks at all. They exist, but they sit elsewhere.
A malicious link. The one genuinely meaningful risk: a tag leading to a phishing page asking for login or banking details. The problem there is the page, not NFC — the identical problem as any link arriving in a text message.
Tag substitution. Someone placing their own tag over yours in a public place to divert your customers. Theoretically possible, and addressed by periodic checking.
Overwriting an unlocked tag. Writable tags can have their contents changed if they were not locked after programming.
Note that none of these involves reading data from your phone. All three concern control of the link's destination.
How a user protects themselves
The single rule any user needs: read the address before you tap.
The phone shows the address in the notification before opening it, and that is opportunity enough. If it belongs to an organisation you recognise, tap. If it is unfamiliar, or long and full of random characters, do not.
The second rule: do not enter sensitive information on a page you reached from a tag without verifying it. A page asking for your bank card number after tapping a sticker in a public place has no legitimate reason to exist.
Those two rules cover, in practice, everything an ordinary user needs.
Business cards versus payment cards
A common conflation worth untangling, because it creates anxiety in the wrong place.
Payment cards also use NFC, but on a completely different basis: strong encryption, a token that changes with each transaction so copying it achieves nothing, and identity verification for phone payments through fingerprint, face or PIN. They interact only with approved payment terminals.
A business card needs none of that, because what it carries was already public. Your name, your work number and your page link are things you hand out deliberately.
The point: caution that is correct about payment data does not automatically transfer to a business card. Both use the same radio band, and that is all they have in common.
Can my card be read from a distance?
No. Practical range does not exceed about four centimetres on most devices, and that is a physical constraint rather than a software setting.
The short distance is itself the protection: nobody reads your tag from the next table or while walking past. The required proximity is obvious and deliberate enough that it cannot happen unnoticed.
And even if someone did read it, what they would find is your public page link — the same page you want people to open.
Can my tag be copied?
Yes, and in this context it barely matters. Anyone who can read the link can copy it to another tag.
But what have they gained? They have copied a public link they could equally have obtained by scanning the QR code in your shop window, or from a message you sent. Nothing about it is secret.
Copying is a legitimate worry for access cards and payment, where the code is a key that opens something. On a business card the link is not a key; it is an address.
Protecting tags in a shop
For shop owners, the right focus is the tag as a physical object in a public place.
Lock the tag after programming so it becomes read-only and nobody can write over it.
Check tags periodically. Once a week or two, tap it yourself and confirm it opens your page. That check catches substitution and damage at once.
Watch the numbers. A sudden drop in opens from one tag may mean it was damaged, covered or replaced. The figures warn you before a customer does.
Fix tags firmly in easily reached positions, ideally using stickers that are destroyed by removal.
What about customer privacy?
Shop owners ask whether the tag collects data about their customers.
The tag itself collects nothing. The page it opens records what any web page records: how many opens and when. No customer's name or number is known unless they enter it into a form themselves.
That distinction matters in dealing with customers. If someone asks, tell them plainly that the page does not know who they are and only knows that it was opened. Transparency builds more trust here than deflecting the question.
Questions people ask before they tap
Three questions recur in daily dealings with customers, and it helps to have short answers ready.
"Will it take money?" No. Payment runs through a secured wallet app requiring fingerprint, face or PIN verification, and only completes with an approved terminal. A business-card tag cannot reach any payment method on the device.
"Will it get into my phone?" No. The tag is a passive storage component with no ability to request anything from the device. It only gets read.
"Do I need to install something?" No. Reading is built into the operating system, and the page opens in the browser already there.
Worth noting: these questions are usually asked in the language of worry rather than enquiry, and a short reassuring answer serves better than a long technical explanation, which tends to increase suspicion.
Why your details are not stored in the tag
Storing a name and number on the chip might sound reasonable, but it is worse on both security and practical grounds.
Practically: data written to a tag is fixed. Changing your number would mean reprogramming every tag you ever handed out, which is impossible after distribution.
On security: data stored in a physical object cannot be withdrawn. A tag you gave someone keeps its contents forever. A link, by contrast, lets you control what is displayed, and lets you edit or disable it.
Storing a link instead of data is therefore not a technical shortcut but the better design on both counts.
What if I lose my NFC card?
A practical question for anyone carrying a personal NFC card.
What has been lost is an object carrying a link to your public page — a page you want people to open in the first place. There is nothing on it to exploit.
The essential difference from losing an access card or a bank card is that those are keys that open something, whereas a business card is an address pointing at something public.
That said, if you would rather sever the connection completely, you can change the page's contents or disable it from the dashboard, and the lost card stops showing anything of value.
The practical conclusion
An NFC tag on a business card is among the simplest and lowest-risk technologies in use: it holds a link, works from a few centimetres, reads nothing, and does nothing without a tap.
The only caution required is the ordinary caution owed to any link — look at the address before opening it. And for shops: lock your tags and check them regularly.
The mechanism is explained in what is NFC and how it works, and durability in NFC sticker maintenance.
With AurCard your tag leads to a page whose contents you control entirely, and whose destination you can change without replacing the tag.
Read next
NFC Sticker Maintenance and Lifespan
An NFC tag has no battery and no moving parts, but installation and environment decide its life. Here is what damages one and how to check yours.
NFC Cards for Teams and Employees
NFC cards for a team mean one identity, central updates, and instant deactivation when someone leaves. Here is how to roll them out without chaos.
Where to Place NFC Stickers in Your Shop
Placement decides usage more than anything else. Here are the positions that work in restaurants, clinics and shops — and the ones that waste a tag.
