Privacy Policy
Last updated: 15 August 2026
This policy explains what data AurCard collects, why we collect it, how we use and protect it, and what rights you have over it. By using the platform you agree to what follows.
1. Data we collect
Account data: your name, email address, mobile number, and a password stored in an irreversible hashed form.
Card data: whatever you choose to publish — job title, contact details, links, logo, images, and opening hours.
Company data: business name, sections, branches, and team members.
Usage data: card views, saves and shares, and device and browser type in aggregate.
2. Payment data
We never store card numbers. Payments are handled by licensed payment gateways, and all we receive back is the last four digits, the card scheme, and the expiry date, so we can show you which card is on file.
When you enable automatic renewal the gateway stores your card and we keep only a reference token that cannot be used anywhere else. You can cancel renewal and delete that token at any time from your account settings.
3. Why we use your data
To run the service and show your card to visitors, to process subscriptions, to send notices about your account, to improve the platform, to answer your enquiries, and to comply with applicable Saudi regulations.
We do not sell or rent your data to anyone.
4. What visitors can see
Your public card is built to be shared, and everything on it is visible to anyone holding its link or scanning its code. Do not put anything on your card that you would not want to be public.
Your account settings, analytics, and team data are not public and are never shown to card visitors.
5. Sharing with third parties
We share the minimum necessary with providers acting on our behalf: payment gateways, our email provider, hosting, and analytics.
Each is bound to protect the data and use it only to deliver that service. We may also disclose data where legally required by a competent authority.
6. Cookies
We use strictly necessary cookies to keep you signed in and to protect forms from automated abuse, and analytics cookies to understand aggregate usage.
You can disable cookies in your browser, but sign-in will not work without the necessary ones.
7. How we protect your data
Traffic is encrypted over HTTPS, passwords are stored hashed with a modern algorithm, and access to data is permission-scoped and logged.
No method of transmission or storage is completely secure, so we encourage a strong password and two-factor authentication.
8. How long we keep it
We keep your data for as long as your account exists. When you delete your account your data is removed within thirty days, except records we are required to retain, such as invoices.
9. Your rights
You may access, correct, export, or delete your data, withdraw consent to marketing messages, and object to particular processing.
Contact us to exercise any of these and we will respond within thirty days.
10. Children
The platform is intended for people aged eighteen and over. We do not knowingly collect data from children, and remove it promptly if we learn we have.
11. Changes to this policy
We may update this policy and will publish the revised date at the top of the page. We will notify you by email before material changes take effect.
Questions about this policy? Contact us