Privacy Policy
Last updated: 21 September 2026
This policy explains what data AurCard collects, why we collect it, how we use and protect it, and what rights you have over it. By using the platform you agree to what follows.
1. Data we collect
Account data: your name, email address, mobile number, and a password stored in an irreversible hashed form.
Card data: whatever you choose to publish — job title, contact details, links, logo, images, and opening hours.
Company data: business name, sections, branches, and team members.
Usage data: card views, saves and shares, and device and browser type in aggregate.
2. Payment data
We never store card numbers. Payments are handled by licensed payment gateways, and all we receive back is the last four digits, the card scheme, and the expiry date, so we can show you which card is on file.
When you enable automatic renewal the gateway stores your card and we keep only a reference token that cannot be used anywhere else. You can cancel renewal and delete that token at any time from your account settings.
3. Why we use your data
To run the service and show your card to visitors, to process subscriptions, to send notices about your account, to improve the platform, to answer your enquiries, and to comply with applicable Saudi regulations.
We do not sell or rent your data to anyone.
4. What visitors can see
Your public card is built to be shared, and everything on it is visible to anyone holding its link or scanning its code. Do not put anything on your card that you would not want to be public.
Your account settings, analytics, and team data are not public and are never shown to card visitors.
5. Sharing with third parties
We share the minimum necessary with providers acting on our behalf: payment gateways, our email provider, hosting, and analytics.
Each is bound to protect the data and use it only to deliver that service. We may also disclose data where legally required by a competent authority.
6. Your customers’ data — processed on your business’s behalf
When your business collects its customers’ numbers through AurCard — by a scan, an import from your phone, or manual entry — your business is the controller of that data and we are the processor acting for it: we store and display it and send only the messages your business asks for, use it for nothing else, and never share it with another business even if it holds the same number.
Responsibility for the lawfulness of collecting those numbers and of the messages sent to them lies with your business as controller; AurCard provides the tools that make it possible: a consent record per number, one-word opt-out, and automatic exclusion of anyone who has not agreed.
7. The consent and opt-out record
For every number in a business directory we keep whether its owner agreed to marketing messages, when, and how we know: a WhatsApp reply with its text and time, a box chosen on a form, or a manual entry with the name of who recorded it. We also keep the stop request when a person sends STOP, and they are then excluded from every later marketing message from that business.
Consent is given to a specific business and does not transfer to another.
8. Linking a business’s WhatsApp number
Your business may link its own WhatsApp number to the dashboard as a linked device, the way WhatsApp Web works. Messages sent from the dashboard and received on that number then pass through our servers to be shown in the inbox and recorded for your business.
We do not read these conversations for our own purposes or analyse them beyond operating the service, and we keep no link-session data beyond what keeps the connection alive. The business can unlink at any time from the dashboard or from WhatsApp’s settings on its phone.
9. What a page visitor is asked
When a visitor scans a business’s code, a sheet may ask for their name and mobile number so the page owner can get in touch. Sharing is entirely optional, the offers box is never pre-ticked, the data is stored with that business alone, and a welcome message in the business’s name is sent only if the business chose that. Whoever closes the sheet or shares is not asked again on the same device.
10. Requesting deletion of a customer’s data
If a customer asks a business to delete their data, the dashboard gives the business a permanent-erasure path separate from ordinary deletion, recording who performed it and when. Anyone may also contact us directly if they cannot reach the business; we will route the request and respond within thirty days.
11. Cookies
We use strictly necessary cookies to keep you signed in and to protect forms from automated abuse, and analytics cookies to understand aggregate usage.
You can disable cookies in your browser, but sign-in will not work without the necessary ones.
12. How we protect your data
Traffic is encrypted over HTTPS, passwords are stored hashed with a modern algorithm, and access to data is permission-scoped and logged.
No method of transmission or storage is completely secure, so we encourage a strong password and two-factor authentication.
13. How long we keep it
We keep your data for as long as your account exists. When you delete your account your data is removed within thirty days, except records we are required to retain, such as invoices.
14. Your rights
You may access, correct, export, or delete your data, withdraw consent to marketing messages, and object to particular processing.
Contact us to exercise any of these and we will respond within thirty days.
15. Children
The platform is intended for people aged eighteen and over. We do not knowingly collect data from children, and remove it promptly if we learn we have.
16. Changes to this policy
We may update this policy and will publish the revised date at the top of the page. We will notify you by email before material changes take effect.
Questions about this policy? Contact us