Privacy Policy
Last updated 8 August 2026
This describes what we hold, why we hold it, and what we do not do with it. It covers three different people: account holders, businesses whose card we host, and members of the public who visit a card.
If you visit a card
You do not need an account and we do not ask you to identify yourself. We count how many times a card has been opened. That count is a number on the card — it is not tied to you, and we do not build a profile of who visited what.
We set no advertising or tracking cookies, and there is no third-party analytics on card pages. Cards may embed content from YouTube or Instagram; those load only when you scroll to them, and once loaded they are governed by those companies' own privacy policies, not ours.
If you leave a review
Ratings above the card's threshold send you to Google, and what you write there is on Google, not here — we only record that a rating of that size was given.
Lower ratings open a private form. What you type there, and any photos or videos you attach, are stored by us and emailed to the business owner. If you enter a name, phone number or email, they are passed on too; leave them blank and your feedback is anonymous.
Photos you attach have their metadata removed before they are stored. Phone cameras write the location where a picture was taken into the file. We strip that out, along with the rest of the embedded metadata, so it does not travel with the photo.
Attachments are stored on Cloudflare R2 at unguessable addresses. Anyone with the exact address can open the file, so please do not attach anything you would not want seen by whoever the business shares that email with.
If you have an account
We hold your email address, and whatever name, phone number and business name you give us. We also keep:
- Your role, and which reseller you belong to if you are a customer of one
- For resellers, the terms agreed with you and every wallet transaction
- A record of actions taken on the platform — who changed what, and when
Passwords are handled by Supabase Auth and stored hashed. We never see them and cannot recover them; we can only reset them.
The activity record exists so that disputes about money or access can be settled by looking rather than arguing. It cannot be edited or deleted, including by us.
Card content
Everything on a published card is public by design — that is what a business card is for. Please do not put anything on one that you would not put on a printed card handed to a stranger.
Who else sees this data
We use a small number of services, each for one job:
- Supabase — database and sign-in, hosted in Mumbai
- Cloudflare R2 — images and video
- Razorpay — payments. Card details go to them, never to us
- An email provider, to deliver private feedback to business owners
We do not sell data. We do not share it for advertising. We do not pass it to anyone beyond the services above, except where the law requires it.
How long we keep it
- Card content — while the card exists, and deleted with it
- Private feedback — while the business's account is open, unless they delete it
- Wallet and payment records — as long as tax and accounting rules require
- Activity records — kept, as they are the record of what happened
Your rights
You can ask what we hold about you, ask for it to be corrected, or ask us to delete an account and its cards. Write to purandardigitalmedia@gmail.com and we will reply within seven working days.
Some things we cannot delete on request: wallet and payment records, which must be kept for accounting, and the activity log, which would be worthless if it could be edited.
Children
This is a service for businesses. It is not meant for anyone under 18 and we do not knowingly collect their information.
Changes
If this policy changes in a way that matters, account holders will be told by email. The date at the top always shows the current version.