Privacy
What your visit leaves behind
You opened a business's digital card, and this is everything that got recorded. Further down, what we keep about the business that pays for the service.
Updated September 2026
Kept
- That the card was opened, and whether you got here by scanning the code or following a link.
- Which button you tapped: WhatsApp, Instagram, the Google review, the contact.
- The city, metro area, region and country you connected from.
- If you left your number in the contact row, your name and phone, so the owner can call you back. You typed those in: they are never inferred from anything.
Not kept
- Your name, phone or email, unless you typed them yourself.
- Your IP address. It is glanced at to stop bots and written down nowhere.
- Your exact location. Your phone is never asked for GPS.
- What phone you have or what browser you use.
- Any identifier that would recognize you from one visit to the next, here or anywhere else.
Where you are, roughly
We never ask for your location: it is what the network already resolved before your visit arrived, and it stops at the city. Never the street, never a point on a map, never GPS.
The owner sees which cities people find them from, which helps them know where to hand out their card. Anything finer isn't business insight: it's surveillance, and it isn't ours to hold.
What stays on your phone
One marker that lasts as long as the tab does, so the same visit isn't counted twice. Close the tab and it goes with it.
Cloudflare, which runs the infrastructure, may leave a cookie of its own to tell a person from a bot. It is security, and it is useless for advertising.
If you save the business's contact, the file downloads to your phone and it is yours. Nothing else: no tracking cookies, which is why there's no banner asking you to accept them.
How long it lasts
Card taps delete themselves after 90 days. What survives the month are the totals (how many opens, how many taps) with no location and nothing pointing at a person.
The number you left in the contact row lives 120 days and then deletes itself. The owner has it to call you back, not to file you away.
What it's for
So the owner knows whether their card works and where people are finding them. Nothing beyond that.
If you tap the button to leave them a review, you go straight to Google: what you write there is between you and Google, under its rules.
It isn't sold, shared, matched against another database or handed to an ad network. No Google Analytics, no Meta pixel, and even the card's fonts and icons come from our own server: no other company learns that you came through here.
If the business is yours
From you, the one who pays for the service, something else is kept: your name, your email, your phone, your business name and where it is, your Google link, what you write on your card, and what you send us from your dashboard (like a suggestion). You typed it when you created your account, or gave it to us when we set you up, and it is there to run the service for you.
If you add your team to your card, we keep the name, title, phone and email of each person you add. Add them with their permission: they are shown to whoever opens their card.
If you turn on alerts on your phone, we keep the address Apple or Google gives that device to receive them. The alert travels end-to-end encrypted, and you turn them off from the same place you turned them on.
Your payment doesn't come through here. Your credit card details are taken by Stripe on its own screen and we never see them: what comes back from that charge is whether it went through, the card brand and the last four digits.
Your dashboard, which only you open, loads its fonts from Google Fonts and its icons from unpkg, like most web pages. The card your customers see does not.
Who else touches it
Cloudflare runs the infrastructure: this all lives there. Stripe charges the subscriptions. Resend sends the emails: the ones that reach the owner, and the alert with the number someone left. Google is where the business's public rating is read from, if its card shows it. And Apple's or Google's push service delivers alerts to the owner's phone, only if they turned them on.
None of them gets anything to sell, and none of them touches the person who opens a card except Cloudflare, which is the server. If we ever add another company, it gets written here before it's plugged in, not after.
What you can ask for
To see what we have about you, correct it or delete it. Write to us with the business and roughly the day: no form, nothing to justify, and we reply within 30 days at most.
Since we don't sell data or use it for advertising, there is nothing you need to opt out of.
This service is not made for children under 13, and we don't knowingly keep anything about them.
Who answers for this
My Orbyn is the brand. The company behind it is Neutron Studio LLC, of Florida, and it answers for everything this page says. You write to the address below and a person replies.
If this changes, it changes here, with the new date at the top. We can't email the person who opens a card, because we don't have their email; the owner, if the change affects them, we do.