Privacy Policy
Last updated: July 9, 2026
This Privacy Policy explains how iKennect ("we", "us"), operated by Sapien360, collects, uses, and shares personal data when you use our digital business card platform. We are the data controller for the personal data we process about our account holders and card visitors.
1. Data We Collect
- Account data: name, email, password hash, organization, avatar.
- Card content: anything you publish on your digital card — job title, phone, address, photos, social links.
- Usage & analytics: card views, saves, QR/NFC taps, share events, referrer, approximate location (from IP), device type.
- Technical data: IP address, user agent, cookies, session identifiers, custom-domain routing data.
- Consent records: your GDPR banner choices with timestamps and policy version.
2. How We Use Data
- Provide the Services (host and display your cards, issue Wallet passes).
- Operate NFC/QR redirects and custom-domain routing.
- Measure card performance and provide analytics dashboards.
- Secure our platform, prevent abuse, and comply with legal obligations.
- Communicate with you about your account and product changes.
3. Legal Bases (GDPR)
- Contract: to provide the Services you signed up for.
- Legitimate interest: platform security, aggregate analytics, product improvement.
- Consent: non-essential cookies and marketing communications.
- Legal obligation: tax, accounting, response to lawful requests.
4. Sharing & Sub-Processors
We share personal data with vetted sub-processors that help us operate the Services:
- Supabase / Lovable Cloud — hosted database, authentication, storage.
- Passcreator — Apple & Google Wallet pass generation.
- SaaS Custom Domains provider — DNS routing and automatic SSL for custom domains.
- Sapien360 — single sign-on and workspace provisioning.
We do not sell your personal data.
5. International Transfers
Where personal data is transferred outside the EEA/UK, we rely on European Commission adequacy decisions or Standard Contractual Clauses (SCCs) with additional safeguards where necessary.
6. Retention
- Account & card data: retained while your account is active; deleted within 30 days after account deletion (backups purge on rolling 90-day cycle).
- Analytics events: 24 months, then aggregated.
- Consent records: 24 months from last consent action.
- Billing records: as required by applicable tax/accounting law (typically 7 years).
7. Your Rights (GDPR / UK GDPR / CCPA)
- Access, rectification, erasure, restriction, and portability of your data.
- Object to processing based on legitimate interests.
- Withdraw consent at any time.
- Lodge a complaint with your local supervisory authority.
- California residents have additional rights under the CCPA, including the right to know and delete.
To exercise these rights, email privacy@ikennect.com. We respond within 30 days.
8. Cookies & Similar Technologies
We use strictly necessary cookies to run the Services (session, auth, custom-domain routing). We ask consent for optional analytics and marketing cookies through our GDPR banner. You can change your preferences at any time by clearing cookies or contacting us.
9. Security
We use encryption in transit (TLS), encryption at rest for stored data, hashed passwords, role-based access control, and audit logs. No system is 100% secure — we will notify affected users of a personal-data breach as required by law.
10. Children
iKennect is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
11. Automated Decision-Making
We do not use automated decision-making that produces legal or similarly significant effects on you.
12. Changes to This Policy
We may update this Privacy Policy. Material changes will be notified via the Services or by email. The "Last updated" date at the top always reflects the current version.
13. Contact
Data Controller: Sapien360, on behalf of iKennect. Email: privacy@ikennect.com.