LEGAL

Privacy Policy

Privacy Policy

Privacy Policy

SuperCard · Effective and last updated July 10, 2026

1. Introduction & Scope
This Privacy Policy (the “Policy”) explains how 超數雲端科技股份有限公司 (Business Registration No. 62253367; English name SuperDigital Co., Ltd) (“we”, “us”, “our”, or “SuperCard”) collects, processes, uses, stores, and protects your personal data when you use the SuperCard business-card management service, website, mobile applications, and related features (collectively, the “Service”).
By accessing or using the Service, creating an account, or otherwise interacting with us, you acknowledge that you have read, understood, and agree to the data practices described in this Policy. If you do not agree with any part of it, please discontinue use of the Service.
This Policy forms part of, and should be read together with, our Terms of Service. In the event of any inconsistency regarding personal-data matters, this Policy prevails over the Terms of Service.

2. Who We Are (Data Controller)
The data controller responsible for personal data collected through the Service is:
Company: 超數雲端科技股份有限公司 (SuperDigital Co., Ltd)
Business Registration No.: 62253367
Registered address: 3F, No. 55, Jinggong Rd., Xinfeng Township, Hsinchu County, Taiwan
Privacy contact email: info@supercard-scan.com

3. Information We Collect
3.1 Information You Provide
- Account & identity data: name, email, phone, password (stored hashed), company name, job title, and tenant information.
- Business-card & contact data: card images you upload, scan, photograph, or enter, and the contained names, titles, companies, phone numbers, emails, addresses, and social handles.
- Transaction & subscription data: plan, number of seats, billing information, and invoice data. Sensitive payment data such as card numbers is handled by our third-party payment processor; we do not store full card numbers.
- Support & communication data: messages, feedback, and issue reports you exchange with us.
3.2 Information Collected Automatically
- Device & technical data: IP address, browser type, operating system, device identifiers, and language settings.
- Usage & log data: login records, feature usage, page views, clicks, crash and error logs, access times, and referring URLs.
- Cookies and similar technologies: see Section 6.
3.3 Information from Third Parties
We may receive data about you from third-party sign-in providers, payment processors, enterprise customers (your employer or tenant administrator), or publicly available sources, and combine it with existing data to provide, maintain, and improve the Service.

4. User-Uploaded Third-Party Contact Data
A core function of the Service is to help you manage business cards and contacts. When you upload, scan, or enter the personal data of others (“Card Subjects”), you (or your enterprise/tenant) act as the data controller for that data, and we act solely as a data processor acting on your instructions.
You represent and warrant that, for any third-party personal data you submit, you have a lawful basis to collect, process, and use it (including any required consent or other legal basis), and that such use complies with all applicable data protection laws. You are solely responsible for, and agree to indemnify and hold us harmless against, any claim, dispute, penalty, or damage arising from your upload or use of third-party data (see Section 13).

5. How We Use Your Information & Legal Bases
We process your personal data for the following purposes:
- To provide, operate, and maintain the Service, verify identity, and manage accounts and seats (performance of contract).
- To process subscriptions, payments, invoicing, and billing reconciliation (performance of contract / legal obligation).
- To analyze usage and to research, develop, and improve our features and user experience (legitimate interests).
- To provide customer support, respond to inquiries, and send service-related notices (contract / legitimate interests).
- To ensure information security and to detect and prevent fraud, abuse, and violations (legitimate interests / legal obligation).
- To send marketing where you have consented (consent; you may opt out at any time).
- To comply with law, regulation, court orders, or requests from competent authorities (legal obligation).
We may also de-identify or aggregate your data into anonymous/aggregated data for statistics, analytics, and product improvement. Anonymous or aggregated data that no longer identifies any individual may be used, analyzed, and disclosed by us indefinitely and without restriction under this Policy.

6. Cookies & Tracking Technologies
We and selected third parties use cookies, local storage, and similar technologies to keep you signed in, remember your preferences, ensure security, and analyze and measure use and performance of the Service.
- Strictly necessary cookies: required for login, security, and core functionality; cannot be disabled.
- Functional cookies: remember your settings and preferences.
- Analytics cookies: help us understand usage and improve the Service (e.g., Google Analytics).
You can manage or block cookies via your browser settings, though disabling some cookies may impair functionality. Where required by law, non-essential cookies are placed only after obtaining your consent.

7. Third-Party Services & Data Sharing
We do not sell your personal data. We share it only in the following circumstances and to the minimum extent necessary to achieve the purpose:
7.1 Service Providers (Processors)
We engage trusted third parties to help operate the Service, requiring them to process data under our instructions, apply appropriate security measures, and not use it for their own purposes. Key categories and providers include:
Category | Provider | Purpose
Website analytics | Google Analytics (Google LLC) | Traffic and usage analysis; performance measurement.
Payments | Third-party payment processor | Subscription payment processing, billing, and fraud prevention; full card numbers are handled by the processor and not stored by us.
OCR / image recognition | Google (Google Cloud Vision) | Text extraction and recognition from business-card images.
AI analytics / LLM | OpenAI (OpenAI, L.P.) | AI processing such as parsing, structuring, classifying, and smart organization of card fields.
Cloud & hosting | Cloud hosting provider | Server hosting, database, and data storage.
Other | System and other service providers | System reliability monitoring, notifications, and customer support.
To provide card recognition and smart-organization features, the card images you upload and the text extracted from them may be transmitted to the OCR and AI/LLM providers listed above for processing. For our part, data obtained from such scanning is used only for database storage, retrieval, and to provide Service features; we do not use it to train our own AI models. The processing of data by third-party OCR and LLM providers is governed by their own terms and privacy policies and is beyond our control.
Each third party’s own privacy policy governs its processing of data; we recommend you review them (e.g., Google’s Privacy Policy). We may add, change, or remove service providers from time to time.
7.2 Legal Requirements & Protection of Rights
We may disclose data where we believe it necessary to comply with law, regulation, subpoena, court order, or lawful government request; to protect the rights, property, or safety of us, our users, or the public; or to enforce our terms and detect and prevent fraud and security incidents.
7.3 Enterprise / Tenant Administrators
If you use the Service through an enterprise or organization account, that organization’s administrators may access, manage, or export your account and usage data within the tenant. Your relationship with that organization is governed by its own policies.
7.4 Business Transfers
In connection with any merger, acquisition, reorganization, financing, sale of assets, or bankruptcy, your data may be transferred or disclosed as part of the transaction, subject to protection standards no less protective than this Policy.

8. International Data Transfers
The Service may operate and store data on servers located outside your country or region. Where we transfer data across borders, we implement appropriate safeguards (such as Standard Contractual Clauses or other legally recognized mechanisms). By using the Service, you understand and consent to such transfers.

9. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described in this Policy, or for a longer period where required or permitted by law (e.g., accounting, tax, legal claims, or audit). When retention is no longer necessary, we delete, de-identify, or anonymize the data.
After account termination or deletion, we may retain certain data for a reasonable period to meet legal obligations, resolve disputes, prevent abuse, and enforce agreements; data in backups is deleted on our routine rotation cycle.

10. Data Security
We implement industry-standard technical and organizational measures to protect your personal data, including encryption in transit, access controls, hashed password storage, and least-privilege access. However, no method of transmission or electronic storage is completely secure. To the maximum extent permitted by law, we cannot guarantee absolute security, and you use the Service at your own risk.
You are responsible for safeguarding your account credentials and for all activity that occurs under your account. If you become aware of any unauthorized use, please notify us immediately.

11. Your Rights
Subject to applicable data protection laws, you may have the following rights regarding your personal data:
- The right to access, review, and obtain a copy.
- The right to request correction or completion of inaccurate or incomplete data.
- The right to request deletion or cessation of processing and use.
- The right to restrict and object to processing (including objection to processing based on legitimate interests and to direct marketing).
- The right to data portability (to the extent applicable by law).
- The right to withdraw consent (without affecting the lawfulness of processing before withdrawal).
- The right to lodge a complaint with a supervisory authority.
You may exercise these rights via info@supercard-scan.com. To protect your data, we may need to verify your identity before processing a request, and we will respond within the timeframe required by applicable law. For Card Subject data you have uploaded, such requests should generally be directed to you (or your organization) as the controller.

12. Children’s Privacy
The Service is designed for business and professional use and is not directed at children. We do not knowingly collect personal data from children under 16 (or the minimum age set in your jurisdiction). If we learn that we have collected such data without the required consent, we will delete it promptly.

13. Disclaimers & Limitation of Liability
To the maximum extent permitted by applicable law:
- The Service is provided “as is” and “as available”, without any express or implied warranty that data processing will be uninterrupted, error-free, or absolutely secure.
- We are not liable, to the extent permitted by law, for data breaches or damages caused by third-party service providers, by you or third parties, or by events beyond our reasonable control (including force majeure, hacking, or unauthorized access).
- We are not liable for any indirect, incidental, consequential, punitive, or special damages; our aggregate total liability shall not exceed the amount you actually paid us for the Service in the twelve (12) months preceding the claim.
- You agree to indemnify and hold us harmless from any claim, loss, penalty, or cost (including reasonable legal fees) arising from your breach of this Policy (including the Section 4 warranties) or your unlawful upload or use of third-party data.
Some jurisdictions do not allow the exclusion of certain warranties or the limitation of certain liabilities; in such cases, the above applies only to the fullest extent permitted by law and does not affect your mandatory statutory rights.

14. Acceptable Use & Termination
You and your enterprise/organization agree not to use the Service for any unlawful activity, infringement of others’ rights, or conduct that harms others, including but not limited to: violating applicable laws or regulations; infringing others’ privacy, intellectual property, or other rights; distributing malware, or engaging in fraud, harassment, hate speech, human trafficking, or other inhumane conduct; or otherwise using the Service to harm, exploit, or endanger any person.
If we reasonably believe that you or an enterprise customer has engaged in any such unlawful, harmful, or inhumane conduct, or has breached this Policy or our Terms of Service, we reserve the right to suspend or terminate your access to the Service, and to disable the relevant account or tenant, at any time and without prior notice, and to pursue legal remedies and report to competent authorities. We shall not be liable for any refund or compensation for a termination arising from such causes.

15. Changes to This Policy
We may revise this Policy from time to time. The revised version will be posted on this page with an updated “Last Updated” date, and for material changes we will provide reasonable notice (e.g., in-product notice or email). Changes take effect upon posting, and your continued use of the Service after they take effect constitutes acceptance. Please review this page periodically.

16. Contact Us
If you have any questions, concerns, or requests regarding this Policy or our data practices, please contact:
SuperDigital Co., Ltd (超數雲端科技股份有限公司, Business Reg. No. 62253367)
Address: 3F, No. 55, Jinggong Rd., Xinfeng Township, Hsinchu County, Taiwan
Email: info@supercard-scan.com
Website: https://supercard-scan.com

超數雲端科技股份有限公司 · SuperDigital Co., Ltd · 2026-07-10

From first card to first lead

AI × OCR × light CRM for enterprise business cards

Contact Us

+886 3559 5858

3F, No. 55, Jinggong Rd., Xinfeng Township, Hsinchu County 304034, Taiwan

© 2026 SuperDigital Taiwan
SuperCard is a product of SuperDigital Taiwan.

From first card to first lead

AI × OCR × light CRM for enterprise business cards

Contact Us

+886 3559 5858

3F, No. 55, Jinggong Rd., Xinfeng Township, Hsinchu County 304034, Taiwan

© 2026 SuperDigital Taiwan
SuperCard is a product of SuperDigital Taiwan.

From first card to first lead

AI × OCR × light CRM for enterprise business cards

Contact Us

+886 3559 5858

3F, No. 55, Jinggong Rd., Xinfeng Township, Hsinchu County 304034, Taiwan

© 2026 SuperDigital Taiwan
SuperCard is a product of SuperDigital Taiwan.