Syncard

Privacy Policy

Version: v2.0
Effective date: 2026-08-13
Last updated: 2026-08-13
Service provider: ObAIoT Information Co., Ltd. (俄巴資訊有限公司, "we", "us")
Contact: support@obaiot.com

Syncard ("the Service") is a digital business card and business-card scanning service. We take the protection of your personal data seriously, and we collect, process and use your personal data in accordance with Taiwan's Personal Data Protection Act (個人資料保護法, the "PDPA") and related regulations. Please read this policy before using the Service.

1. What data we collect

We collect the following only to the extent necessary to provide the Service:

1.1 Data you provide

  • Card images: photographs of business cards you take with the camera or upload (these may include both your own card and the card of the person you are exchanging with).
    • Exchanged and collected cards are retained by the recipient (please understand this before you exchange): when you exchange your card with someone, or when your card is collected from a public page by someone, that delivery is complete — the recipient receives card content they may keep indefinitely (the card image and the recognised fields), not a link you can later withdraw on your own. Deleting that card or deleting your account afterwards does not make the content in the recipient's hands disappear. This is the same as handing over a paper card: once given, it cannot be taken back. For the exact scope of deletion and its exceptions, see section 5.
  • Contact details extracted from cards: the fields obtained from a card image through optical character recognition (OCR) and structuring — for example name, job title, company, phone, email, address, website and social accounts.
  • Persona (digital card) content you create: display name, self-introduction, contact fields, social links, avatar and other data you enter or edit.
  • Exchange and interaction records: the content and metadata generated when you exchange cards or send messages through the Service.

1.2 Account and authentication data

  • When you sign in with a third-party account (for example Google or LINE), the identifier, email address and basic profile supplied by that identity provider. We do not receive your password for that third-party account.

1.3 Payment-related data

  • Subscription plan, purchase records and transaction status.
  • We do not handle or store your full credit card number or financial account number; the actual charge is processed by the third-party payment providers described below, and we receive only the transaction result they return and the identifiers necessary for reconciliation.

1.4 Device, usage and technical data

  • Device and browser type, operating system, language and time zone, approximate usage behaviour and error-diagnostic records, used for operations, debugging and security.
  • To provide the offline and caching features of a progressive web app (PWA), we store necessary preferences and cached data in your device's local storage (such as localStorage, Service Worker cache and IndexedDB); see section 6.

1.5 Location data (optional)

  • If you use location-related features, we may process approximate or precise location information with your permission, in order to show nearby results or normalise addresses. You can withdraw that permission in your device settings at any time.

2. How we use this data (purposes of collection)

We process your personal data for the following specific purposes:

  • Providing core features: recognising cards, creating and managing your digital cards, card exchange, contact management and search.
  • Account management and authentication: creating, signing in to and maintaining your account and its security.
  • Payments and subscriptions: processing payments, subscriptions, refunds and reconciliation.
  • Service improvement and customer support: debugging, performance work, and responding to your questions and complaints.
  • Legal compliance and security: preventing fraud, abuse and unauthorised access, and responding to lawful requests.

We do not sell your card content or contact data to third parties, and we do not use it for marketing unrelated to the purposes above unless you separately consent.

3. Card recognition (OCR / AI) — specific notes

  • How recognition works: after a card image is uploaded to our cloud storage, a third-party image text-recognition service reads the image and extracts text; the extracted text is then sent to a large language model (LLM) for field classification and structuring (deciding which value is the name, the company, the phone number, and so on). Once recognition completes, the structured result is stored back to your account.
  • We send only the image and text content necessary to complete recognition. The third parties above act as our processors: by contract they may process the data only on our instructions and may not use it for their own purposes. See section 4.
  • Notice and consent before anything is sent: before you use the scanning feature for the first time and before any image is sent to those third parties, we explain the processing described in this section on a dedicated screen and obtain your consent; nothing is sent until consent is given. You can withdraw consent at any time under Settings → Privacy & data → AI recognition. After withdrawal, new scans still arrive in your inbox but are not sent for AI recognition, so no structured fields are produced.
  • On whether your data trains AI models: for the field-classification LLM step, we require upstream model providers not to retain the content and not to train models on it; if no provider meeting those conditions is available, the request fails outright — it is not re-routed to a provider that would retain the content.
  • Some card text recognition happens locally on your device (using the text recognition built into the operating system); that part sends no image to any third party.
  • Please note: when you scan someone else's card, you may be collecting that third person's personal data. You are responsible for ensuring you have a lawful basis for collecting, storing and subsequently using it (for example the other party's reasonable expectation when exchanging cards). For contact records you create yourself, you are the controller of that data and must respect the data subject's rights.

4. Which third parties we share data with (processors)

To provide the Service we engage third-party processors. They may process data only on our instructions and only to the extent necessary to provide their service, and they are bound by confidentiality and security obligations.

Categories of processor include: cloud infrastructure and storage, managed databases, cache and job queues, image text recognition (third-party AI), large language model routing (third-party AI), third-party sign-in, messaging channels, mobile payments, and transactional email.

Your card images are sent to a third-party AI service for text recognition, and the recognised text is then sent to a third-party AI model for field classification. We explain this separately and obtain your consent before you use the scanning feature for the first time (see section 3).

The complete list of processors — each processor's name, purpose and the data it handles — is maintained at Subprocessors. We announce additions and changes on that page.

We also require the processors above to provide protection for the user data they receive that is the same as or equivalent to what this policy sets out; where such protection cannot be provided, we do not share user data with them.

No one outside the subprocessor list handles your data. We share it further only: (a) with your consent; (b) where necessary to perform our contract with you; (c) where required by law or by a competent authority or court; or (d) to protect the rights, property or safety of us or others. We do not sell your card content or contact data, and we do not use it for marketing unrelated to the purposes in section 2.

4.1 Cross-border transfers

The Service's infrastructure is located outside Taiwan, specifically:

  • Card images are stored in Japan and text recognition is performed in Japan.
  • Account data, card fields and contact records are stored in Singapore.
  • The text needed for card field classification is passed by a third-party model-routing service to its upstream model providers (see section 3); the actual country of processing depends on those providers' nodes.

These transfers are international transfers within the meaning of the PDPA. We protect them through contractual terms with each processor, encryption in transit and access controls.

5. Retention and deletion

  • Retention period: we retain your personal data only for as long as necessary to achieve the purpose of collection, or until a retention period required by law expires.
  • Deleting a card or contact: you can delete cards or contacts you created within the Service. Once deleted, the card and its image and derived data are removed from your account and no longer appear in your card list, search results, public pages or usage counts.
    • Never delivered: if the card has never been obtained by anyone through exchange or collection, its image and derived data are erased from our storage (including object storage) within a reasonable period.
    • Already delivered (exception): if the card is already held by someone else, we do not delete its content — the card data remains in the Service so that the copy in the holder's hands stays complete and readable, but it is unlinked from your account (the owner field is replaced with a non-reversible placeholder). From then on it belongs to no account and no longer counts towards any of your usage. Only once the last holder removes the card or deletes their account is the data genuinely erased.
    • We state this plainly: in the exception above, your card content remains on our systems — it is not merely sitting on the other party's device. This is necessary to honour what delivery means, and it is not a stricter form of deletion.
  • Deleting your account: you can request this directly in the Service under Settings → Privacy & data → Delete account. If you can no longer sign in, you can email support@obaiot.com instead. Once requested, the process is:
    • 14-day grace period: we mark your account "pending deletion" and start a 14-day grace period from the time of the request. You can keep using the Service normally during that period.
    • Cancellable within the grace period: before the period expires you can ask to cancel the deletion and the account returns to normal. When you make the request we email you the scheduled deletion date and how to cancel.
    • Permanent deletion on expiry: when the grace period expires, the system deletes automatically — removing the cards under your account and their images (including originals and derivatives in object storage), contacts, message records, notifications, collections, preferences and the account itself. This deletion is irreversible.
    • Two exceptions on expiry (stated plainly): the following two categories are not deleted, in both cases because they involve the other party to an exchange and cannot be disposed of on your request alone —
      1. Cards already held by others: handled exactly as under "Deleting a card or contact → already delivered" above (content kept, unlinked from your account, erased only once the last holder leaves).
      2. Exchange records: an exchange record belongs to you and to the other party at the same time, so deleting it would also erase the record the other party lawfully holds. We therefore anonymise rather than delete — the identifiers in that record that belong to you are replaced with a non-reversible placeholder, and the record itself is kept for the other party.
    • The very small amount of data kept after deletion: to detect repeat registrations and prevent abuse of the grace-period mechanism, we keep a value derived from your email address / third-party account identifier by one-way hashing (it cannot be reversed to the original data), and erase it 365 days after deletion.
    • Scope limit: account deletion is handled on the principle of "deleting only the data under your own account". Data generated jointly with an exchange partner, or already delivered to them, is outside what you can delete unilaterally — and that scope is not limited to a single row in a contact list: it covers the complete content of the card (the card image, all recognised fields, and the exchange record).
    • One-way collection counts too: "delivered" above is not limited to a two-way exchange. When someone collects your card one-way from a page you made public, that also constitutes delivery, and deleting the card or your account afterwards will not withdraw that recipient's access. So when deciding whether to make a card public, weigh this consequence at the moment you make it public.
    • Platform store subscriptions must be cancelled separately: if you subscribed to a paid plan through a platform store such as the App Store, you must cancel that subscription with the platform yourself; deleting your account does not automatically end it.
  • In backups, audit logs, or where required by law, some data may persist briefly beyond the periods above and is deleted or anonymised once that period expires.

6. Cookies and local storage (PWA)

  • The Service is a progressive web app (PWA) and uses your browser's local storage mechanisms (localStorage, Service Worker cache, IndexedDB and similar) to keep you signed in, remember preferences such as dark mode, and provide offline use and performance caching.
  • This data is stored locally on your device. You can clear local storage and caches through your browser settings, though some features — offline use and remembered preferences, for example — may be affected afterwards.
  • We do not use third-party advertising or tracking cookies.

7. Your rights (under the PDPA)

In respect of the personal data we hold about you, you may exercise the following rights under Article 3 of the PDPA:

  • Enquire about or request to review your personal data.
  • Request a copy.
  • Request supplementation or correction.
  • Request that we stop collecting, processing or using it.
  • Request deletion.

Most of these — enquiry, review, correction and deletion — can be done directly in the Service: cards and contacts can be edited or deleted on their own screens, account deletion is under Settings → Privacy & data → Delete account, and consent to third-party AI processing can be withdrawn under Settings → Privacy & data → AI recognition. For other requests, or if you can no longer sign in, email support@obaiot.com; to protect your data we may need to verify your identity first, and we will respond within the period the law allows.

If you have concerns about how we handle your personal data, you may also raise them with Taiwan's competent data protection authority.

7.1 The boundary of a deletion request (cards already delivered to others)

For card content already delivered to other users through exchange or collection (see sections 1.1 and 5), your deletion request has the following boundary, which we state plainly:

  • What we will do: unlink that card from your account so that it is removed entirely from your card list, search, public pages and usage counts, and replace the owner identifier with a non-reversible placeholder.
  • What we will not do: retrieve that card content from a holder's card book. A holder exercises rights over the data in their own card book independently, so a request to delete that copy must be directed to that holder — it is outside what the Service can carry out unilaterally.
  • Eventual erasure: once the card has no holders left, its content is erased by the Service without any further request from you.
  • This boundary rests on the consent and understanding you gave at the moment the exchange was made, or at the moment you made the card public. If you believe a particular situation does not meet those premises, contact us at support@obaiot.com and we will handle it case by case.

8. Data security

We take reasonable technical and organisational measures — encryption in transit, access controls and the principle of least privilege among them — to protect your personal data against unauthorised access, alteration, disclosure or destruction. However, transmission and storage over the internet cannot be guaranteed absolutely secure, and we cannot promise complete data security.

9. Children and minors

The Service is not directed at children. If you are a minor, you should use the Service with the consent of your legal guardian.

10. Changes to this policy

We may revise this policy in response to features, legal requirements or operational needs. We will notify you of material changes within the Service or by other appropriate means. A revised policy applies from the effective date announced with it.

11. Contact us

If you have any questions about this policy or your personal data, please contact:


The Traditional Chinese version of this policy is the authoritative text. Translations into other languages are provided for convenience only; in the event of any discrepancy between language versions, the Traditional Chinese version prevails.