Privacy & terms
Your digital card is built on one principle: we cannot read your data. We keep an encrypted copy only; its key lives in your link alone, and you can delete it any time.
This is a translation for convenience. If it differs from the Arabic version, the Arabic version prevails.
Where is my data kept?
Everything you enter (name, numbers, links, photo, logo) is compressed and stored inside your full card link itself — in the part after the # sign. Browsers never send this part to any server. If an NFC chip carries this full link, it shows your card even without our servers. If the chip carries your short link instead (when the full card does not fit), it needs our service to work.
The short link: to make sharing easy, on activation we store an encrypted copy of your card on our servers (Cloudflare). The decryption key is the part after # in your link and never reaches us — so neither we nor the hosting provider can read the copy. When your card is opened (by short link, or by tapping the chip while online), the browser requests its encrypted copy from our servers by its short ID to show the latest edit; we do not log that, but the network provider sees the request like any website visit. We use no analytics tools.
Editing and deleting are in your hands: on activation you receive a private “edit link”. With it you edit your card whenever you like — free, instant and without anyone’s approval — and with it you permanently delete the encrypted copy. Only the holder of the edit link can edit your card — and the stand, when it reissues the link at your request after verifying your identity with your card present. We do not keep the edit link. Only your name is locked, to protect your card from being transferred, and it is changed through the stand. After deletion the short link stops working; a chip carrying the full card keeps showing its copy, and a chip carrying the short link stops. If you send a link via WhatsApp or another app, you are handing it to that app.
What the server keeps with each encrypted copy (no personal data): its short ID, its version number, the public key of your edit link (so we can verify your edits without holding their secret), the activation key number, the activation time to the minute, the creation date, and a daily save counter (limit: 30 saves a day). The name fingerprint inside the certificate is encrypted with your card’s key, so it cannot be matched against lists of names.
Activation
After payment, a stand team member issues a digital activation certificate on the stand’s device, and it is added to your card link so the card works. The certificate contains no personal data: the key number, the short ID, the public edit key, the activation time, and an encrypted fingerprint of the name. An unactivated draft link is shown as a preview only and is not stored by us.
What we do not do
- No accounts, no customer database we can read (we do not hold the keys to the encrypted copies), and no cookies. The only things stored on your own device (not with us) are your interface language and light/dark display preference.
- No analytics or tracking tools on card pages.
- We do not sell or share data — because we do not hold it in the first place.
What you should know
- Your card is public to anyone with its link: anyone who taps your card, scans its code or receives its link sees the details you chose to show — just like a printed business card. Do not add details you do not want to share.
- Copies kept by others: anyone who saved your contact or kept your link keeps their copy, even if you change your card later.
- Editing: with your private edit link, free and without approval. If you lose it or it leaks, the stand issues you a new one and the old one stops working.
- Loss: a lost chip keeps showing your card to whoever finds it; we can write a new card for you. A chip carrying the full link cannot be disabled remotely because it never passes through our servers; you can delete the encrypted copy behind the short link (chips carrying the short link then stop working).
- Continuity: the card works as long as the
c.velunapress.comdomain exists; we commit to renewing it and keeping the card format compatible with every earlier version.
Purchase records
When you buy, we keep only what the law requires for invoicing and accounting (order date, type, amount and payment method), in an encrypted record that contains none of your card’s details.
Contact
For any privacy question or a request about your data, contact us through our stand or Veluna Press’s official channels.
Last updated: September 2026 — this page explains how the service works and is subject to legal review under the Personal Data Protection Law of the Kingdom of Saudi Arabia.