Privacy Policy — Lets Connect

Last updated: 2026-07-20. Lets Connect ("we", "us", "our") operates letsconnectcard.com and related regional storefronts. This Privacy Policy explains what personal information we collect when you visit our website, order an NFC business card, activate a digital profile or contact our support team, how we use that information, the legal bases we rely on under the EU/UK General Data Protection Regulation (GDPR), and the rights available to residents of California under the CCPA/CPRA and other applicable jurisdictions.

1. Who we are and how to contact us

Lets Connect is the controller of the personal data described in this policy. You can reach our privacy team at privacy@letsconnectcard.com or by post at 107 Sunbeam Street, Wolverhampton, WV2 4PG, United Kingdom. For general inquiries visit our contact page.

2. Personal information we collect

We collect the following categories of personal information, either directly from you or automatically when you interact with our sites and cards:

  • Account and profile data — name, job title, employer, phone number, email address, profile photo, social links, portfolio URLs and any additional fields you publish on your digital business card.
  • Order and billing data — shipping address, billing address, order history, product configuration (material, color, engraving), and the last four digits of the card used. Full payment card numbers are collected and stored by our PCI-DSS certified payment processor, not by Lets Connect.
  • Lead capture data — contact details submitted by people who tap or scan your card and complete the lead form on your profile, stored inside the CRM area of your account.
  • Support and correspondence — messages, attachments and call notes when you email, live-chat or phone our support team.
  • Device and usage data — IP address, approximate location derived from IP, browser type, operating system, referring URL, pages viewed, buttons clicked, session duration and card-tap events.
  • Cookies and similar technologies — session cookies, authentication cookies, preference cookies and, subject to your consent where required, analytics and advertising cookies.

3. How and why we use your information

We use personal data for the following purposes and rely on the following legal bases under GDPR/UK GDPR:

  • To provide the service you ordered — programming your NFC card, hosting your digital profile, delivering physical goods and providing customer support (legal basis: performance of a contract).
  • To operate lead capture and CRM features — storing contacts that people voluntarily submit on your profile so you can follow up (legal basis: performance of a contract with you; legitimate interest of the person submitting the form to contact you).
  • To secure our platform — fraud prevention, abuse detection, audit logs and rate limiting (legal basis: legitimate interests in keeping the service safe).
  • To improve our products — aggregated analytics, feature testing and troubleshooting (legal basis: legitimate interests, or consent where cookies require it).
  • To send transactional emails — order confirmations, shipping updates, password resets and security alerts (legal basis: performance of a contract).
  • To send marketing — newsletters, product announcements and offers (legal basis: consent, which you can withdraw at any time via the unsubscribe link in every email).
  • To comply with legal obligations — retaining invoicing and tax records, responding to lawful requests from public authorities (legal basis: legal obligation).

4. Cookies and tracking

We use strictly necessary cookies to keep you logged in and to remember your cart. With your consent we also use analytics cookies (to measure aggregate site performance) and, on some regional storefronts, advertising cookies to measure the effectiveness of paid campaigns. You can accept, reject or manage individual cookie categories at any time from the cookie banner on the site, and you can disable cookies entirely from your browser settings. Rejecting non-essential cookies will not prevent you from placing an order.

5. Third-party processors we share data with

We share the minimum data required with vetted service providers who act on our written instructions and are contractually bound to protect your data:

  • Payments — Stripe (card processing, fraud checks).
  • Hosting and database — our production infrastructure runs on managed Postgres and edge functions in the EU and US regions.
  • Shipping and fulfilment — Royal Mail, DPD, DHL, FedEx, USPS, Canada Post, Australia Post and regional couriers, depending on the destination.
  • Email delivery — Resend and equivalent transactional email providers for order confirmations and support replies.
  • Analytics — privacy-first analytics for aggregated traffic metrics; loaded only after consent where required.
  • Customer support — helpdesk tooling for ticket triage.

We do not sell your personal information and we do not share it for cross-context behavioural advertising as defined by the CCPA/CPRA.

6. International transfers

Some of our providers process data outside your country of residence. When we transfer personal data out of the EEA, UK or Switzerland we rely on adequacy decisions where they exist, or on the European Commission's Standard Contractual Clauses (2021 modules) together with technical safeguards such as encryption in transit and at rest. A copy of the safeguards can be requested at privacy@letsconnectcard.com.

7. How long we keep your data

We retain your account and profile data for as long as your account is active and for up to 24 months after closure to handle refund, warranty and dispute obligations. Order and invoicing records are retained for 6 years (or longer if a local tax authority requires it). Marketing consents are retained until you withdraw them. Support tickets are retained for up to 36 months for training and quality monitoring. Server logs are retained for up to 90 days for security investigations.

8. Your rights

Depending on where you live, you have the right to: request access to the personal data we hold about you; correct inaccurate data; delete data ("right to be forgotten"); restrict or object to certain processing; port your data to another provider in a structured, machine-readable format; and withdraw consent for anything you previously opted in to. California residents additionally have the right to know the categories and specific pieces of personal information collected, to request deletion, to correct inaccurate information, to opt out of any "sale" or "sharing" (we do neither), and to limit the use of sensitive personal information. To exercise any of these rights email privacy@letsconnectcard.com — we will respond within 30 days (45 days for CCPA/CPRA requests, extendable once by another 45 days where permitted by law). You will not be discriminated against for exercising any of these rights.

9. How we protect your data

All traffic to letsconnectcard.com and its regional storefronts is served over HTTPS with TLS 1.2 or higher. Personal data at rest is encrypted using AES-256. Access to production systems is restricted to named engineers via single sign-on with mandatory multi-factor authentication and is fully audit-logged. We run automated dependency and vulnerability scans on every release and conduct periodic third-party penetration tests.

10. Children's privacy

Our services are intended for adult professionals. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal data, contact privacy@letsconnectcard.com and we will delete it.

11. Complaints

If you are unhappy with how we have handled your personal data you can lodge a complaint with the UK Information Commissioner's Office (ico.org.uk), your local EU data protection authority, or, for California residents, the California Attorney General.

12. Updates to this policy

We may update this policy from time to time to reflect changes in our services or in applicable law. When we make material changes we will notify account holders by email and update the "Last updated" date at the top of this page. Continuing to use the service after an update means you accept the revised policy.

Related pages: Refund & Returns · Contact us · Sitemap.