Privacy Policy
Effective date: 9 October 2026
Last updated: 30 September 2026
1. Who we are
NemKad ("NemKad", "we", "us") is operated by NemKad Solutions (Malaysia), [BUSINESS REGISTRATION NO.], No. 22-2, Jalan Prima Setapak 3, Taman Setapak, 53300 Kuala Lumpur, Malaysia. We are the data user (controller) for the personal data described in this policy under the Personal Data Protection Act 2010 ("PDPA").
Privacy contact: helpline@nemkad.com.
2. What this policy covers
This policy explains what personal data we collect when you use nemkad.com and the NemKad service (the "Service"), why we collect it, who we share it with, how long we keep it, and your rights. It applies to card owners, to visitors who view a card, request contact details or send a message through a card's Contact me form, and to people who join a waitlist.
3. Data we collect
Account data (card owners). Email address; if you sign in with Google, the name, email and profile picture Google shares with us; the username you claim; sign-in timestamps; whether you asked for tips emails, and which tips emails we sent you.
Card content (card owners). Everything you put on your card: name, title, company, photo, banner, phone, WhatsApp, email, links, bio and any other detail you choose to add. You decide what goes on your card and, for phone, WhatsApp and email, whether each is public, for connections only, or private. Your email address is never shown to visitors, whatever its setting: visitors reach you through the Contact me form, and only members you are connected with can see it.
Connections. When you ask to connect with a card owner we collect your account details (see above), an optional message (up to 140 characters) and the time of the request. When you use an invite link we record which member invited you.
Messages. The text of messages you send to your connections, when they were sent and read, and any report you make about a conversation.
Enquiries (Contact me form). When you send a message to a card owner through the Contact me form on their card: your name, your email address, your message, the card it was sent to and the time. You do not need an account. If you are signed in, the enquiry is linked to your account and uses your account email. To keep the form from being abused we check it with Cloudflare Turnstile (signed-out senders only) and apply limits using a salted hash of your IP address; we do not store the IP address itself with the enquiry.
Waitlist. Your email address, the product you asked to be notified about (for example Premium), and the time you signed up.
Usage and technical data. Server logs (IP address, browser type, pages requested, timestamps), card view counts, and product events such as "card claimed" or "banner uploaded". We use a session cookie to keep you signed in and do not use advertising cookies.
We do not ask for, and you should not put on your card, identity card numbers, bank details or other sensitive personal data as defined in the PDPA.
4. Why we use your data (purposes)
- To provide the Service: create and publish your card, sign you in, show your card to visitors, generate QR codes and vCards.
- To run your network: deliver connection requests, show connected members each other's connections-only details, and deliver messages between connections.
- To deliver enquiries: pass a message sent through a card's Contact me form to the card owner, keep it in the owner's Enquiries inbox, and confirm to the sender that it was sent.
- To send service emails: sign-in links, connection requests and acceptances, enquiries and their confirmations, new-message and activity notifications (which you can turn off), and important changes to the Service or this policy.
- To send onboarding tips and a monthly product update, only if you asked for them when you claimed your card (you can turn them off in Account or from any email).
- To send launch and product announcements to people who joined a waitlist (you can opt out at any time).
- To keep the Service secure: rate limiting, abuse and fraud prevention, debugging.
- To understand how the Service is used and improve it, using aggregated or pseudonymised data where possible.
- To comply with law and enforce our Terms.
The legal basis under the PDPA is your consent (given when you create an account, submit a request or join a waitlist), performance of our contract with you, and our legitimate interests in running a secure service.
5. Public information — please read
Your card is public by design. Anything you mark as public, and everything on your card other than contact channels you set to "connections only" or "private", is visible to anyone with your link and may be indexed by search engines, copied, or saved to a visitor's phone. Do not put anything on your card that you would not hand to a stranger.
Connections. When you request to connect, the owner sees your name, picture, card (if you have one), email and your message. Once connected, each of you can see the other's channels marked "connections only". Either of you can remove the connection at any time; details stop showing immediately, but anything already saved to a phone cannot be recalled.
Save contact. When a visitor taps Save contact on your card, the contact saved to their phone holds your name, company, title, photo, the link to your card, and your headline and bio. It does not include your phone number, WhatsApp number or email address. Members you are connected with get those too (the channels you set to public or connections only).
Enquiries. When you send a message through a card's Contact me form, the card owner sees your name, email address and message so they can reply to you by email. We email you a confirmation that does not repeat your message. The owner's email address is not shown to you unless they reply.
Messages. Messages are private to the two people in the conversation. We do not read them, except that a member of our team may review a conversation that one of the participants has reported, and that review is logged.
6. Who we share data with
We do not sell personal data. We share it only with:
- Service providers who process data for us (data processors): Supabase (database, authentication and file storage, hosted in Singapore), Vercel (hosting, primary region Singapore), Resend (transactional email, servers in Japan), Google (sign-in, if you choose it) and Cloudflare (DNS, network security, and Turnstile, which checks that the Contact me form is being sent by a person). Each is bound by contract to protect your data.
- Other users, as described in section 5 (card visitors; your connections; the owner of a card you send an enquiry to).
- Authorities, where the law requires it or to protect the rights, property or safety of NemKad, our users or the public.
- A successor if NemKad is sold or merged, in which case this policy continues to apply until you are told otherwise.
7. International transfers
Our providers store and process data outside Malaysia (Singapore, Japan, the United States and other countries where they operate). By using the Service you consent to this transfer. We choose providers with recognised security certifications and contractual safeguards.
8. How long we keep data
- Account and card data: for as long as your account exists. When you delete your account, your card is taken down immediately and your data is deleted from our live systems within 30 days, and from backups within 90 days.
- Declined connection requests: 12 months after the decision, then deleted. Accepted connections: for as long as the connection exists. Removed connections: the record is kept for 90 days to prevent immediate re-requests, then deleted.
- Messages: while the connection exists; deleted 90 days after either side removes the connection or deletes their account. Reports: 12 months.
- Enquiries: until the card owner deletes them, or deletes their account. If you sent an enquiry and want it removed, write to us (section 10).
- Waitlist: until you unsubscribe or 12 months after the relevant product launches, whichever is earlier.
- Server logs and security data: up to 90 days.
- Records we must keep by law (for example, payment records once paid plans exist): for the period the law requires.
9. Security
Data is encrypted in transit (TLS) and at rest by our providers. Access to production data is limited to people who need it to run the Service. Contact details you mark "connections only" or "private" are enforced on the server, not only hidden in the browser. No system is perfectly secure; if we become aware of a breach affecting your personal data we will notify the Personal Data Protection Commissioner and, where required, you, within the timelines set by the PDPA.
10. Your rights
Under the PDPA you may: access the personal data we hold about you; ask us to correct it; withdraw your consent (which may mean we can no longer provide parts of the Service); ask us to stop using your data for marketing; and, from the date the relevant provisions of the PDPA come into force, request a copy of your data in a portable format.
Most of this you can do yourself: edit or delete anything on your card, change contact visibility, remove a connection, turn off message, activity or tips emails, or delete your account from the dashboard. You can also write to us at any time through the Contact page. For anything else, email helpline@nemkad.com. We respond within 21 days. We may charge the fee permitted under the PDPA for access requests and will ask you to verify your identity first.
If you are unhappy with our response you may complain to the Personal Data Protection Commissioner of Malaysia (pdp.gov.my).
11. Children
The Service is for people aged 18 and above. We do not knowingly collect data from anyone under 18. If you believe a minor has created a card, contact us and we will remove it.
12. Changes
We will post changes here and update the date above. For material changes we will email account holders before they take effect. Continued use after that date means you accept the updated policy.
13. Contact
NemKad Solutions (Malaysia)
No. 22-2, Jalan Prima Setapak 3, Taman Setapak, 53300 Kuala Lumpur, Malaysia
helpline@nemkad.com