← Back to XDigitalApps
Privacy Policy
Last updated: June 25, 2026
This Privacy Policy explains how XDigitalApps ("we," "us," or "our") collects, uses, and
protects information when you use the XDigitalApps mobile application and related website and
services (collectively, the "Service"). By using the Service, you agree to the practices
described here.
1. Who we are
The Service is provided by SAHAJ Consultants Inc,
located at 2655 Alpine Terrace, Cumming, GA 30041, USA. For privacy questions, contact us at Privacy Support.
2. Information we collect
We collect only the information needed to provide the Service:
- Account and authentication information. You sign in using your mobile
phone number, which we verify with a one-time passcode (OTP). We collect your phone number
as your account identifier and process the OTP to authenticate you. Authentication is handled
using Amazon Cognito.
- Contact and card information you create. Information you enter to build
your digital cards and store contacts — such as names, email addresses, phone numbers,
company, job title, website, social links, and notes.
- Access to your device contacts. With your permission, the app accesses
the contacts stored on your device so it can display them alongside cards you have scanned in
a unified contacts view. Your device contacts are used to provide this in-app functionality.
We request your permission before accessing them, and you can use the app with limited or no
contacts access.
- Business cards you scan. You may scan another person's paper business card
using your device camera or a photo from your library. The image is processed by our
optical-character-recognition (OCR) service (hosted on Amazon Web Services) to extract details
such as the name, title, phone, email, company, and website on the card, which you can then
save to your device contacts. By scanning a card, you confirm you have a legitimate basis to
process that person's contact details.
- Camera and photo access. With your permission, the app uses your camera
and photo library so you can add a profile picture, attach files, and scan business cards.
- Attachments you upload. Files you choose to attach to your cards (for
example, brochures, resumes, portfolios, certificates, business licenses, or images), up to
five per card. The Service is not intended for, and does not support the storage of,
government-issued identification documents such as passports, driver's licenses, or insurance
cards, or other highly sensitive personal documents. Please do not upload such
documents.
- Shared card and link data. When you generate a shareable card link, we
store the card content and generate short links so recipients can view your card.
- Usage, analytics, and diagnostic information. We use Firebase Analytics to
understand how the app is used and New Relic to monitor performance and reliability. This may
include technical information such as app interactions and events, request timing, app
version, device type, and error logs, used to keep the Service stable, secure, and improving.
- Push notification token. If you enable push notifications, we use Firebase
Cloud Messaging, which involves a device push token used to deliver notifications to you.
3. How we use information
We use the information we collect to:
- Provide, operate, and maintain the Service;
- Create and display your digital cards and shareable links;
- Let you store and manage your own contacts, including displaying your device contacts
within the app and saving scanned cards to your device;
- Process business-card images you scan to extract contact details;
- Send you push notifications you have enabled;
- Understand usage and improve the app;
- Respond to your support requests;
- Keep the Service secure and diagnose technical problems;
- Comply with legal obligations.
We do not sell your personal information. We do not use the
content of your attachments to train artificial-intelligence models, and we do not send your
attachments to third-party AI services.
4. How information is stored and protected
Your data is stored using Google Cloud Platform, where our backend services and file storage
are hosted. Authentication is handled using Amazon Cognito, and business-card scanning is
processed using Amazon Web Services (AWS Lambda). Uploaded documents are served through
time-limited signed URLs. Data is encrypted in transit using HTTPS/TLS, and stored data is
encrypted at rest by our cloud providers. We restrict access to personal data to what is
necessary to operate the Service. No method of transmission or storage is completely secure, and
we cannot guarantee absolute security.
5. Sharing of information
We share information only as follows:
- When you choose to share. Card information you publish via a share link is
visible to anyone who has the link.
- Service providers. We use trusted third parties to host and operate the
Service: Google Cloud Platform (hosting and storage), Amazon Web Services — including Amazon
Cognito (authentication) and AWS Lambda (business-card OCR processing), Firebase Analytics
(usage analytics), Firebase Cloud Messaging (push notifications), and New Relic (performance
monitoring). They process data only on our behalf and under appropriate safeguards.
- Legal reasons. We may disclose information if required by law or to
protect the rights, safety, or property of users or the public.
6. Your choices and rights
You can:
- Access and update your card and contact information within the app;
- Delete individual cards, contacts, or attachments;
- Delete your account and all associated data from within the app. To request deletion, use Settings > Delete Account, or email us at the address above.
Depending on where you live, you may have additional rights under laws such as the GDPR or
CCPA, including the right to access, correct, or delete your personal data. To exercise these
rights, contact us at the email above.
7. Data retention
We keep your information for as long as your account is active or as needed to provide the
Service. When you delete your account or content, we delete the associated data within 30 days, except where we must retain it to comply with legal
obligations.
8. Children's privacy
The Service is not directed to children under 13 (or the minimum age required in your
jurisdiction), and we do not knowingly collect personal information from them. If you believe a
child has provided us information, contact us and we will delete it.
9. International users
The Service is operated from the United States. If you use it from outside the U.S., you
understand your information will be processed in the U.S.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version here
with a new "Last updated" date. Continued use of the Service after changes means you accept the
updated policy.
11. Contact us
Questions? Email Customer Support.
© 2026 XDigitalApps. All rights reserved.