Privacy Policy

Last updated: September 10, 2026

This is one of the MyVisito legal documents. See all documents

MyVisito ("we", "us") is a digital business card service operated by EmodeFlow, LLC, a company registered in the United States. For the personal information described here, EmodeFlow, LLC is the data controller. This policy describes what information we collect when you use myvisito.com, the app, and published cards, how we use it, who we share it with, and the choices and rights you have.

We collect only what we need to run the service. We do not sell your personal information, and we do not use it for third-party advertising.

You are under no legal obligation to give us any information. Some details are needed to open an account and use the service (your name, email address, how you prefer to be addressed and your date of birth, for example), and without them we cannot provide it. What you give us stays with us and reaches only the service providers listed in this policy, for the purposes it describes.

Information we collect

  • Account information: your email address, name, and password (stored in hashed form), or your Google profile details when you sign in with Google.
  • Profile details: your line or lines of work, how you prefer to be addressed (the grammatical form in gendered languages) and your date of birth. The last two are asked when you open your account and are used to address you correctly and to tailor the service; your date of birth is also our age check: the service is open from 16, and selling through the shop, hosting events and purchases open at 18, so the seller record can take it from your profile once you confirm it. They are never shown on a card, never visible to visitors or other members, and you can change them in your profile at any time.
  • Card content: everything you choose to place on your cards, such as your name, role, contact details, photos, logo, services, prices, and links. When you publish a card, that content becomes publicly visible at its web address; with the default public search setting it may also be indexed by search engines, and you can switch the card to private (not indexed) at publish time or anytime in the editor. A published card is also listed by default in the MyVisitors community directory on our site (name, photo, role, and field only, never contact details), and you can remove it from the directory at any time in the card's settings.
  • Workspace details: your workspace name and the public web address (handle) you choose.
  • Usage and analytics: events on your own cards, such as views, contact saves, link taps, and shares, so we can show you how your card performs.
  • Copilot conversations: when you use the AI copilot, we store your chat with it, along with any images, PDFs, or links you attach, so the assistant works and you can return to a conversation. Flyer Studio: when you design a flyer with AI, the words you typed are sent to the image model (OpenAI) to draw the flyer, and your photo is sent only when you switch on "Compose my photo into the design"; neither is used to train those models.
  • Technical information: when you create an account, and again on each sign-in, we record your IP address, approximate location, and device and browser type, to protect your account and the service against abuse. Your recent sign-ins are shown to you in your account security settings, and if you mark a device as trusted we remember it so you are not asked for a second factor every time.
  • Visit counts on our public website: when you read a page on our marketing site or blog, we count the visit and how far the article was read, without a cookie and without any identifier on your device. Your address is turned into a code that changes every day and is never stored, so visits cannot be linked to you or to each other across days. We use these counts only to learn which pages help people.
  • Payment information: when you buy a plan, your payment is handled by Stripe. We receive billing details such as your name, email, country, and subscription status, but not your full card number.
  • Identity verification: if we place your account under review and the question is whether the account is really yours, we may ask you to verify your identity. The document and the selfie are collected and checked by Stripe Identity on Stripe's own page. We receive only the outcome of the check and store only that outcome with its date; we never receive or store the document, the photo, or your identity number. This is asked only where a specific risk was identified, never routinely.

Information from card visitors and leads

When you publish a card, people can view it, and some information is collected from those visitors.

Lead details: when a visitor leaves their details through a lead form on your card, those details (such as name, phone, email, and message) are collected for you, the card owner. For that lead information you are the data controller, and we process it on your behalf as your service provider. You are responsible for having a lawful basis to collect it and, where the law requires, for giving those visitors your own privacy notice.

Event guest lists: names, phone numbers, and emails a host adds to an event guest list are the host’s data. The host is the data controller for that list, and we process it on their behalf to deliver their invitations, confirmations, reminders, and updates. Guests can opt out of phone messages at any time through the link on the event page or by replying to a message, and we honor that opt-out across the whole service. When someone registers to an event through its public page, we also record the technical details of that registration (IP address, approximate location, network, device and browser type, and the page that led there) and show them to the host, so the host can spot abuse, impersonation or duplicate registrations. Hints derived from them are presented to the host as facts to check, never as a verdict about the guest. Since September 2026, email a host sends to guests carries the host’s own identification in its footer, the business name and postal address the host entered in their settings, and that identification is disclosed to every recipient of those emails. When a guest unsubscribes and chooses to tell us why, we keep that reason with the unsubscribe and show the host that the contact is blocked; the host cannot remove that block.

Replies to our messages: when someone replies to a WhatsApp or SMS message sent from our number, we record the reply, including its text, so that we can answer it, register an RSVP made from the message itself, honor an opt-out request, and keep our sending number safe from abuse. The text of a reply is deleted after 90 days; only the fact that a message arrived, over which channel, and what we did about it is kept beyond that.

Visitor analytics: when a published card is viewed, we record analytics events (such as a view, a QR scan, a saved contact, or a link tap) together with approximate location (country and city), device and browser type, and the referring website. We use this to give the card owner performance statistics and to protect the service. We do not use it to identify individual visitors or to serve advertising.

Card scanning: a card owner can scan a paper business card, and on some cards a visitor can choose to scan their own business card to hand over their details. In both cases the photo is processed by AI only to extract the contact details on it (such as name, phone, email, and social links) into the card owner's contacts. The card owner is the data controller for the scanned details, just like lead-form details, and we process them on the owner's behalf.

Contacts import: a card owner can import contacts from a file, such as a CSV or vCard export from another app. The imported details go only into that owner's own contacts; the owner is the data controller for them, is responsible for having the right to import them, and we process them on the owner's behalf.

Imported public reviews: a card owner can import their public Google reviews onto their card, including each reviewer's public name, profile photo, and review text. The imported reviews become part of the owner's card content, and the owner is responsible for displaying them.

The places directory

Our site includes a directory of places (venues such as clubs, bars, halls and restaurants) with a page for each. The details on a place's page (name, type, address, phone, website, social links, a map and a logo) come from publicly available sources, including OpenStreetMap and the place's own website, from details members entered when naming the place on their own shows or events, and from the place itself once it claims the page. Where a place is run by one person, some of these details (for example a contact phone) may be personal data. We process them on the basis of our legitimate interest in running a public directory of places where events happen, we show only business contact details that the place itself makes public, and we never add private details.

If you own or manage a place and want its details corrected, the page claimed, or the page removed, or if you object to your details appearing, write to contact@myvisito.com and we will act promptly.

Buyers and purchases (Earn)

Card owners on selling plans can offer products for sale from their cards ("Earn"). If you buy from a seller, the seller is the merchant and the data controller for your purchase; we process your details on the seller's behalf as their service provider.

For each order we collect and store for the seller: your name, email, phone if you provide it, your shipping address for physical products, your answer to any question the seller added at checkout, and the product, amount, and status of the order. We use these details to deliver your purchase (your order page and order email) and to show the seller their orders and buyers.

When your payment is collected through MyVisito's own payment rail (shown on the checkout page and on your card statement as MyVisito together with the seller's name), the payment itself is processed by Stripe on MyVisito's account. We receive the order details and the payment status; your full card number is handled by Stripe and never reaches our servers. Cancellation rights depend on the product type and applicable law, as explained in the Commerce Rules; requests are made from your order page.

On the seller-owned Stripe rail, Stripe processes the payment in the seller's connected account. Legacy orders may reference another provider or an external payment link that was available when the order was created. In every case, the full card number is handled by the payment provider and never reaches MyVisito's servers.

If the seller connected external tools (such as an email marketing service, a CRM, or a spreadsheet), we pass your order details to those tools on the seller's instructions. The seller may also issue you an invoice through an invoicing service they connected.

Order records are kept for the seller and for fraud prevention, dispute handling, and legal compliance. To exercise your privacy rights over purchase information, contact the seller directly, or write to contact@myvisito.com and we will route your request to them.

How we use your information

  • To create, host, and display your digital business cards (to perform our contract with you).
  • To generate and edit card content with AI when you ask the copilot to do so (to perform our contract with you).
  • To show analytics about cards, to keep the service secure, and to prevent fraud and abuse (our legitimate interest in running a safe, useful service).
  • To process payments and manage subscriptions (to perform our contract and meet legal and tax obligations).
  • To send you service emails such as verification codes and important account notices (to perform our contract), and, only with your consent where required, occasional product updates.
  • To respond when you contact support (our legitimate interest and, where relevant, our contract with you).
  • To comply with the law and enforce our terms (to meet a legal obligation and our legitimate interests).

Usage measurement inside your account

When you are signed in to your account area, we measure how the service is used: which screens are visited and how pages are used (clicks, scrolling, and movement between screens), including through an analytics and session-replay service that works for us. Text you type and media you upload are masked before anything is recorded. We use this information to operate, secure, and improve the service; it is part of providing the service under our Terms of Use, which you agree to when you create an account.

This in-account measurement is separate from measurement on our public website, which runs according to your cookie choice as described below and in our Cookie Policy.

AI processing

When you use the copilot, the text you provide and your card content, plus any images, PDFs, or links you attach, are sent to our AI provider only to produce the result you requested. This content is not used to train AI models.

We do not use the copilot to make decisions about you that produce legal or similarly significant effects without human involvement. Please do not paste other people’s sensitive personal information into the copilot unless you are permitted to.

Published content (cards and shop products) may be automatically scanned by AI to detect violations of our Terms of Use, such as illegal or harmful content. Flagged content is reviewed by a person before any final decision about your account.

Signing in with Google

If you choose to sign in with Google, we receive only your basic profile information: your name, email address, and profile picture. We use it solely to create and secure your account and to prefill your profile.

If you also connect Google Calendar (from Settings > Integrations, or by leaving the calendar box ticked when signing in), we ask for one narrow permission: to create a calendar named "MyVisito" in your account and to manage the entries we put in it (the events you publish, the meetings you confirm, the consultations people pay for, and their Google Meet links). We never read your other calendars or their events. We store the encrypted refresh token, the id of that calendar and the ids of the entries we created, and delete them when you disconnect.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not share, sell, or use Google user data for advertising, and we do not use it to train AI models. You can disconnect Google from your account at any time, and you can request deletion of this data by contacting us.

Pre-saves on music services

When an artist offers a pre-save for an upcoming release and you tap a music service (Apple Music, Deezer or TIDAL), you authorize that service directly, and it gives us a token for one purpose: adding that release to your library on release day. We store the token encrypted, use it only for that release, and delete it when you remove the pre-save (a link in the release-day message does that) or once the release is delivered and the retry window ends. We never read your listening history or change anything else in your library. A Spotify pre-save opens a page run by a partner or by the artist's distributor, under that page's own privacy terms.

Cookies

We use a small number of cookies and similar technologies to keep you signed in, remember preferences such as language, and measure usage. On our public website, measurement runs only with the relevant permission through the cookie banner; inside your signed-in account area, usage measurement is part of the service itself, as described above. For our own advertising on Facebook, Instagram and LinkedIn, the Meta Pixel, the LinkedIn Insight Tag and a server-side connection to those two networks run on our public website only with your permission through the cookie banner, and the identifiers we send (email, account id) are hashed first; without that permission nothing reaches them. If you arrive through a partner (affiliate) link, a temporary attribution cookie is set for up to 90 days so the referral can be credited. A card owner may configure Google Analytics or Facebook Pixel on their public card; those tools remain off until the visitor separately allows card-owner tracking. Our Cookie Policy explains every category and how to change your choice.

How we share information

We do not sell your personal information. We share it only with the categories of service providers below, which run the service under our instructions and data-processing agreements, and only with what each needs to perform its role:

  • Cloud infrastructure providers: hosting the service and running its database, authentication, and file storage.
  • AI providers: processing your copilot and import requests, only to produce the result you asked for; never to train their models.
  • Email delivery providers: sending transactional emails such as verification codes and account notices.
  • Usage measurement: analytics and session-replay services measuring our own service, with typed text and media masked; on the public website only according to your cookie choice, and inside your signed-in account area as part of the service.
  • Advertising measurement: Meta and LinkedIn, to measure our own campaigns, receiving hashed identifiers and signup (and, for Meta, first-purchase) events only when you allowed MyVisito analytics on our public website.
  • Fraud-prevention providers: turning an IP address into an approximate location, to protect against abuse.
  • Stripe: payment processing when you purchase a plan, and, if you sell through MyVisito, payments from your buyers through your own connected Stripe account. For sellers using payments through MyVisito (currently offered in Israel), buyer payments are processed on MyVisito's own Stripe account, with MyVisito acting as the seller's limited payment collection agent; card details are handled by Stripe and never reach our servers. Where we ask you to verify your identity, Stripe Identity performs the check on Stripe's page and returns only the result to us.
  • Google: sign-in, if you choose to use it, and Google Tag Manager measurement tags (on the public website according to your cookie choice, and inside your signed-in account area as part of the service).
  • Apple and Google Wallet: if you add a card to Apple Wallet or Google Wallet, the details shown on the pass (such as the name, role, photo, and card link) are sent to Apple or Google to create the pass on your device.
  • Zoom: if you connect your Zoom account, we create, update and delete meetings and webinars in it for the sessions you sell, confirm or host, sending Zoom the session title, time, duration and a short agenda line. We store your encrypted OAuth tokens, your Zoom user id and account email, and the ids and join links of the sessions we created; we never access recordings, chat, transcripts or participant data. Everything is deleted when you disconnect in MyVisito or remove MyVisito inside Zoom. Zoom's own privacy policy applies to your Zoom account.
  • Tools you connect yourself, such as a CRM, an email marketing service, a spreadsheet, an automation service, a payment provider, or an invoicing service: we send lead and order details to them at your direction, and their own terms and privacy policies apply to them.

Legal disclosures and business transfers

We may disclose information if required by law, to respond to lawful requests, to protect the rights, safety, and security of our users and the service, or in connection with a merger, acquisition, or sale of assets, in which case we will take reasonable steps to ensure your information stays protected.

Where your information is processed

We and our providers process information in the United States and in other countries. When we transfer personal information out of the European Economic Area, the United Kingdom, or Israel, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, so that your information keeps a comparable level of protection.

Data retention and deletion

We keep your information for as long as your account is active. You can delete a card at any time, and you can permanently delete your entire account yourself from your account settings (Login and security > Delete account) on the web or in the mobile app. Deletion is immediate: your cards go offline, your data is removed, and any active subscription is cancelled immediately with no further charges. You can also request deletion by writing to contact@myvisito.com.

Some information is kept longer where we must: billing and tax records are typically kept for around seven years, and limited information may remain to meet a legal obligation, resolve a dispute, or enforce our terms. After account deletion we retain a minimal record of the account (such as the account email, billing history, and usage records of paid features such as AI credits) for fraud prevention, dispute handling, accurate billing, and legal compliance. Uploaded images may remain in storage for a period even after the card that used them is deleted, and copies may persist in routine backups for a limited time. Lead details you collect are kept until you delete them.

Your privacy rights

Depending on where you live, you have rights over your personal information. We honor these rights for everyone where we can.

If you are in the EU/EEA or the UK, you have the right to access, correct, delete, or receive a copy of your personal information, to restrict or object to certain processing, and to withdraw consent at any time. You also have the right to complain to your local data protection authority.

If you are in California or another US state with privacy rights, you have the right to know what personal information we collect, to access and delete it, and to correct it. We do not sell or "share" personal information for cross-context advertising, so there is nothing to opt out of, and we honor recognized opt-out signals such as Global Privacy Control. We will not discriminate against you for exercising your rights, and you may use an authorized agent.

If you are in Israel, you have the right to review and correct information we hold about you under the Protection of Privacy Law.

To exercise any right, email contact@myvisito.com from your account address. If you are a card visitor or a lead, the card owner is responsible for your information; you can contact them directly, or contact us and we will route your request to them.

Security

We protect information using measures that include encryption in transit, encryption at rest through our infrastructure providers, database-level access policies and user roles, one-way password hashing through our authentication provider, and restricted access to production systems. Card payments are handled by Stripe, and MyVisito does not store your full card number. MyVisito also completes an annual PCI DSS assessment (SAQ A) that Stripe validates. No method of storage or transmission is completely secure, but we work to protect information and improve our safeguards.

Data breaches

If a data breach affects your personal information, we will notify you and the relevant authorities where the law requires, and take reasonable steps to limit the impact.

Children

MyVisito is open from age 16. Between 16 and 18 the service is the card only; selling, hosting events and purchases open at 18, and the date of birth given at signup is how we check this. The service is not directed at anyone under 16, we do not knowingly collect information about children under 16, and an account we learn belongs to someone under 16 may be closed. If you believe a child under 16 has given us personal information, contact us and we will delete it.

Changes and contact

If we make material changes to this policy we will take reasonable steps to let you know. For any question or request about your privacy, or to reach EmodeFlow, LLC as the data controller, write to contact@myvisito.com, or by mail: EmodeFlow, LLC, 1111b South Governors Avenue, Suite 93153, Dover, DE 19904, United States.

We use essential storage to run MyVisito. Optional analytics, including tools a card owner configured, run only with your permission. Cookie policy