1. Who we are
Navidad Infotech Pvt. Ltd. operates Pulsar Cards. Contact contact@pulsar.cards. Hardware is quoted by the same operator — there is no public shop.
When you store notes about people you met, you are the controller of that book. Pulsar hosts it on your instructions.
2. Scope
This notice covers pulsar.cards, the Pulsar mobile app, public profiles, exchange, the contact book, team workspaces, privacy tickets, invoices we issue, and hardware enquiries we take by email. It does not cover WhatsApp, Zoom, Teams, or Meet.
3. What we collect
We collect only what the product needs to run the surfaces you use.
- Account identity: username, email, password hash, optional name fields, 18+ confirmation.
- Published card fields you choose: photo, role, phone, WhatsApp, address, services, links. Email, phone, WhatsApp, and address stay blank for visitors when Contact is off.
- Owner-scoped contacts, notes, encounters, follow-ups, and optional voice extracts you review before save.
- Organisation membership, brand-kit settings, and join or SSO records.
- Hashed API tokens, session identifiers, CSRF tokens, captcha challenges, and rate-limit rows.
- Aggregate analytics: views, saves, exchanges, inquiries. Card-open events store a channel and a daily-rotating IP hash — not a visitor dossier, city, or device trail.
- Optional NFC bindings you attach to a profile.
- Consent records and privacy-ticket metadata.
- Invoice records we issue. Not payment card numbers.
- On-device optional models and a local index stay on the device when you enable them. They are not file-encrypted. We do not send live user content to a cloud inference API.
4. How we use it
We use personal data to create and secure your account, host the public card you publish, run exchange and follow-up offers you start, keep your book, apply team brand rules, issue invoices, detect abuse, and respond to rights tickets. We do not sell personal data. We do not build a stranger-who-glanced dossier.
5. Operating view of legal bases
The following is our current operating view. It is not a signed lawful-basis register and not a GDPR or DPDP certificate. Counsel should confirm bases for a given deployment.
- Contract: creating and securing an account, hosting the card you asked us to publish, delivering quoted team work.
- Consent: optional public Contact fields, exchange, search indexing, optional voice extract, optional on-device models.
- Legitimate interests, balanced against your rights: security, rate limits, captcha, fraud and abuse, aggregate analytics that do not identify a visitor.
- Legal obligation: preserving records we must keep, and responding to a competent authority when the law requires it.
6. Who we share with
We do not sell lists. We use processors to host and send transactional mail. People you share a card with see what you published.
- DigitalOcean Droplet (operator-controlled) — Hosting — Apache, PHP, MySQL on loopback. Application database and uploaded files. Required for the product. Region is whatever the operator declared.
- Transactional mail (HTTPS API) — Mailgun or Brevo. Reset codes, invoice notices, and other transactional addresses. Used only when the active provider keys are set. SMTP is not used.
- Stripe or Razorpay — only if operations enables hosted checkout. They receive payment-instrument data on their hosted page. Pulsar never collects a card number.
- Google Analytics — only if operations sets ANALYTICS_GA_ID. IP anonymisation is on. See the cookie notice.
7. Analytics
Owner dashboards show aggregates. Identity-linked activity appears only when the other person exchanged, inquired, or tapped while signed in and the action is meant to notify you. We do not show “opened 19 times from this city on this phone.” Raw analytics events default to a 30-day retention (minimum 7, maximum 365).
8. Cookies
See the cookie notice. Strictly necessary cookies run the session. Measurement loads only if operations set a Google Analytics ID.
9. Retention
Account data stays until you close the account or we must keep a subset for law, dispute, or security. Nightly jobs expire analytics events, login attempts, used reset codes, revoked tokens, and old audit rows. A litigation hold is not implemented in product. Export and erase are available to the signed-in owner in Settings.
10. Your rights
Depending on where you live, you may ask for access, correction, erasure, restriction, portability, objection, withdrawal of consent, nomination, or a grievance. India DPDP and EU GDPR list those families. Use the privacy request (30-day clock) or Settings export and close.
Completing a ticket does not automatically export or erase. We will verify the requester before we act. We may refuse a request that the law allows us to refuse, and we will say why.
11. International transfers
Operations has recorded hosting as: Operator-declared DigitalOcean Droplet. Mailgun may process transactional addresses outside your country. We do not claim EU-US Data Privacy Framework participation unless operations turns that flag on in the Trust Center. Counsel must name the transfer mechanism that applies to a given customer. The DPA draft is not execution.
12. Children
Signup requires confirmation that you are 18 or older. Organisation-provisioned accounts are not age-gated in product. If you believe a child created an account, write to contact@pulsar.cards.
13. Automated decisions
Rate limits, captcha, and honeypots are automated abuse controls. They do not produce a legal or similarly significant decision about you as a person. No cloud model writes a relationship note.
14. Security
Passwords are hashed. Sessions are HttpOnly. Uploads are re-encoded. Transit is HTTPS. This is not a Type II audit report and not “bank-grade” advertising.
15. Grievance officer and DPO
A DPDP grievance officer has not been appointed in product settings. Use contact@pulsar.cards or the privacy request until operations records a named officer. We will not invent a name on this page.
A data protection officer has not been published in product settings.
16. Changes
We will post updates on this page and change the effective date. Material changes that need a new consent will be asked at the point of use.
17. Contact
Navidad Infotech Pvt. Ltd.. contact@pulsar.cards. Privacy request. Terms of Use.