Create your card
Privacy Notice

The meetings you chose to keep

Pulsar remembers the people and meetings you chose to keep. The formal notice below is what we process, not a certification.

Effective 12 September 2026 · Version 2026-09-12 · Navidad Infotech Pvt. Ltd.

These notices describe Pulsar Cards as Navidad Infotech Pvt. Ltd. operates it today. They are not a certification. Visiting a page does not execute a DPA or MSA. Hardware is optional and quoted by email — there is no public shop. A signed order or MSA issued by counsel prevails over these website terms for that customer to the extent of any conflict. Mandatory consumer rights are not excluded.

1. Who we are

Navidad Infotech Pvt. Ltd. operates Pulsar Cards. Contact contact@pulsar.cards. Hardware is quoted by the same operator — there is no public shop.

When you store notes about people you met, you are the controller of that book. Pulsar hosts it on your instructions.

2. Scope

This notice covers pulsar.cards, the Pulsar mobile app, public profiles, exchange, the contact book, team workspaces, privacy tickets, invoices we issue, and hardware enquiries we take by email. It does not cover WhatsApp, Zoom, Teams, or Meet.

3. What we collect

We collect only what the product needs to run the surfaces you use.

  • Account identity: username, email, password hash, optional name fields, 18+ confirmation.
  • Published card fields you choose: photo, role, phone, WhatsApp, address, services, links. Email, phone, WhatsApp, and address stay blank for visitors when Contact is off.
  • Owner-scoped contacts, notes, encounters, follow-ups, and optional voice extracts you review before save.
  • Organisation membership, brand-kit settings, and join or SSO records.
  • Hashed API tokens, session identifiers, CSRF tokens, captcha challenges, and rate-limit rows.
  • Aggregate analytics: views, saves, exchanges, inquiries. Card-open events store a channel and a daily-rotating IP hash — not a visitor dossier, city, or device trail.
  • Optional NFC bindings you attach to a profile.
  • Consent records and privacy-ticket metadata.
  • Invoice records we issue. Not payment card numbers.
  • On-device optional models and a local index stay on the device when you enable them. They are not file-encrypted. We do not send live user content to a cloud inference API.

4. How we use it

We use personal data to create and secure your account, host the public card you publish, run exchange and follow-up offers you start, keep your book, apply team brand rules, issue invoices, detect abuse, and respond to rights tickets. We do not sell personal data. We do not build a stranger-who-glanced dossier.

5. Operating view of legal bases

The following is our current operating view. It is not a signed lawful-basis register and not a GDPR or DPDP certificate. Counsel should confirm bases for a given deployment.

  • Contract: creating and securing an account, hosting the card you asked us to publish, delivering quoted team work.
  • Consent: optional public Contact fields, exchange, search indexing, optional voice extract, optional on-device models.
  • Legitimate interests, balanced against your rights: security, rate limits, captcha, fraud and abuse, aggregate analytics that do not identify a visitor.
  • Legal obligation: preserving records we must keep, and responding to a competent authority when the law requires it.

6. Who we share with

We do not sell lists. We use processors to host and send transactional mail. People you share a card with see what you published.

  • DigitalOcean Droplet (operator-controlled) — Hosting — Apache, PHP, MySQL on loopback. Application database and uploaded files. Required for the product. Region is whatever the operator declared.
  • Transactional mail (HTTPS API) — Mailgun or Brevo. Reset codes, invoice notices, and other transactional addresses. Used only when the active provider keys are set. SMTP is not used.
  • Stripe or Razorpay — only if operations enables hosted checkout. They receive payment-instrument data on their hosted page. Pulsar never collects a card number.
  • Google Analytics — only if operations sets ANALYTICS_GA_ID. IP anonymisation is on. See the cookie notice.

7. Analytics

Owner dashboards show aggregates. Identity-linked activity appears only when the other person exchanged, inquired, or tapped while signed in and the action is meant to notify you. We do not show “opened 19 times from this city on this phone.” Raw analytics events default to a 30-day retention (minimum 7, maximum 365).

8. Cookies

See the cookie notice. Strictly necessary cookies run the session. Measurement loads only if operations set a Google Analytics ID.

9. Retention

Account data stays until you close the account or we must keep a subset for law, dispute, or security. Nightly jobs expire analytics events, login attempts, used reset codes, revoked tokens, and old audit rows. A litigation hold is not implemented in product. Export and erase are available to the signed-in owner in Settings.

10. Your rights

Depending on where you live, you may ask for access, correction, erasure, restriction, portability, objection, withdrawal of consent, nomination, or a grievance. India DPDP and EU GDPR list those families. Use the privacy request (30-day clock) or Settings export and close.

Completing a ticket does not automatically export or erase. We will verify the requester before we act. We may refuse a request that the law allows us to refuse, and we will say why.

11. International transfers

Operations has recorded hosting as: Operator-declared DigitalOcean Droplet. Mailgun may process transactional addresses outside your country. We do not claim EU-US Data Privacy Framework participation unless operations turns that flag on in the Trust Center. Counsel must name the transfer mechanism that applies to a given customer. The DPA draft is not execution.

12. Children

Signup requires confirmation that you are 18 or older. Organisation-provisioned accounts are not age-gated in product. If you believe a child created an account, write to contact@pulsar.cards.

13. Automated decisions

Rate limits, captcha, and honeypots are automated abuse controls. They do not produce a legal or similarly significant decision about you as a person. No cloud model writes a relationship note.

14. Security

Passwords are hashed. Sessions are HttpOnly. Uploads are re-encoded. Transit is HTTPS. This is not a Type II audit report and not “bank-grade” advertising.

15. Grievance officer and DPO

A DPDP grievance officer has not been appointed in product settings. Use contact@pulsar.cards or the privacy request until operations records a named officer. We will not invent a name on this page.

A data protection officer has not been published in product settings.

16. Changes

We will post updates on this page and change the effective date. Material changes that need a new consent will be asked at the point of use.

Questions about these notices

Rights tickets take 30 days. Hardware questions go to contact@pulsar.cards.

Privacy Notice

The formal notice

Effective 12 September 2026 · Version 2026-09-12. This is the operator notice. It is not a certificate.

These notices describe Pulsar Cards as Navidad Infotech Pvt. Ltd. operates it today. They are not a certification. Visiting a page does not execute a DPA or MSA. Hardware is optional and quoted by email — there is no public shop. A signed order or MSA issued by counsel prevails over these website terms for that customer to the extent of any conflict. Mandatory consumer rights are not excluded.

1. Who we are

Navidad Infotech Pvt. Ltd. operates Pulsar Cards. Contact contact@pulsar.cards. Hardware is quoted by the same operator — there is no public shop.

When you store notes about people you met, you are the controller of that book. Pulsar hosts it on your instructions.

2. Scope

This notice covers pulsar.cards, the Pulsar mobile app, public profiles, exchange, the contact book, team workspaces, privacy tickets, invoices we issue, and hardware enquiries we take by email. It does not cover WhatsApp, Zoom, Teams, or Meet.

3. What we collect

We collect only what the product needs to run the surfaces you use.

  • Account identity: username, email, password hash, optional name fields, 18+ confirmation.
  • Published card fields you choose: photo, role, phone, WhatsApp, address, services, links. Email, phone, WhatsApp, and address stay blank for visitors when Contact is off.
  • Owner-scoped contacts, notes, encounters, follow-ups, and optional voice extracts you review before save.
  • Organisation membership, brand-kit settings, and join or SSO records.
  • Hashed API tokens, session identifiers, CSRF tokens, captcha challenges, and rate-limit rows.
  • Aggregate analytics: views, saves, exchanges, inquiries. Card-open events store a channel and a daily-rotating IP hash — not a visitor dossier, city, or device trail.
  • Optional NFC bindings you attach to a profile.
  • Consent records and privacy-ticket metadata.
  • Invoice records we issue. Not payment card numbers.
  • On-device optional models and a local index stay on the device when you enable them. They are not file-encrypted. We do not send live user content to a cloud inference API.

4. How we use it

We use personal data to create and secure your account, host the public card you publish, run exchange and follow-up offers you start, keep your book, apply team brand rules, issue invoices, detect abuse, and respond to rights tickets. We do not sell personal data. We do not build a stranger-who-glanced dossier.

5. Operating view of legal bases

The following is our current operating view. It is not a signed lawful-basis register and not a GDPR or DPDP certificate. Counsel should confirm bases for a given deployment.

  • Contract: creating and securing an account, hosting the card you asked us to publish, delivering quoted team work.
  • Consent: optional public Contact fields, exchange, search indexing, optional voice extract, optional on-device models.
  • Legitimate interests, balanced against your rights: security, rate limits, captcha, fraud and abuse, aggregate analytics that do not identify a visitor.
  • Legal obligation: preserving records we must keep, and responding to a competent authority when the law requires it.

6. Who we share with

We do not sell lists. We use processors to host and send transactional mail. People you share a card with see what you published.

  • DigitalOcean Droplet (operator-controlled) — Hosting — Apache, PHP, MySQL on loopback. Application database and uploaded files. Required for the product. Region is whatever the operator declared.
  • Transactional mail (HTTPS API) — Mailgun or Brevo. Reset codes, invoice notices, and other transactional addresses. Used only when the active provider keys are set. SMTP is not used.
  • Stripe or Razorpay — only if operations enables hosted checkout. They receive payment-instrument data on their hosted page. Pulsar never collects a card number.
  • Google Analytics — only if operations sets ANALYTICS_GA_ID. IP anonymisation is on. See the cookie notice.

7. Analytics

Owner dashboards show aggregates. Identity-linked activity appears only when the other person exchanged, inquired, or tapped while signed in and the action is meant to notify you. We do not show “opened 19 times from this city on this phone.” Raw analytics events default to a 30-day retention (minimum 7, maximum 365).

8. Cookies

See the cookie notice. Strictly necessary cookies run the session. Measurement loads only if operations set a Google Analytics ID.

9. Retention

Account data stays until you close the account or we must keep a subset for law, dispute, or security. Nightly jobs expire analytics events, login attempts, used reset codes, revoked tokens, and old audit rows. A litigation hold is not implemented in product. Export and erase are available to the signed-in owner in Settings.

10. Your rights

Depending on where you live, you may ask for access, correction, erasure, restriction, portability, objection, withdrawal of consent, nomination, or a grievance. India DPDP and EU GDPR list those families. Use the privacy request (30-day clock) or Settings export and close.

Completing a ticket does not automatically export or erase. We will verify the requester before we act. We may refuse a request that the law allows us to refuse, and we will say why.

11. International transfers

Operations has recorded hosting as: Operator-declared DigitalOcean Droplet. Mailgun may process transactional addresses outside your country. We do not claim EU-US Data Privacy Framework participation unless operations turns that flag on in the Trust Center. Counsel must name the transfer mechanism that applies to a given customer. The DPA draft is not execution.

12. Children

Signup requires confirmation that you are 18 or older. Organisation-provisioned accounts are not age-gated in product. If you believe a child created an account, write to contact@pulsar.cards.

13. Automated decisions

Rate limits, captcha, and honeypots are automated abuse controls. They do not produce a legal or similarly significant decision about you as a person. No cloud model writes a relationship note.

14. Security

Passwords are hashed. Sessions are HttpOnly. Uploads are re-encoded. Transit is HTTPS. This is not a Type II audit report and not “bank-grade” advertising.

15. Grievance officer and DPO

A DPDP grievance officer has not been appointed in product settings. Use contact@pulsar.cards or the privacy request until operations records a named officer. We will not invent a name on this page.

A data protection officer has not been published in product settings.

16. Changes

We will post updates on this page and change the effective date. Material changes that need a new consent will be asked at the point of use.