Last updated: May 27, 2026
EVISITA is a digital business card platform. Data controller contact: evisita@espinita.com
Account data: Name, email, hashed password. Google profile data if you sign in with Google.
Business card data: Name, title, company, phone, bio, photos, social links, and custom fields you enter.
Payment data: Processed by Stripe. We store a Stripe customer ID and subscription status only. We never store card numbers.
Analytics: Anonymous visitor counts per card. IP addresses are stored as one-way SHA-256 hashes — they cannot be reversed.
Log data: Standard server logs for security, retained 30 days.
We do not use your data for advertising and we do not sell your personal data.
All processors are bound by data processing agreements. No data is shared with advertisers.
Data is retained while your account is active. When you delete your account, all personal data is removed within 30 days including cards, templates, payment history, and uploaded media.
Email evisita@espinita.com to exercise any right. We respond within 30 days.
We use only strictly necessary cookies: a session authentication cookie and an onboarding status cookie. No advertising or tracking cookies. See our Cookie Policy.
We use HTTPS/TLS, bcrypt password hashing, and access controls. No system is completely secure — please use a strong password.
EVISITA is not directed at children under 16. Contact us if you believe we have collected data from a child.
We may update this policy. We'll notify you by email for material changes.
Questions: evisita@espinita.com
EU/UK users may lodge a complaint with their local data protection authority.