Skip to content

Slick.cards policies

Privacy Policy

How the application handles account, card, workspace and visitor information.

Launch legal document | Draft pending production publication

Owner-approved launch terms. Effective date will be the actual approved production launch date; these documents are not yet effective. Attorney review has not been claimed.

Operator: onthemon.io LLC.

About this policy

This launch Privacy Policy describes Slick.cards and its initial US-focused launch. Operator information and launch status appear above. For privacy, access or deletion requests, contact privacy@slick.cards.

Information you provide

Account information includes your email address, profile name and authentication information. You may provide a workspace name, team invitations and member roles. Supabase Auth handles account authentication, email confirmation and password-reset flows.

Digital-card content can include names, roles, companies, biography, contact details, links, images and other blocks you choose to add. Relationship tools can also collect visitor-provided contact details, meeting context, notes and follow-up information. Review the sharing choices in those tools before sending information.

Public cards and uploaded files

Publishing makes a saved snapshot of card content publicly accessible. People may copy, download or share it, and search engines or other services may retain copies. Save Contact downloads a VCF only when the visitor chooses that action; it does not automatically add a contact.

Uploaded card images use public Supabase storage URLs, including assets uploaded while editing a draft. Unpublishing a card, archiving it or removing an image from the editor should not be treated as deleting every uploaded file or outside copy. Do not upload confidential material.

Workspaces and relationships

Workspace roles and card assignments control available management actions. Workspace owners and administrators can access workspace information needed for those functions. Relationship and sharing links may grant access to information associated with that link; share them only with intended recipients. Do not assume that a shared link expires or that archiving a card deletes related information.

Billing information

Stripe hosts payment checkout and subscription-management pages. Slick.cards stores billing identifiers and subscription metadata, including the workspace plan, interval, status, customer and subscription identifiers, and relevant invoice or payment references. The application does not provide its own card-number entry form. Stripe processes information entered into its hosted payment flows under its own terms and privacy information.

Referrals and affiliate information

The referral system records referral codes, attribution, registrations, qualifying invoice activity, credits, affiliate applications, account-specific rates, commission status and payout records. Affiliate accounts can provide a PayPal email address. Payout records include payment references and dates. The operator makes PayPal payments separately; this application does not automatically transfer funds.

Referral abuse controls may use salted hashes of request IP and user-agent information when the configured hashing salt is available, as well as referral and commission status. This does not mean all hosting request logs are anonymized.

Visitor analytics and device information

Public card views and link clicks can record a random visitor-session identifier, the card or block involved, a reduced device category and referral information. General analytics reduces a valid referrer to its hostname. QR resolution separately receives the referring-page header and a QR session identifier; it should not be described as always storing only a hostname.

Hosting and service providers may process network and request logs, including IP addresses and device or browser information, to deliver and protect their services. See the Cookie Policy for application cookies and browser storage.

How information is used

We use information to provide Slick.cards, administer accounts, publish and share cards, manage team permissions and relationship tools, process billing and referral attribution, administer commissions, understand visitor activity, protect security, prevent fraud, troubleshoot the service, meet legal obligations and resolve disputes.

Service providers and other recipients

Supabase supplies database, authentication and file storage. Stripe supplies hosted billing and payment processing. Vercel hosts the deployed application. These providers process information for their respective services under the applicable arrangements.

Cards may contain user-selected external links or embeds, including YouTube, Vimeo, Spotify, Calendly and Google Maps. Those services may receive connection information and use their own cookies when content loads or links are followed. An embed provider is not necessarily a contracted Slick.cards service provider. PayPal receives information when the operator performs an affiliate payment separately.

Information is made available to people you share it with and workspace users according to their access. We may disclose information as reasonably necessary to comply with legal obligations, protect users and the service, prevent fraud or resolve disputes. This policy does not promise that no data is shared or sold under every legal definition.

Choices, access and deletion

You can edit account and card details through available settings, control publishing, and manage browser storage. Account settings support email and password changes. For privacy, access or data-deletion requests, email privacy@slick.cards. We may need to verify your identity and authority before acting on a request.

Account cancellation, card archiving and data deletion are separate concepts. Cancellation or archiving does not automatically erase an account, uploaded files or all related records. We handle requests subject to applicable legal obligations and the retention purposes below. Do not assume that every backup or externally copied public asset disappears immediately.

Retention

We retain information only as reasonably necessary to provide Slick.cards, administer accounts, protect security, prevent fraud, meet accounting and legal obligations, resolve disputes and maintain backups. The period varies with the information, its purpose and applicable requirements; there is no fixed universal deletion schedule.

Retention can include account, card, relationship, billing, analytics and referral records, logs, uploaded files and backups. Deletion from active systems does not promise immediate removal from every backup. External recipients may retain public content and downloaded copies independently. Cookie lifetimes do not establish database retention periods.

Security

The application uses authenticated sessions and role-based access checks, with database row-level policies for relevant records. Public content is intentionally public. No service can promise absolute security. Report suspected abuse or security issues to abuse@slick.cards, and privacy concerns to privacy@slick.cards. No certification, security standard or fixed response time is promised.

Children and international users

Slick.cards is intended for people aged 18 or older and is initially focused on the United States. It is not intended for children. Contact privacy@slick.cards if you believe a child has provided personal information. Use of service providers may involve processing outside your state or country. We will reevaluate market-specific privacy and consent requirements before intentionally targeting additional jurisdictions.

Changes and contact

We may update this policy as the service or its practices change. The approved effective date will be set at production launch, and updated versions will identify their effective date. Any additional notice required by applicable law will be provided.

Privacy and deletion requests: privacy@slick.cards. General support: support@slick.cards. Legal matters: legal@slick.cards. Abuse reports: abuse@slick.cards.