Legal · Last updated July 29, 2026
Privacy Policy
This policy explains what data hunybadgr, operated by Civic Dialog (“hunybadgr”, “we”, “us”), collects when you use our websites, mobile applications, and services (the “Service”), why we collect it, who we share it with, and how to get it corrected or deleted. The short version: we collect what the product needs to work, we sell none of it, and we show no ads.
Two kinds of people, two roles
hunybadgr handles data about two different groups, and our role differs for each. For you and your team — the people with hunybadgr accounts — we decide how account data is handled, and this policy describes that directly.
For the people you scan — the contacts whose badges and business cards your team captures at events — your company decides why that data is collected and what happens to it; we process it on your company’s behalf and on its instructions. Your company is responsible for having a lawful basis to capture and use that information, as described in our Terms of Service.
Data you give us
Account data. Name, email address, and sign-in credentials, managed by our authentication provider Clerk. If you sign in with Google or another identity provider, we receive your name and email from them.
Workspace data. Your company name, team membership and roles, the events you create, and settings such as which CRM you connect.
Billing data. Payments are handled by Stripe. We store your subscription status and seat count; your card number never touches our servers.
CRM credentials. When you connect a CRM, we store the access tokens or API keys needed to sync leads, encrypted with AES-256-GCM. We access your CRM only to push and check the leads you sync.
Data captured about your leads
The point of the product: when your team scans a badge, business card, or QR code, we capture the photo and extract contact details from it — typically name, job title, company, email address, and phone number. Voice memos your team records about a lead are stored and transcribed into text notes. Enrichment may add publicly available professional details, such as company size or industry.
Lead data belongs to the workspace that captured it. We use it only to provide the Service to that workspace — we never sell it, share it across customers, use it for advertising, or use it to train AI models.
Photos and voice recordings
Captured photos and voice recordings are stored privately in cloud storage (Cloudflare) and are accessible only through short-lived, signed links issued to authenticated members of your workspace. Photos are sent to OpenAI to read the text off them; recordings are sent to OpenAI to be transcribed. OpenAI processes this data under API terms that prohibit using it to train their models.
Data collected automatically
Usage analytics. We use Vercel Analytics, which is cookieless and does not track you across sites, to understand aggregate product usage (for example, how many visitors start a trial).
Error reports. When something crashes, Sentry collects the technical error details so we can fix it.
Cookies. We use only the cookies required to keep you signed in (set by Clerk). There are no advertising or cross-site tracking cookies.
Mobile app permissions and on-device data
The mobile app asks for permissions only when a feature needs them: camera to scan badges and cards, microphone to record voice memos, and photo library to import an existing photo of a card. You can decline any of these and use the rest of the app.
When you scan without an internet connection, captures are held in storage on your device and uploaded automatically when you reconnect. Signing out clears your session from the device.
How we use data
We use the data described above to:
- provide, maintain, and improve the Service;
- process scans: extract text, enrich contacts, transcribe memos;
- sync leads to the CRM your workspace connects;
- bill subscriptions and prevent abuse of free trials;
- send transactional email such as invites and receipts;
- respond to support requests and legal obligations.
We do not sell personal data, share it with data brokers, use it for third-party advertising, or use your content to train AI models.
Who we share data with
We share data with the service providers below, each only for the purpose listed, under agreements that restrict their use of it:
Beyond these: leads are sent to the CRM your workspace chooses to connect (Salesforce, HubSpot, Pipedrive, Close, Freshsales, or servis.ai) — that transfer is under your control and governed by your CRM provider’s terms. We may also disclose data if required by law, or as part of a merger or acquisition, in which case this policy continues to apply to it.
Security
All traffic is encrypted in transit (TLS). CRM tokens and API keys are encrypted at rest with AES-256-GCM. Photos and recordings are never publicly accessible; they are reachable only through short-lived signed links. Access to production systems is limited to those who operate the Service. No system is perfectly secure, but if we learn of a breach affecting your data we will notify you without undue delay.
Retention and deletion
We keep your data while your workspace is active. Deleted leads and events are first soft-deleted (recoverable, in case of mistakes) and then purged. When a workspace is deleted or you ask us to erase data, we delete it from production systems promptly and from backups on their rotation schedule.
To request deletion or a full export of your workspace’s data, email us at the address below — we honor these requests whether or not a privacy law in your jurisdiction requires it.
Your rights
Depending on where you live (for example under GDPR in Europe or CCPA in California), you may have rights to access, correct, export, delete, or restrict processing of your personal data. Email us and we will act on your request; we do not discriminate against you for exercising these rights. We do not sell personal data as defined by the CCPA.
If someone scanned your badge or card: the company that scanned you controls that record. You can contact them directly, or email us and we will identify the workspace and pass your request on, or delete the record where the law requires us to.
Children
The Service is for business use and not directed at children. We do not knowingly collect data from anyone under 16; if you believe we have, email us and we will delete it.
International transfers
We are based in the United States and our subprocessors store data primarily in the US. If you use the Service from elsewhere, your data is transferred to and processed in the US under this policy.
Changes to this policy
When we make material changes we will update the date at the top and, for significant changes, notify workspace admins by email. Continued use of the Service after a change means you accept the updated policy.
Contact
Questions, requests, or complaints: hi@hunybadgr.com. You can also lodge a complaint with your local data protection authority.
This document is provided for transparency and does not replace legal advice.