← Back

Privacy Policy

Last updated 22 September 2026

GWB Technologies Ltd ("we", "us", "our") operates Handbeam. This policy explains what personal data we collect, why, and what rights you have over it. We are the "data controller" for the purposes of UK data protection law.

1. Data we collect

Account holders (people who sign up)

  • Your email address and authentication data, handled by our infrastructure provider, Supabase; we never see or store your raw password.
  • Whatever profile fields you choose to fill in for each Card: name, job title, company, bio, phone number, email address, website/portfolio links, social links, profile photo, company logo, and your chosen accent color.
  • Which fields you've chosen to hide from public view.
  • Engagement on your own Card's (view counts, contact saves, and link taps) so you can see how it's performing. Your own visits to your Card don't count toward this.
  • Approximate location (country and city, derived from your IP address at the moment you sign up) so we can understand where our users are for product and marketing purposes. We don't store the IP address itself.

Visitors to a Card (people who view a published Card, no account needed)

  • We log anonymous interaction events against the Card they viewed: that it was viewed, and which link or button (if any) was tapped, so the Card's owner can see aggregate engagement. We don't collect a visitor's name, account, or any way to identify who made a specific visit.
  • Where a Card view came from — QR code, NFC tap, saved vCard, or (when the visitor's browser sends one) the referring site — so the owner can see which sharing method is working. We don't store a visitor's browsing history or any cross-site tracking identifier, just this one signal per view.
  • Approximate location (country and city, derived from the visitor's IP address by our hosting provider) for the same purpose. We don't store the IP address itself.
  • Standard technical data (like IP address and browser type) may be briefly processed by our hosting providers for security and performance, as with any website.

Visitors to handbeam.com (our marketing site)

  • We log anonymous page-view events for our homepage — that it was visited, whether the visitor went on to click through to sign up, where the visit came from (a referring site or sharing source, when the visitor's browser sends one), and approximate country/city — so we can understand how people find Handbeam. This is aggregate, cookie-free, and can't be tied back to an individual visitor.

2. Why we process it

  • To create and operate your account and Cards (performance of a contract with you).
  • To show you engagement on your own Card (contract, and our legitimate interest in providing a useful product).
  • To keep the Service secure and prevent abuse (legitimate interest).
  • To understand, in aggregate, how visitors find Handbeam and which sharing methods work, and where our users are based, so we can improve the product and focus our marketing (legitimate interest).
  • Fields you mark as visible are displayed on your published Card and included in the downloadable vCard because you've actively chosen to publish them, using the visibility controls in your dashboard (consent).

3. Who we share it with

We don't sell your data or share it with advertisers or data brokers. We use infrastructure providers to run the Service, who process data on our behalf under their own security commitments:

  • Supabase: database, authentication, and file storage.
  • Vercel: application hosting.
  • Resend: sends account and Card-related emails (using your email address).
  • Stripe: processes payments if you choose to use the optional tip link (using the payer's payment details).

These providers may process data outside the UK/EEA; where they do, they provide appropriate safeguards (such as Standard Contractual Clauses) for that transfer. We'll also disclose data if required by law, or to protect the rights, safety, or property of Handbeam, our users, or the public.

4. How long we keep it

We keep your account and Card data for as long as your account is active. If you delete a Card or your account, we remove it from active use; residual copies may persist briefly in backups before being purged. Anonymous visitor interaction events are kept in aggregate for as long as the Card they relate to exists.

5. Security

Access to your data is enforced at the database level (row-level security), so only you can read or modify your own Card data, and a Card is only publicly readable once you choose to publish it. Photos and logos are stored in access-controlled storage scoped to each Card.

No system is 100% secure, and we can't guarantee against every possible incident. If a breach affecting your personal data occurs, we'll notify affected users and the ICO as required by law.

6. Your rights

Under UK GDPR, you have the right to:

  • access the personal data we hold about you;
  • correct inaccurate data (you can edit most of this yourself in your dashboard);
  • delete your data ("right to be forgotten");
  • restrict or object to certain processing;
  • receive your data in a portable format; and
  • complain to the Information Commissioner's Office if you believe we've mishandled your data.

To exercise any of these, contact us using the details below. There's currently no self-serve account-deletion button. Email us and we'll action it.

7. Cookies

We use a strictly necessary cookie to keep you signed in. We don't use tracking or advertising cookies.

8. Children

The Service isn't intended for anyone under 16. We don't knowingly collect data from children.

9. Changes to this policy

We'll update the date above if this policy changes materially.

10. Contact

contact@handbeam.com
GWB Technologies Ltd (company number 17278675), 167-169 Great Portland Street, London, United Kingdom, W1W 5PF