Privacy policy
Effective October 9, 2026
In short
We collect what we need to run the service and nothing to sell. Visitors to cards are counted anonymously. Contacts captured on a card belong to the card owner’s workspace, and marketing permission is only ever recorded when someone explicitly gives it.
Who this policy covers
This policy explains how Furnace Card Studio (“Furnace”, “we”) handles personal data for three groups: customers who create an account and workspaces; contacts whose details customers store, for example someone who exchanged details on a card; and visitors who view a published card.
For contacts, the customer’s workspace decides why and how their data is used — the customer is the controller and we process that data on their behalf (see the data processing summary). For customer accounts and our own website, we are the controller.
What we collect
Customers
- Account details: name, email, password hash (never the password itself), time zone and preferences.
- Workspace content: cards, businesses, contacts, notes, messages, automations and settings you create.
- Billing details: plan, invoices and payment status. Card numbers are handled by our payment processor (Square), not stored by us.
- Security records: session information, a hashed IP address, and an audit log of sensitive actions in your workspace.
Visitors to cards
- Anonymous interaction events: views, taps, scans, clicks and downloads, with the card, link or device involved, a coarse device class, browser, operating system and country.
- No tracking cookies are set on cards. Unique visits are estimated with a hash of request details and a salt that rotates every day, so a visitor can’t be recognised across days.
- Known bots and crawlers are flagged and excluded from reports.
Contacts
- Only what a person chooses to share — for example in a contact-exchange form, when booking a meeting, or details a customer enters or imports themselves.
- Consent records: when someone ticks a marketing checkbox we store the exact wording, the time and the card it was on. Exchanging details, saving a contact or booking a meeting never counts as marketing consent.
How we use data
- To provide the service: publish cards, deliver form submissions, send the messages customers approve, run automations and show analytics.
- To keep it secure: prevent abuse and spam, rate-limit requests, investigate reported cards and keep audit logs.
- To support and bill customers, and to tell them about changes to the service.
We don’t sell personal data, and we don’t use contacts’ data for our own marketing.
AI features
When a customer uses AI features, only the data that request needs — from that workspace, limited to what the requesting person can see — is sent to our AI provider (Anthropic) to generate a response. Workspace administrators can turn AI features off. AI output is shown as an editable draft and isn’t sent or applied without a person approving it.
Sharing with service providers
We use providers to host the service, store files, send email and SMS, process payments and power AI features. They process data only on our instructions. Integrations a customer connects (for example a CRM) receive data because that customer chose to connect them.
Retention
Workspace content is kept while the workspace exists. Analytics history is kept for the period included in the workspace’s plan. When a workspace is deleted, its content is deleted from our live systems; backups expire on a rolling schedule.
Your rights
Depending on where you live, you may have rights to access, correct, delete or export your data, and to object to or restrict certain processing. Customers can do most of this in their account. If you are a contact or visitor, the quickest route is to contact the card owner; you can also send us a privacy request and we’ll help or pass it on.
Anyone can unsubscribe from marketing email using the link in every message; unsubscribes are honoured across the sender’s workspace.
Children
The service is for professional use and isn’t directed at children under 16.
Changes
We’ll update the effective date above when this policy changes, and notify customers by email of material changes.
Contact
Privacy questions and requests: use the contact form and choose “Privacy or data request”.