1. Who operates the service
Tanuki Labs operates Tanuki Web and the Digital Business Card System (the "Service"). Privacy requests can be sent to privacy@tanukilabs.fun.
2. What the Service does
The Service provides a protected visual editor for creating and managing digital business cards and event tickets. Each published design can have its own public URL and QR code destination. A public page is intentionally focused on the individual card or ticket requested by its URL. An administrator may also create a single-use, card-specific link so a card owner can correct their own details without entering the administration area.
3. Information processed
- Card content: names, roles, company labels, photos or logos, descriptions, phone numbers, email addresses, websites, social links, QR destinations, colors, and layout information that a publisher chooses to enter.
- Event ticket content: event names, dates, venues, addresses, ticket types, attendee names, seat or gate details, ticket numbers, entry instructions, images, and QR destinations chosen by a publisher.
- Uploaded design assets: background images, photographs, logos, transparent borders, and other image layers uploaded into the visual editor.
- Editor access data: the protected backend uses an access code and a temporary session token. The access code is checked server-side and is not placed in public card data.
- Card-owner edit access: a single-use random link may be created for one business card. The Service stores a one-way hash of that invitation, records when it is used, and issues a temporary session limited to the selected card.
- Technical data: hosting and security providers may process IP address, browser, device, request, diagnostic, and security-log information when the Service is accessed.
- Messages: if someone contacts the operator by email, the contact details and message are processed to respond and keep a record of the request.
4. Why information is processed
Information is processed to provide and secure the Service, publish the card or ticket requested by a publisher, save and retrieve design content and uploaded assets, generate requested QR codes, troubleshoot failures, prevent abuse, respond to requests, and comply with legal obligations. Where optional processing requires consent, consent is requested and can be withdrawn.
5. Public card and ticket pages
When a publisher makes a card or ticket public, the selected content is available to anyone who has its URL. Public pages may be copied, shared, cached, or indexed by search engines. The Service does not disclose private backend datasets through public URLs, but a publisher remains responsible for the content and permissions associated with a design they publish.
6. Providers and disclosures
The Service may use the following providers to operate its features:
- Vercel: hosting, serverless runtime, deployment, security logs, and private Blob storage for live site data and uploaded design assets.
- QR code provider: when the QR action is used, the requested card URL and QR styling parameters are sent to the QR image service used by the application.
- Content delivery providers: the editor may load third-party libraries from jsDelivr and unpkg. Those providers can receive technical request data when the library is requested.
Providers process information under their own terms and privacy notices. Information may be processed in countries outside the user's country, subject to the safeguards required by applicable law.
7. Cookies and local storage
The application does not intentionally use advertising or profiling cookies. The protected editor stores its session token in browser local storage so the editor can remain unlocked on that device until logout, storage is cleared, or the session is rejected. A card-owner editor stores its temporary, card-specific session in session storage for the current browser tab. Hosting or security services may use strictly necessary technical cookies or similar mechanisms.
8. Retention
Published card and ticket content and uploaded assets are retained while the publisher keeps them active or until they are deleted. Signed editor sessions expire automatically. Unused card-owner invitations expire automatically, and used invitation records may be retained briefly for security and replay prevention. Support messages and technical logs are retained only as long as reasonably necessary for the stated purpose, security, dispute handling, and legal obligations, subject to provider retention settings.
9. Rights and requests
Subject to applicable law, people may request access, correction, deletion, restriction, portability, or objection to processing, and may withdraw consent where processing is based on consent. Send a request to privacy@tanukilabs.fun with enough information to identify the relevant card or request. The operator may need to verify identity before responding.
People in the European Economic Area may also complain to their local data protection authority. In Italy, the supervisory authority is the Garante per la protezione dei dati personali.
10. Security
The Service uses HTTPS, protected backend endpoints, access-code authentication, and private storage for live site data. No online service can guarantee absolute security. Do not place highly sensitive information in a public card.
11. Children
The Service is not directed to children. Do not publish a child's personal information without the permissions and safeguards required by applicable law.
12. Policy updates
This policy will be updated when the Service adds or changes data collection, storage, analytics, cookies, external providers, account features, card visibility, or new products such as tickets and events. The date at the top of this page records the latest substantive update.
This notice is written for the current implementation and is not a substitute for legal advice. The operator should confirm the legal entity name, address, applicable jurisdictions, retention settings, provider contracts, and privacy contact before launch or whenever the processing model changes.