Vela

Digital Business Card

Privacy Policy

Last updated: 18 June 2026

This Privacy Policy explains how Vela ("we", "our", or "the app"), operated by Cheah Wai Kit, collects, uses, and protects your information when you use the Vela mobile application and the recipient web page at card.velacard.app.

By using Vela, you agree to the practices described in this policy. If you do not agree, please discontinue use of the app.

1. Information We Collect

We collect only the information you explicitly provide when creating your Vela profile:

We also collect the following account information:

2. Business Cards You Scan

Vela is built on a privacy-by-design principle. When you scan a third-party business card, the card image never leaves your device — text recognition (OCR) is performed entirely on your device. The text extracted from the card is then sent to our server and to Google Gemini solely to parse it into structured contact fields (see Section 5). We do not retain that text after parsing, and we do not store the finished contact record on our servers — the parsed contact is returned to your device and held in local storage (SQLite) only until you save it to your native contacts app or discard it.

To be clear about what this means:

We do not collect:

3. How We Use Your Information

Your profile information is used solely to:

We do not use your data for advertising, profiling, or any purpose beyond operating the Vela service.

4. How Your Card is Shared

Your Vela profile is accessible via a unique URL of the form card.velacard.app/view.html?id=YOUR_ID. This URL is encoded in your QR code. Anyone who scans your QR code or has your link can view the profile fields you have chosen to fill in. Only fields you have populated are shown — empty fields are not displayed.

Your account type, scan credits, and usage are never shown on your public card.

5. AI Card Scanning

When you scan a physical business card, your device's on-device text recognition (Google ML Kit OCR) first extracts the text from the card image. This step happens entirely on your device — the card image itself is never uploaded. That extracted text — not the card image — is then sent to our secure server-side function, which forwards it to Google Gemini (a large language model API) to parse it into structured contact fields. This text is used only to perform the parsing and is not retained by Vela after the parsed result is returned to your device.

Google's handling of data sent to the Gemini API is governed by Google's Privacy Policy. By using the card scanning feature, you acknowledge that text extracted from scanned cards is processed by Google Gemini for the purpose of structuring contact details.

6. Third-Party Services

Vela uses the following third-party services to operate:

7. Data Storage and Security

Your profile data is stored in Supabase's managed PostgreSQL database, hosted on AWS infrastructure. All data is transmitted over encrypted connections (TLS). Access to your profile is protected by Row-Level Security policies — only you can modify your own profile, and billing-related fields cannot be altered from the client. Your public card is served through a restricted database function that returns only your own card's public fields.

Your session credentials are stored in your device's secure storage (iOS Keychain / Android Keystore) and are never stored in plain text.

8. Data Retention

Your profile data is retained for as long as your account is active. Contact data from cards you scan is held only in local storage on your device and is removed when you save or discard the contact; it is never backed up to our servers.

Purchase records are retained for accounting and dispute-resolution purposes, even after account deletion, where required for legal or financial compliance.

9. Your Rights

You have the right to:

You can delete your account directly in the app at any time: open Settings → Delete Account. This permanently removes your profile, your card, and your account data. If you have an active Premium subscription, please cancel it separately through your app store — Apple on iOS, Google Play on Android — as deleting your Vela account does not cancel your subscription billing.

You may also email us at privacy@velacard.app to request access to, or deletion of, your data. We will respond within 30 days.

10. Additional Information for EEA, UK & Swiss Residents (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the following additional information applies to you under the General Data Protection Regulation (GDPR) and equivalent UK and Swiss law. Where this section conflicts with anything above, this section governs for residents of those regions.

10.1 Data Controller and EU Representative

The data controller for your personal data is Cheah Wai Kit, operating as Vela (contact: privacy@velacard.app). Vela is not currently offered to users in the EEA, the United Kingdom, or Switzerland. If and when Vela becomes available in those regions, we will appoint a representative as required under Article 27 GDPR and publish their contact details here. Until then, you may contact us directly at privacy@velacard.app regarding the processing of your personal data.

10.2 Legal Bases for Processing

We process your personal data on the following legal bases:

10.3 Your GDPR Rights

In addition to the rights listed in Section 9, you have the right to:

To exercise any of these rights, email privacy@velacard.app. We will respond within one month, as required by GDPR.

10.4 International Data Transfers

Vela operates from Singapore, and some of our service providers are located outside the EEA, including in the United States. In particular, text extracted from scanned cards is processed by Google Gemini, and your account data is hosted on Supabase (AWS) infrastructure.

Where personal data is transferred to the United States, we rely on the EU-U.S. Data Privacy Framework (DPF) and its UK and Swiss extensions, under which Google is certified, and/or on the European Commission's Standard Contractual Clauses (SCCs) as a safeguard. Transfers to Singapore and other locations are made under appropriate safeguards or applicable adequacy decisions. You may request more information about these safeguards by contacting us.

10.5 Contact Data From Scanned Cards

When you scan a business card, you are acting as the controller of the resulting contact data — it is your contact, saved for your own use, much like typing it into your phone's address book. Vela acts as a processor that performs the parsing on your behalf, and (as described in Section 2) does not retain the extracted text or store the finished contact on our servers.

If you are a business user scanning cards for professional purposes, you are responsible for ensuring you have a lawful basis to process the contact details of the individuals whose cards you scan, and for honouring their data-protection rights. If an individual whose card was scanned wishes to exercise their rights, they should contact the Vela user who scanned their card; you may also contact us at privacy@velacard.app and we will assist where we are able.

10.6 Automated Processing

The AI parsing described in Section 5 structures text into contact fields. It does not make any decision that produces legal or similarly significant effects about any individual, and you review and confirm every parsed contact before it is saved. We do not carry out automated decision-making within the meaning of Article 22 GDPR.

11. Children's Privacy

Vela is intended for working professionals and is not directed at children. We do not knowingly collect personal information from children under the age of 13. If you believe a child has provided us with personal information, please contact us at privacy@velacard.app and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of Vela after changes are posted constitutes acceptance of the updated policy.

13. Governing Law

This Privacy Policy is governed by the laws of Singapore, including the Personal Data Protection Act 2012 (PDPA). For residents of the EEA, the UK, or Switzerland, nothing in this section limits the mandatory data-protection rights you have under GDPR or equivalent local law, including the right to bring a claim before the courts or supervisory authority of your country of residence.

14. Contact

If you have any questions or concerns about this Privacy Policy, please contact us at:

Cheah Wai Kit
Operating as: Vela
Privacy enquiries: privacy@velacard.app
Support: support@velacard.app