Back to Home

Data Protection Policy

Last updated: 22 March 2026

Business Privacy Terms Refund Data Protection Contact

Our Commitment

BestDigitalCard is committed to protecting your personal data in compliance with applicable Indian data protection laws, including the Digital Personal Data Protection Act, 2023 (DPDP Act) and Information Technology Act, 2000.

Security Measures

We implement the following technical and organizational measures:

MeasureDetails
Password EncryptionAll passwords are hashed using bcrypt (one-way, irreversible)
Session SecurityHTTP-only cookies, SameSite=Lax, secure flag on HTTPS, 2-hour expiry
CSRF ProtectionToken-based cross-site request forgery prevention on all forms
Input SanitizationAll user input is sanitized to prevent SQL injection and XSS attacks
File Upload SecurityExtension whitelist, MIME validation, magic byte verification, double-extension blocking
Rate LimitingIP-based rate limiting on all public endpoints to prevent abuse
Payment SecurityNo card/bank data stored — handled entirely by PCI-DSS compliant Razorpay
IP AnonymizationVisitor IPs are stored as one-way SHA-256 hashes, not raw IPs
Data CleanupAnalytics logs automatically purged after 90 days

Data Storage & Location

Third-Party Services

ServicePurposeData Shared
RazorpayPayment processingName, email, payment amount
SMTP (Email)Transactional emailsRecipient email, name
Google Places APIReview card Place IDBusiness place ID only

We do not share data with advertising networks, social media platforms, or data analytics companies.

Data Deletion

When you delete a card, all associated data is permanently removed:

Account deletion removes all cards and personal data. This action is irreversible.

Data Breach Protocol

In the event of a data breach, we will:

BestDigitalCard © 2026. All rights reserved.