Contexion
  • Product
  • Solutions
  • Pricing
  • About
  • Contact
  • Sign In
Sign In
Privacy & Data Protection
Last updated · July 28, 2026

Privacy Policy

How Contexion collects, uses, and protects information about you, the people you share your card with, and the workspaces you connect.

On this page
  1. Introduction
  2. Who we are & our role
  3. Information we collect
  4. Authentication & account security
  5. How we use information
  6. Legal bases (EEA & UK)
  7. How we share information
  8. Third-party integrations
  9. Cookies & analytics
  10. AI features & automated decisions
  11. Card recipients
  12. Mobile apps & device permissions
  13. Data retention
  14. How we protect your data
  15. Your rights
  16. US state privacy rights
  17. International transfers
  18. Children's privacy
  19. Changes
  20. Contact us

Introduction

Contexion™ ("Contexion," "we," "us") operates Contexion.ai — a digital business card and intelligent contact-sharing platform that helps professionals capture, enrich, and follow up on every connection. This Privacy Policy explains what we collect, why we collect it, who we share it with, and the rights you have over your data.

What this Policy covers

This Policy applies to every part of Contexion, on every device — collectively, the "Service":

  • contexion.ai — our public marketing website.
  • app.contexion.ai — the Contexion web application, where you sign in, build and manage your cards, and work with your leads.
  • The Contexion mobile apps for iOS and Android, however you obtained them (Apple App Store, Google Play, or a managed enterprise distribution).
  • Contexion digital cards — the card pages you publish and share, including when a recipient opens one without having an account.
  • Our APIs, integrations, email notifications, and support channels.

You get the same privacy protections on every one of these surfaces. Your data is held in one account regardless of where you signed in, so a right you exercise — access, correction, export, deletion — applies across the web app, the mobile apps, and your published cards together, not to one of them in isolation. Where a practice is specific to one surface, we say so: see Mobile apps and device permissions for what the iOS and Android apps do differently, and Cookies and analytics for the difference between the marketing site and the signed-in app.

By using the Service, you agree to the practices described here.

In short: you sign in with your email address and a one-time code — we never ask you to create a password and we never store one. We do not sell your personal information. We do not use your cards, leads, or messages to train third-party AI models. You can access, export, correct, or delete your data at any time.

Who we are and our role in your data

The Service is operated by Veloxs AI Inc., a company incorporated in the United States, with a mailing address at 1209 170th St SW, Unit B, Lynwood, WA 98037, USA. Veloxs AI Inc. is the entity responsible for the personal information described in this Policy.

  • We are the controller (a "business" under US state privacy laws) for your account information, billing data, authentication records, support communications, and website usage data.
  • We are a processor (a "service provider") for the lead and contact records that you capture through your Contexion card. For that data, you are the controller: you decide what to collect and why, and we process it only on your instructions. If you want a lead record about you corrected or deleted, the Contexion user who captured it is the first point of contact — but you can also write to us and we will route the request.

Business customers subject to GDPR, UK GDPR, or CCPA/CPRA can request our Data Processing Agreement, including Standard Contractual Clauses and our current subprocessor list, at info@contexion.ai.

For privacy questions, including requests from data protection authorities, contact our privacy team at info@contexion.ai.

Information we collect

Information you give us

  • Account data: your email address (required — it is both your identifier and how you sign in), and optionally your name, profile photo, role, company, location, and time zone. We do not collect or store a password — see Authentication and account security.
  • Card content: the contact details, links, social handles, and rich media you choose to publish on your Contexion card.
  • Billing data: billing address, tax ID, and the last four digits of your payment method (full card details are handled by our payment processor and never touch our servers).
  • Communications: messages you send our team, survey responses, and feedback.

Information generated when you use the Service

  • Authentication data: one-time password (OTP) records and sign-in logs, described in detail in the next section.
  • Share events: when, how (QR, link, Apple/Google Wallet), and where (approximate city derived from IP) your card is shared.
  • Recipient interactions: when someone views your card, taps a contact method, saves your contact, or submits the optional capture form.
  • Lead records: the contact details a recipient voluntarily submits, plus public enrichment data (company name, public job title, public LinkedIn URL).
  • AI relationship signals: recency, frequency, depth, and mutual-contact indicators derived from your activity. These power the relationship score and AI follow-up drafts.
  • Device & log data: browser type, device type, operating system, IP address, referring URLs, timestamps, and crash logs.

Information from third parties

  • Connected CRMs and tools (HubSpot, Salesforce, Notion, Slack, etc.) — we read and write the records you authorize.
  • Enterprise identity providers — where your organization has configured SAML single sign-on, we receive the identity assertion it sends us (typically email address, name, and group membership).
  • Public enrichment providers — limited public business information about people whose contact details you import or capture.
  • Payment processor — confirmation of payment status, card brand, and last four digits. We never receive full card numbers.

What we do not collect

  • Passwords. The platform is passwordless; there is no password field, no password database, and no password reset flow to compromise.
  • Precise geolocation. We derive an approximate city or country from IP address; we do not track your GPS location.
  • Special category data. We do not ask for, and ask you not to upload, information revealing health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, or sexual orientation.
  • Government identifiers or financial account numbers. These are never required by the Service.

Authentication and account security

Contexion uses passwordless authentication. You create an account with an email address and sign in with a one-time password sent to that address. This section explains exactly what that involves for your data.

Email address collection

Your email address is the only credential the Service requires. We use it to create and identify your account, to deliver sign-in codes, to send transactional messages (lead alerts, billing receipts, security notices), and — only if you opt in — product news. Because it is your credential, you cannot remove your email address while your account is open, though you can change it after verifying the new address.

OTP generation and email delivery

  • When you request sign-in, we generate a random one-time password using a cryptographically secure random number generator.
  • The OTP is delivered to your registered email address by our transactional email provider, which acts as our processor under a written data processing agreement and does not use your address for its own purposes.
  • Each OTP is valid for 5 minutes and expires automatically. It is single-use: redeeming it, or requesting a newer code, invalidates it immediately.
  • We store the OTP only as a salted hash alongside its expiry time — never in a form that we or an attacker could read back out of our database. The record is deleted or marked spent as soon as it is used or expires.
  • We rate-limit code requests and failed attempts per email address and per IP address to prevent enumeration, brute-force, and mail-flooding attacks.

Session management

Entering a valid OTP creates an authenticated session. We store a session identifier in a strictly necessary cookie (cx_session, described in our Cookies Policy) together with the device and browser characteristics of the session, so that we can detect session hijacking. Sessions expire after a period of inactivity, and you can end them at any time by signing out. Signing out revokes the session token on our side, not just in your browser.

Because there is no password

Passwordless authentication removes an entire class of risk — there is no password to reuse, leak, phish, or store. In exchange, your email account becomes the key to your Contexion account. Anyone who can read your inbox can request a code and sign in. We strongly recommend enabling multi-factor authentication with your email provider. We will never ask you for an OTP by phone, chat, or support ticket; treat any such request as phishing and report it to info@contexion.ai.

Authentication logs

We keep a security log of authentication events — the email address involved, the time, the IP address, the user agent, and whether the attempt succeeded or failed. We use these records only to investigate suspicious activity, to respond to account-takeover reports, to enforce rate limits, and to meet our security obligations. They are stored encrypted, access to them is restricted to authorized security personnel, they are never used for marketing or profiling, and they are retained for 12 months before being deleted or irreversibly aggregated. You can request a copy of the authentication log for your own account — see Your rights.

Enterprise single sign-on

Where your organization has configured SAML single sign-on, authentication happens at your organization's identity provider rather than through our OTP flow. We receive only the identity assertion the provider sends, and your organization's own authentication policies and logs apply.

How we use information

  • Create your account and authenticate you — generate and deliver sign-in codes, maintain sessions, and protect against account takeover.
  • Deliver and operate the Service — host your card, route shares, capture leads, and sync to your connected tools.
  • Generate AI-powered relationship scores, follow-up drafts, and reminders.
  • Process payments and manage subscriptions.
  • Send transactional emails (sign-in codes, account activity, lead alerts, billing receipts, security notices). You cannot opt out of essential transactional emails while you have an account.
  • Send product news and tips — only if you opt in. You can unsubscribe at any time.
  • Improve the Service — debug, measure performance, conduct aggregated analytics, and develop new features.
  • Detect, prevent, and respond to fraud, abuse, and security incidents.
  • Comply with legal obligations and enforce our Terms.

We do not sell your personal information, we do not use it for cross-context behavioral advertising, and we do not use the content of your cards, leads, or messages to train third-party AI models. We will not use your information for a materially different purpose without telling you first and, where required, obtaining your consent.

Legal bases for processing (EEA and UK)

If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data on the following legal bases under the GDPR and UK GDPR:

  • Performance of a contract — creating and authenticating your account, hosting and sharing your card, capturing and syncing leads, running integrations, and providing support. Without this processing we cannot provide the Service.
  • Legitimate interests — securing the platform (rate limiting, fraud and abuse detection, authentication logging), debugging, aggregate product analytics, and direct marketing to existing business customers. We balance these interests against your rights, and you may object at any time.
  • Consent — non-essential cookies and analytics in regions that require consent, marketing emails to prospects, and any optional feature we describe as opt-in. You can withdraw consent at any time without affecting processing already carried out.
  • Legal obligation — tax and accounting records, responding to lawful requests, and retaining security records where required.
  • Vital interests / public interest — only in the rare case of an emergency involving someone's safety.

Where we act as a processor for lead data, the controller is the Contexion customer who captured it, and the legal basis is theirs to determine and document.

How we share information

We never sell your personal information. We share it only in these circumstances:

  • Service providers (subprocessors) — cloud hosting and storage, transactional email delivery (including sign-in codes), analytics, error monitoring, customer support tooling, and payment processing. They act on our instructions under written data-processing agreements, may not use your data for their own purposes, and are bound to confidentiality and security obligations. A current subprocessor list is available on request.
  • AI providers — where an AI feature requires it, the relevant content is sent to a model provider under contract to us. Those providers are contractually prohibited from retaining your content beyond what is needed to return a response, or from using it to train their models.
  • Integrations you connect — we send the data you authorize to the third-party tools you link to your Contexion workspace.
  • Within your workspace — if you are on a Team or Enterprise plan, admins and members can see workspace-level activity according to the role you assign them, and your workspace administrator may be able to access, export, restrict, or delete content in your account.
  • Legal compliance — to comply with law, valid legal process, or to protect rights, property, and safety. We review every request for validity and scope, object to overbroad demands, and notify affected users unless legally prohibited.
  • Corporate transactions — in connection with a merger, acquisition, financing, or sale of assets, with notice to you. Any successor remains bound by this Policy for information collected before the change, unless you agree otherwise.
  • With your direction — anything you publish on your card or choose to share is shared as you instruct.

Third-party integrations

When you connect a third-party tool, you authorize Contexion to read and write data on your behalf within the scopes that tool exposes. The third-party tool's own privacy policy governs what it does with that data once it leaves Contexion, and data already synced there is not deleted when you disconnect or close your Contexion account — you must delete it in that tool. You can disconnect any integration at any time from your account settings.

Cookies and analytics

We use strictly necessary cookies to keep you signed in and to protect against cross-site request forgery — the Service cannot function without them. We use functional cookies to remember your preferences and privacy-friendly analytics to understand which features are used, at an aggregate level. We set no advertising or marketing cookies at all, and we do not use cookies to build advertising profiles or to sell your behavior.

Our public marketing website sets no cookies whatsoever and loads no third-party resources — all assets, including our typefaces, are served from our own domain, so browsing contexion.ai transmits nothing about you to any outside company.

In regions with consent requirements (the EEA, UK, California and others), non-essential cookies are off until you opt in through our consent banner, and you can change your choice at any time from Cookie preferences. Full detail, including the specific cookies we set and the third parties involved, is in our Cookies Policy.

Do Not Track and Global Privacy Control

Browsers and extensions may send a Do Not Track (DNT) header. There is no common industry standard for interpreting DNT, so like most operators we do not alter our behavior in response to it — but we also do not track you across other companies' websites or apps, which is what DNT was designed to prevent.

We do honor Global Privacy Control (GPC) signals. If your browser or extension sends a GPC signal, we treat it as a valid, legally binding opt-out of the sale and sharing of personal information and as a withdrawal of consent to non-essential cookies for that browser, without requiring you to interact with the banner.

AI features and automated decision-making

The Service derives relationship signals — recency, frequency, depth, mutual connections — from your activity and uses them to produce a relationship score and to draft suggested follow-ups. This is profiling in the GDPR sense, so we want to be explicit about it:

  • Scores and drafts are decision support, not decisions. Nothing in the Service produces a legal or similarly significant effect on a person automatically, and we do not carry out automated decision-making within the meaning of Article 22 of the GDPR.
  • You review and edit every AI-drafted message before it is sent. AI output can be inaccurate and should not be relied on as professional advice.
  • We do not use your cards, leads, or messages to train third-party AI models, and our providers may not do so either.
  • You can request an explanation of how a relationship score was derived, or ask us to exclude your account from AI scoring, by writing to info@contexion.ai.

If someone shares a card with you, or you scan one

When a Contexion user shares their card with you, you receive the contact information they chose to publish. If you choose to save their contact or submit the optional capture form, the information you provide becomes a lead in their Contexion account and may flow to their connected CRM.

You do not need a Contexion account to view a card, and viewing one does not create an account for you. For lead records, the Contexion user who captured your details is the controller of that data — we process it on their behalf. You have rights over this information: see Your rights, or contact us at info@contexion.ai and we will forward your request to the relevant user and help them act on it.

Mobile apps and device permissions

The Contexion mobile apps request device permissions only when a feature needs them, and only after you grant them at the operating-system level. You can revoke any of these at any time in your device settings; the rest of the app keeps working.

  • Camera — to scan a QR code or capture a paper business card. Images are processed for the scan and are not retained unless you save the resulting contact.
  • Photo library — only for the images you explicitly choose to upload to your card.
  • Contacts — only if you choose to save a scanned contact to your phone, or to import contacts. We do not upload your address book in the background.
  • Notifications — to alert you to new leads and reminders. Optional, and controllable per category in the app.
  • Approximate location — where you enable event or venue tagging on a share. We do not collect precise background location.

We collect mobile device identifiers and crash diagnostics to keep the apps stable. We do not use the Advertising Identifier (IDFA/AAID), we do not track you across other companies' apps and websites, and so we do not present App Tracking Transparency prompts. The privacy labels published on the Apple App Store and the Data safety section on Google Play reflect the practices described in this Policy.

Data retention

We keep personal information only as long as we need it for the purpose it was collected, or as long as the law requires. In practice:

  • Account and card data — for as long as your account is active.
  • One-time passwords — the hashed code is valid for 5 minutes and is deleted or marked spent as soon as it is used or expires.
  • Authentication and security logs — 12 months, then deleted or irreversibly aggregated.
  • Session records — until the session expires or you sign out.
  • Lead records — for as long as the customer who captured them keeps them, subject to any retention rule that customer configures.
  • Support communications — 24 months after the conversation closes.
  • Analytics data — 14 months in identifiable form, then aggregated.
  • Financial and tax records — typically 7 years, as required by law.
  • Backups — deleted data persists in encrypted backups until they age out on our normal rotation, within 35 days.

When you delete your account, we delete or anonymize your personal data within 30 days, except the records above that we are required to keep. Lead records you have synced to third-party tools remain in those tools according to their own retention rules.

How we protect your data

We encrypt data in transit with TLS 1.2 or higher and at rest with AES-256, restrict internal access on a least-privilege basis with mandatory multi-factor authentication, log privileged actions, and monitor production systems continuously. Because the platform is passwordless, there is no password database to breach and no password reset flow to abuse. Our full control set is described on our Security page.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant supervisory authority without undue delay — and within 72 hours of becoming aware where the law requires it.

Your rights

Depending on where you live (notably the EEA, UK, Switzerland, California, and a growing number of other jurisdictions), you may have rights to:

  • Access the personal information we hold about you, including your authentication log.
  • Correct inaccurate or incomplete information.
  • Delete your personal information.
  • Object to or restrict certain processing, including processing based on our legitimate interests and direct marketing.
  • Receive a portable copy of your data in a structured, machine-readable format.
  • Withdraw consent where processing is based on consent, without affecting processing already carried out.
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
  • Lodge a complaint with your local data protection authority. If you are in the EEA you may complain to your national authority; in the UK, to the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to address your concern first.

Much of this is self-service: you can view and edit your profile, export your cards and leads, and delete your account from your account settings. Otherwise, email info@contexion.ai. We verify requests before acting on them — normally by confirming control of the registered email address, and for sensitive requests by asking for additional information. We respond within 30 days (45 days for US state privacy requests, extendable once by a further 45 days with notice). Exercising these rights is free unless a request is manifestly unfounded or excessive, and we will never discriminate against you for making one.

If your request concerns a lead record held by a Contexion customer, we will forward it to that customer, who is the controller of that data, and support them in responding.

US state privacy rights

If you are a resident of California, Colorado, Connecticut, Virginia, Texas, or another US state with a comprehensive privacy law, the rights above apply to you, along with the following disclosures.

Categories of personal information

In the 12 months preceding the date of this Policy we collected these CCPA/CPRA categories: identifiers (name, email address, IP address, account and device identifiers); commercial information (subscription plan, billing records, transaction history); internet or network activity (usage, share events, log and authentication data); approximate geolocation (city or country derived from IP); professional or employment information (job title, company, and the card and lead content you provide); and inferences (relationship scores and engagement signals). We collect them from you, from your use of the Service, from your connected integrations and identity provider, and from public enrichment providers, for the business purposes described in How we use information, and we disclose them to the service providers listed in How we share information.

No sale or sharing

We do not sell personal information, and we have not sold it in the preceding 12 months. We do not share personal information for cross-context behavioral advertising, and have not done so in the preceding 12 months. We run no advertising tags, retargeting pixels, or cross-site trackers. We do not knowingly sell or share the personal information of consumers under 16.

Sensitive personal information

We do not collect sensitive personal information for the purpose of inferring characteristics about you, and we do not use or disclose it beyond the purposes permitted under CPRA § 7027(m). Accordingly, we do not offer a separate "Limit the Use of My Sensitive Personal Information" control.

How to exercise your rights

Submit a request by emailing info@contexion.ai or through our contact form. We will confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 days with notice. An authorized agent may submit a request on your behalf with written permission that we can verify. You have the right not to receive discriminatory treatment for exercising any of these rights, and you may appeal a denied request by replying to our decision — where your state provides an appeal right, we will explain the outcome in writing and tell you how to contact your attorney general.

California "Shine the Light"

California Civil Code § 1798.83 permits California residents to request details of personal information disclosed to third parties for those third parties' own direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes, so there is nothing to report; you may still submit a request to info@contexion.ai.

Nevada residents

Nevada law (NRS 603A.340) lets Nevada consumers opt out of the sale of certain covered information. We do not sell covered information, but you may submit a verified opt-out request to info@contexion.ai and we will honor it.

International data transfers

Contexion is operated from the United States, and our infrastructure and service providers are located there. If you access the Service from outside the US, your information will be transferred to, stored, and processed in the US and other countries whose data protection laws may differ from your own.

For transfers of personal data out of the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum where applicable), supported by a transfer impact assessment and supplementary technical measures including encryption in transit and at rest. Copies of the relevant clauses are available on request at info@contexion.ai. Enterprise customers may ask about regional data residency options.

Children's privacy

Contexion is a professional networking tool intended for adults in a business context. It is not directed to children, and we do not knowingly collect personal information from anyone below the minimum age of digital consent where they live — 13 in the United States under COPPA, and up to 16 in parts of the European Economic Area. If you believe a child has provided us with personal information, contact info@contexion.ai and we will delete the account and the associated data promptly.

Changes to this Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. We will notify you of material changes by email or in-product notice at least 30 days before they take effect, and where the law requires it we will ask for your consent. Previous versions are available on request.

Contact us

For questions about this Policy, to exercise your rights, or to request our Data Processing Agreement:

  • Privacy and data protection: info@contexion.ai
  • Security reports: info@contexion.ai with the subject "Security report" — see our Security page.
  • Enterprise security and privacy reviews: sales@contexion.ai
  • Contact form: contexion.ai/contact
  • Mail: Contexion™ (a product of Veloxs AI Inc.), 1209 170th St SW, Unit B, Lynwood, WA 98037, USA

Related pages: Terms of Service · Cookies Policy · Security

Contexion

AI-powered digital business cards and relationship intelligence for professionals and teams.

Product
  • Digital Cards
  • Lead Capture
  • AI Intelligence
  • Integrations
Solutions
  • Sales Teams
  • Recruiters
  • Founders
  • Enterprise
Legal
  • Privacy
  • Terms
  • Security
  • Cookies
Company
  • About
  • Contact Us
© 2026 Contexion™ by Veloxs AI Inc. All rights reserved.