EdgeNFC
Home

Privacy Policy

This Privacy Policy explains what personal data EdgeNFC processes, why, on what legal basis, who we share it with, how long we keep it, and how you can exercise your rights. It covers the EU/EEA and UK (GDPR / UK GDPR), California (CCPA / CPRA), and Brazil (LGPD).

Who we are. EdgeNFC is operated by Blackwell Digital, a sole proprietorship based in California, United States. Blackwell Digital is the data controller for the personal data described here. You can reach us about anything in this policy — including access, deletion, and complaints — at support@edgenfc.com, or by post at the controller's address:

Blackwell Digital
3912 Ellenboro Ave
Modesto, CA 95357
United States

1. What we collect and why

The table below is our data map — the categories of personal data we process:

DataPurposeLegal basis (GDPR)Retention
Email, password hashAccount / authenticationContractLife of the account; deleted when the account is deleted, and in any case within 30 days of a verified deletion request
Stripe customer / subscription IDsBillingContract / legal obligationLife of the account; deleted when the account is deleted. Stripe keeps its own invoice and payment records for as long as tax and accounting law requires
Tag UIDs, countersProduct function (verify)Contract / legitimate interestLife of system
Verify events (UID, counter, verdict, time, coarse country)Anti-replay, scan analyticsLegitimate interestLife of the account — we do not currently expire them on a schedule. The tag UID is overwritten with an anonymous marker when the account is deleted, leaving only aggregate counts
IP / rate-limit stateSecurity, abuse preventionLegitimate interestShort TTL
Consent recordsProve consentLegal obligationLife of the account, so we can show what you agreed to and when; deleted when the account is deleted
Support messages — your email address and whatever you write to usAnswering your support or contact requestLegitimate interest / contractLife of the account; deleted when the account is deleted. Messages sent without an account cannot be linked to you and are kept as ordinary correspondence
Orders — shipping name, address, phone
Not currently collected.
Would fulfil hardware orders — we no longer sell hardware, so no shipping data is collected, stored, or shared. Row retained because it would apply again if the EdgeNFC store re-opens; if it does, this policy is updated first.Contract (n/a today)n/a — nothing collected

How long we keep things, plainly. We do not run a scheduled job that ages data out. Account data, tag data, verification history and consent records are kept for as long as the account exists, and are removed or anonymised when the account is deleted or when you ask us to delete them (see section 4). Rate-limiting state lives in a short-lived cache and expires on its own. Records we need for tax and accounting — principally the invoices and payment records held by Stripe — are kept for as long as tax law requires, even after your account is gone.

People who tap your tags (end users). The public tap/verify path processes a tag UID and counter to perform the verification the tag exists for. That processing is strictly necessary to deliver the service and is not gated on a cookie banner. We record a coarse (country-level) geo hint for analytics and never store a raw IP address for this path; UID-hiding (encrypted PICC) is available as a privacy control.

2. Processors and sub-processors

We use the following sub-processors to operate the Service. Each processes personal data only on our instructions and under a data-processing agreement:

Sub-processorPurposeData
StripePayments & billingBilling identifiers, payment status (card data is handled by Stripe, never by us)
CloudflareHosting, edge compute, storage (D1/KV)All Service data processed at the edge; request metadata
ResendTransactional email (sign-in links, invitations, account and support notices)Recipient email address and the contents of the message we send you
Ahrefs
Only if you opt in.
Aggregate analytics on our public marketing pages — which pages are read and where visitors arrive from. Loaded only after you turn on the Performance cookie category, and never on the signed-in app or the tag-verification pagePage address, referrer, approximate location and device/browser type, and the IP address that necessarily reaches them to serve the request. Ahrefs states the product is cookie-free and collects no personal data; we treat it as a sub-processor regardless, because we would rather over-disclose than under-disclose

We no longer use a fulfillment sub-processor. EdgeNFC previously sold physical tags and shared shipping details with GoToTags to fulfil those orders. We have stopped selling hardware, so GoToTags is no longer a sub-processor and we send them no personal data. We still recommend them as a place to buy tags at /hardware, but any purchase you make there is directly with them under their own privacy policy — we are not involved in it and never see your order.

We keep this sub-processor list up to date. Each of these sub-processors is engaged under a data-processing agreement that includes the transfer terms described in section 3.

3. International transfers

The Service is operated from the United States, and our sub-processors operate globally, so personal data may be processed outside your own country. Where personal data is transferred out of the EEA, Switzerland, or the UK, our data-processing agreement with each sub-processor relies on the European Commission's Standard Contractual Clauses (with the UK Addendum where the UK GDPR applies).

Our three US sub-processors are, in addition, self-certified participants in the EU–US Data Privacy Framework and its UK Extension. We confirmed this on the official participant list maintained by the US Department of Commerce at dataprivacyframework.gov, where they are listed as Cloudflare, Inc., Stripe, LLC, and Resend. Cloudflare and Stripe are also certified under the Swiss–US Framework; Resend's listing is active with its annual re-certification under review. A certification can lapse, so the Standard Contractual Clauses — not the Framework — remain the mechanism we contract on, with the Framework applying in parallel while a given certification is active. You can check any of these entries yourself on that list, or ask us which mechanism applies to a particular sub-processor at support@edgenfc.com.

Ahrefs is different, and we will not blur it. Ahrefs is Ahrefs Pte Ltd, a company incorporated in Singapore (16 Raffles Quay #33-03, Hong Leong Building, Singapore 048581), so data reaching it goes to Singapore rather than to the United States. The Data Privacy Framework is a programme for US organisations, and Ahrefs — correctly — does not appear on the Commerce Department's participant list at all; we searched for it there on 2026-08-06. We make no Data Privacy Framework claim for Ahrefs. Singapore has not received an EU adequacy decision either, so the safeguard for this transfer is the European Commission's Standard Contractual Clauses — the same mechanism as for our other sub-processors — which Ahrefs offers in its published data-processing addendum. This transfer happens only if you turn on the Performance cookie category; decline it, or use Global Privacy Control, and nothing is sent to Ahrefs at all.

No personal data goes anywhere else. In particular, GoToTags is not on the Data Privacy Framework list — which has no effect on you, because they are not a sub-processor and we send them nothing (see section 2). If you buy tags from them, that transfer is between you and them under their own privacy policy.

EU/UK representative and Data Protection Officer. We have not appointed an EU or UK representative under Article 27 GDPR, and we have not appointed a Data Protection Officer. We are a small operation based in the United States and do not currently target the Service at customers in the EU or UK. If and when we onboard EU or UK customers, we will appoint a representative and update this policy before doing so. In the meantime you can contact us directly at support@edgenfc.com, and this does not affect your right to complain to your local supervisory authority.

4. Your rights and how to exercise them

Depending on where you live, you have rights to access, correct, export (portability), delete, restrict, and object to the processing of your personal data, and to withdraw consent. To exercise them:

California (CCPA/CPRA). We do not sell or share your personal information, and we do not use or disclose sensitive personal information for any purpose beyond providing the Service. You may still exercise "Do Not Sell or Share My Personal Information" and "Limit the Use of My Sensitive Personal Information", and we honor Global Privacy Control (GPC) browser signals as a valid opt-out. We do not discriminate against you for exercising any of these rights.

We verify your identity before acting on an access or deletion request to protect your account. Requests we cannot fulfil self-serve, and any complaint, can be sent to our privacy contact: support@edgenfc.com. You also have the right to lodge a complaint with your local supervisory authority.

5. Cookies and local storage

For details on cookies, local storage, and how to change your consent, see our Cookie Policy. The only third-party script on this site is Ahrefs Web Analytics on the public marketing pages, and it is loaded only after you opt in to the Performance category — never before, and never on a visit where you chose "Reject all" or sent a Global Privacy Control signal.