Legal
Privacy Policy
What Atlorin collects, why, and who else is involved. Written to describe the product as it actually works today — not a template.
Effective date: August 28, 2026
1.Who we are and what this covers
Atlorin (“Atlorin”, “we”, “us”) provides a free digital profile — a shareable business card at a link like atlorin.com/p/… — together with optional NFC and QR products that point to it.
This policy explains what information we collect when you use atlorin.com, why we collect it, and who else is involved in handling it. It applies to visitors, people with an Atlorin account, and people who share their details with a profile owner through a public Atlorin profile.
If a section here does not match what you actually experience in the product, treat that as a bug and tell us through the contact form.
2.Information you provide
Account information
To create an account we ask for your email address and a password. We store your email address, a one-way hash of your password (never the password itself), your account status, whether your email has been verified, and your country and language preference. If you sign in with Google or Apple instead, we do not receive or store a password at all — see social sign-in.
Your digital profile
Everything on your profile is content you choose to enter, and you decide how much of it to fill in. Depending on what you add, this can include your name, job title, company, a short bio, a phone number, a contact email address, a website, a WhatsApp number, an address you choose to display, links to social accounts (Instagram, LinkedIn, Facebook, TikTok, X, YouTube), a profile photo, a cover photo, and any custom links or blocks you add.
Your profile is public by design. Anyone with your profile link, QR code, or a tap of your NFC product can see whatever you have put on it. Please only publish details you are comfortable making public. You can edit or remove any of it at any time from your dashboard.
Contact exchange
A public Atlorin profile can include a form that lets a visitor share their own details back with the profile owner. If you fill that in, we store the name, email address, phone number and (optionally) company you entered, and make it available to the owner of the profile you were viewing. We collect this because you submitted it — we do not build it from any other source.
Orders and shipping
If you buy a physical product, we store your order — the items, quantity, amount, currency and status — along with the shipping name and address, and the contact email address and phone number collected at checkout so we can fulfil and deliver the order. Physical products currently ship to United States addresses only.
Support messages
When you write to us through the contact form, we store your name, email address, an optional company name, the reason you selected, and your message, so we can reply and keep a record of the conversation.
3.Authentication and account security data
When you sign in, we create a signed session token stored in a cookie in your browser. We also record when your account last signed in.
Email verification and password resets work through single-use tokens sent to your email address. We store only a hash of each token, along with when it was issued and whether it has been used — not the token itself.
We apply rate limiting to sign-in attempts to slow down password guessing. This involves temporarily keeping a count of recent failed attempts associated with the network address they came from.
5.Payments
Payments are processed by Stripe. When you check out, you are taken to a payment page hosted by Stripe and you enter your card details there.
Atlorin does not receive or store your full payment card number. What we store is the record of the transaction: the amount, the currency, the status, and the identifiers Stripe gives us for the checkout session and the payment, which we use to match up payments, fulfil orders and process refunds.
Stripe handles your card data under its own privacy policy and its own security obligations as a payment processor.
6.NFC products, QR codes and profile links
Each physical product we ship carries a unique token embedded in its NFC chip or printed QR code. Tapping or scanning it opens a URL on atlorin.com that resolves that token and forwards the visitor to the profile it points at. Your digital profile also has its own separate public token used for its shareable link and QR code.
These tokens are random identifiers. They are tied to the product and to the account that owns it so we can route the visitor and support the device — they are not derived from, and do not contain, any personal information.
We do not build a visitor profile from taps or scans, and we do not run advertising or cross-site tracking on these redirects.
7.Operational and security data
Our servers keep ordinary operational logs of the kind any website produces — things like the time of a request, the path requested, the response status, and the network address it came from. We use these to keep the service running, investigate errors, and detect abuse.
We also record administrative events inside the product, such as when a device is assigned to an order or released back to inventory, so that order history is auditable.
9.Why we use this information
We use the information described above to:
- create and maintain your account, and verify your email address;
- publish and serve the digital profile you have configured;
- deliver contact-exchange submissions to the profile owner they were meant for;
- take payment, fulfil orders, ship products, and handle cancellations and refunds;
- send transactional email — verification, password reset, and order-related messages;
- respond to your support messages;
- keep the service secure, prevent abuse, and diagnose problems;
- meet legal and accounting obligations connected to the sales we make.
We do not sell your personal information, and we do not share it with third parties for their own advertising.
10.Service providers
We rely on a small number of providers to operate the service. Each receives only what it needs for its function:
- Stripe — payment processing and refunds. Receives your payment details directly, plus the order amount and identifiers.
- Resend — delivery of transactional email. Receives the recipient address and the contents of the message being sent.
- Hostinger — hosting of the application servers and database on which the service and your data run.
If we add or change a provider in a way that materially affects how your information is handled, we will update this page.
11.When we disclose information
Beyond the service providers above, we disclose information only:
- because you published it — anything on your digital profile is public to anyone with the link, QR code or NFC product;
- to the profile owner — contact details you submit through a profile’s contact-exchange form go to the owner of that profile;
- when the law requires it — in response to a valid legal request, or where we believe disclosure is necessary to protect our rights, our users, or the public;
- in a business transfer — if Atlorin or its assets are acquired, your information may transfer as part of that transaction, subject to this policy.
12.How long we keep information
We keep your account, profile and related content for as long as your account exists, because that content is the service.
Order, payment and refund records are kept after an order completes, since we need them for support, accounting and tax purposes.
Support messages and contact-exchange submissions are kept until they are deleted from the product.
We have not set fixed retention periods for each category, and we would rather say so than publish a schedule we do not actually enforce. If you want your information removed sooner, ask us through the contact form and we will act on it.
13.Security
The site is served over HTTPS. Passwords are stored as one-way hashes using a memory-hard algorithm, never in a readable form. Session cookies are signed and marked HttpOnly. Sign-in attempts are rate limited. Credentials that the service itself needs to hold — such as payment and sign-in provider keys — are encrypted at rest with a key kept outside the database.
No system is perfectly secure, and we do not claim to hold any security certification. If you believe you have found a vulnerability, please tell us through the contact form so we can fix it.
14.Your choices and how to reach your information
- View and edit — your profile content, account email and preferences are editable from your dashboard at any time.
- Unpublish — removing content from your profile removes it from the public page.
- Disconnect a sign-in method — from your account page, as long as you keep at least one way to sign in.
- Transactional email — verification, password reset and order messages are part of the service and are not marketing, so they are not something you can unsubscribe from while holding an account.
- Access, correction or deletion — if you want a copy of your information, a correction, or your account and its data deleted, contact us through the contact form. There is no self-service delete button in the product today, so this is the route, and we will confirm when it is done.
15.Children's privacy
Atlorin is a professional networking product. It is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has given us information, contact us through the contact form and we will delete it.
16.Where your information is processed
Our application servers and database are hosted in the United States. Our service providers may process information in other countries as part of their own operations.
If you use Atlorin from outside the United States, you are sending your information to be processed there, where data protection law may differ from the law where you live.
17.Changes to this policy
We may update this policy as the product changes. When we do, we will revise the effective date at the top of this page. If a change materially affects how we handle your information, we will make a reasonable effort to tell you directly. Continuing to use Atlorin after an update means the updated policy applies to you.
18.Contact us
Questions about this policy, or about the information we hold about you, go through the contact form on atlorin.com. Choosing Account Help or General Question routes it to the right place.
Our transactional email is sent from a no-reply address, so the contact form is the reliable way to reach a person.
4.Google and Apple sign-in
Atlorin supports signing in with Google and with Apple. An administrator has to configure and switch each one on before it appears; if you do not see the option, it is not enabled on this deployment.
When you use one of these, the provider tells us:
We store that identifier, the email address the provider reported, and whether it was verified, so we can link the sign-in to your Atlorin account. We do not receive your password at the provider, and we do not get access to your Google or Apple account beyond the sign-in itself.
If you use Sign in with Apple and choose to hide your email address, Apple gives us a private relay address instead of your real one. That works normally for receiving email from us, and we do not attempt to resolve it to your actual address.
Disconnecting a provider from your account page removes the link between it and your Atlorin account. We will not let you remove your last remaining way to sign in.