Last updated 1 August 2026

Privacy Policy

ConX is a digital business card and event-networking platform operated from Australia ("ConX", "we", "us"). This policy explains what personal information we collect, why, where it goes, and the choices you have — whether you hold a ConX account or you simply scanned a ConX code at an event.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. If you're reading this because you scanned a company's code and want to know what they got — start here.

1.Information we collect

In short: Your account and card details, the things you exchange at events, and basic usage data. Card payments never touch us — they go straight to Stripe.This summary is for readability — the full text below it is what applies.

Account information. Name, email address and password (held by Firebase Authentication), and your subscription status.

Card and profile content. Whatever you put on your cards: name, title, company, email, phone, website, profile photo — and, if you attach one, your resume (see section 7, it gets special treatment). Company accounts add their logo, blurb, links, brochure and the team members they list.

Exchange and scan data. When you exchange with a company or scan a dock, we record the exchange: the time, the company and dock/event involved, which card you shared, and the fields that card shared. This is the product — the exchange is what both sides keep.

Web capture forms.If you scan a company's code without the app, the form collects your name, email and (optionally) phone — nothing else.

Usage and device data. Product analytics events (screens opened, exchanges completed) via PostHog, which is linked to your account email and name so we can understand usage; and session analytics on this website via Microsoft Clarity. See section 12.

Payment information.Handled entirely by Stripe. Your card details are entered on Stripe's payment page and never touch ConX servers — we hold only your subscription status and a Stripe customer reference.

2.People who are not ConX users

In short: If you scanned a code or were scanned at an event but never made an account, we still hold what you chose to hand over — and you have the same rights over it as any user. Email us and we'll action it.This summary is for readability — the full text below it is what applies.

ConX holds personal information about people without accounts in two situations:

You filled in a capture form.Scanning a company's code without the app and submitting the form stores your name, email and optional phone with that company as a lead, and creates a "pre-account" keyed to your email so that everything you collected at the event is waiting for you if you later sign up. If you never sign up, the pre-account simply sits unclaimed; you can ask us to delete it at any time.

A member added you.A company admin can list a colleague (name, title, email) as a contact card on their public page, and members can record people they met manually. Companies must have the person's consent to do this (it's a condition of our Terms).

Your rights as a non-user: you can request access, correction or deletion of any of this by emailing conx.connect@gmail.com — no account required. We respond within 30 days.

3.When you scan a company's ConX code

The exchange form collects your name and email — plus your phone number and resume only if you choose to include them. ConX holds that information for two purposes: delivering the exchange to the company whose code you scanned, and keeping your copy of everything you collected waiting for you in your ConX library. It's stored securely on our infrastructure (hosted in the United States — section 9), it isn't used for anything else, and it's never sold. If you'd rather we didn't hold it, email conx.connect@gmail.com and we'll delete it.

What the company itself does with the details you handed over is up to that company — section 5 explains that split.

4.How we use information

We use personal information to:

— run the service: delivering exchanges, storing connections, showing companies the leads they captured;
— send the emails the product promises: your exchanged card after a web capture, verification codes, team invites, and follow-up messages a company sends its leads (see section 11);
— operate subscriptions and billing through Stripe;
— understand product usage and improve ConX (analytics, section 12);
— keep the platform safe: abuse prevention, security and debugging.

We do not sell personal information, and we do not use your data to train AI models.

5.When ConX acts for a company

In short: Leads a company captures at its stand belong to that company's relationship with you — the company decides how they're used, and ConX processes them on the company's instructions.This summary is for readability — the full text below it is what applies.

When you exchange with a company's dock or a team member's work card, the personal information you share becomes a lead in that company's workspace. For that data, the company is the controllerand ConX processes it in accordance with the company's instructions — the company decides who on its team sees it, how you're followed up, and when it's deleted. Privacy questions about a specific company's use of your details are best directed to that company; we'll assist either side on request.

Notes, ratings and tags a company's team attaches to a lead are the company's own records about the interaction.

6.Your content stays yours

You own the content you put into ConX — your cards, your resume, your connections. You grant us the licence needed to operate the service (storing, displaying and transmitting your content to the people you exchange with), nothing broader.

7.Resumes

In short: Your resume is private by default, shared only with a company you explicitly shared it with, and only for the time window that company advertised — after that, access closes automatically.This summary is for readability — the full text below it is what applies.

Resumes get stricter handling than any other field. Your resume file is stored privately (it has no public link). It is shared with a company only when you exchange with that company while resume-sharing is part of the exchange — that moment creates an access grant for that one company. The grant expires automatically after the share window shown on the exchange page (48 hours unless the company sets 12–168 hours), and companies access the file through our servers on every open, so expiry is enforced, not honorary. Companies must not retain or redistribute resume files beyond the window (a condition of our Terms).

If you use ConX Gold's AI cover letters, your resume is transmitted to Anthropic (our AI provider) to write the draft — that happens only when you request a cover letter, and Anthropic's API terms prohibit using it to train models.

8.Who we share information with

We share personal information only with the service providers that run ConX:

Google Firebase / Google Cloud — hosting, database, file storage and authentication (data hosted in the United States);
Stripe — subscription payments;
Anthropic — AI features: generating company page drafts from public company information, and (Gold only, at your request) cover letters from your resume;
Resend — transactional email delivery;
PostHog and Microsoft Clarity — analytics (section 12).

Beyond these: the people and companies you deliberately exchange with receive what you shared; and we'll disclose information if the law requires it. That's the list.

9.Where your data lives

ConX runs on Google Cloud infrastructure hosted in the United States, and the providers above operate internationally. By using ConX you consent to your information being processed in those locations. Wherever it goes, this policy still governs how it's handled.

10.Retention and deletion

We keep your information while your account is active. You can delete individual items in-app — contacts, your resume, company brochures, and leads — and removing a team member destroys their work card so future exchanges stop feeding the company.

To delete your account and associated data, or any non-user data we hold about you, email conx.connect@gmail.com. We action deletion requests within 30 days. Unclaimed pre-accounts and expired verification codes are periodically cleared.

11.Follow-up messages

Companies can message the leads they captured through ConX. The company is the sender and is responsible for the content and for complying with the Spam Act 2003 (Cth) — messages must relate to why you connected, and we suspend senders who abuse it. Marketing emails from ConX itself are opt-in at signup and every one carries an unsubscribe.

12.Cookies and analytics

The app and website use PostHogfor product analytics — events like "exchange completed", associated with your account email and name so we can understand real usage. This website also uses Microsoft Clarity(session replays and heat maps) to see where pages confuse people, and stores small preferences (like a capture form remembering your details on your own device) in your browser's local storage. We don't run advertising trackers.

13.Security

Encryption in transit and at rest, per-company access rules enforced at the database layer, and payments that never touch our servers. The full picture — including how resume access control works — is on our Security page.

14.Data breaches

We follow the Notifiable Data Breaches scheme: if a breach is likely to result in serious harm, we'll notify affected people and the Office of the Australian Information Commissioner (OAIC) as required by law.

15.Children

ConX is built for professional networking and is not directed at children under 16. If you believe a child has provided us personal information, contact us and we'll delete it.

16.Users in the EEA and UK

If you use ConX from the EEA or UK: our legal bases are contract (running the service you signed up for), legitimate interests (security, analytics, improving the product) and consent (marketing). You have rights of access, rectification, erasure, restriction, portability and objection — exercise any of them via conx.connect@gmail.com. International transfers rely on standard contractual clauses or equivalent safeguards. You may complain to your local supervisory authority.

17.Access, correction and complaints

You can access and correct most of your information directly in the app. For anything else — access requests, corrections, deletion, complaints — email conx.connect@gmail.com. We respond within 30 days. If you're not satisfied with our handling of a privacy complaint, you can lodge it with the Office of the Australian Information Commissioner.

18.Changes to this policy

When we change this policy we update the date at the top; for material changes we'll tell you in the app or by email. ConX™ — the ConX name, the X mark and "Connect and Exchange" are our brand.