Digital business cards are safe when you treat them as what they are: a public web page. Your card shows only the details you choose to publish, an NFC tag stores a link rather than personal data, and the genuine risks are fake QR codes and careless provider data handling. Both are manageable with a few habits.
What does "safe" actually mean for a digital business card?
"Is it safe?" is really three questions bundled into one, and the honest answers differ:
- Exposure — what personal information becomes visible, and to whom.
- Interception — whether someone can read, clone or hijack the scan or tap.
- Custody — what happens to data your card collects, and who holds it.
Most coverage only answers the second. In practice, exposure and custody are where the real decisions sit. A card can be technically flawless and still be a bad idea if you published your home address on it.
What data does a digital business card actually expose?
Only the fields you fill in. A digital business card is a hosted profile at a URL, and that URL opens for anyone who has it, with no login on the visitor's side. There is no hidden layer of data behind it to dig out.
Typical published fields are name, job title, company, photo, short bio, phone number, email, social links, services, a product catalogue, a portfolio gallery, and a booking or enquiry form. On a platform like Follow My Site, that profile is closer to a mini-website than a card, so the exposure question matters more, not less: there is simply more surface to fill in.
The rule that keeps people out of trouble is blunt. Treat everything on the card as public. Not "public to people I hand it to" — public to search engines, scrapers, competitors and anyone the link gets forwarded to. Links get pasted into group chats and email signatures constantly.
The test to apply before publishing a field
Ask: would I be comfortable if this appeared in a search result, or in a marketing list someone bought? If the answer is no, that field belongs off the card and in a direct conversation instead.
Practical consequences: publish a business phone number, not your personal mobile. Publish a business email. Publish your city and a service area rather than a street address, unless you run a walk-in location and want to be found. Skip birthdays, personal social accounts and family photos. A downloadable vCard that saves straight to the recipient's phonebook is useful, but it carries the same fields — convenience, not a privacy boundary.
Are QR code business cards safe, and how does quishing work?
The QR code itself is safe. It is nothing more than a machine-readable way of writing a URL. It cannot execute code, install anything, or carry a payload of its own. The risk is human: a person cannot read a QR code by looking at it, so they cannot tell a real one from a fake one before scanning.
That gap is what "quishing" — QR phishing — exploits. Two patterns dominate:
- Physical overlay. Someone sticks their own printed QR sticker over a legitimate one on a poster, table tent, parking meter or event badge. The victim scans what they believe is the venue's code and lands on an attacker-controlled page.
- Delivered code. A QR arrives in an email, PDF or printed letter, often framed as a login, a delivery, or a document to review. Because the code moves the victim from a monitored work computer to a personal phone, it can sidestep email link filtering and endpoint controls.
Neither attack involves breaking the QR format. They rely on the reader not checking where the link goes.
How to check a QR link before you act on it
Most modern phone cameras show the destination URL as a preview banner before opening it. Read it, and read it properly:
- Find the registrable domain — the part immediately before the first single slash. In followmysite.com.verify-login.example, the real domain is example, not followmysite.com. Attackers hide the trusted name in a subdomain.
- Watch for character swaps and hyphenation: a lowercase L for an I, a zero for an O, "brand-secure.com" instead of "brand.com".
- Be sceptical of link shorteners on physical signage, where the owner controls the print anyway.
- Never enter a password, card number or one-time code on a page you reached by scanning a code. Navigate to the site yourself instead. This single rule defuses almost every quishing attempt.
- Check physical codes for a sticker edge. Run a thumbnail over the corner — layered stickers are easy to feel.
If you are the one handing out the code, you have obligations too. Use a domain a stranger can sanity-check, keep your link stable so people learn to recognise it, and inspect your own printed material and signage for overlays. A custom domain or a clean, readable profile link does more for trust than any badge on the page. If you are still setting yours up, our guide on how to create a QR code business card covers the practical side.
Can someone secretly read my NFC business card?
Not from across a room, and not without you noticing. NFC is a near-field technology in the literal sense. Reliable phone-to-tag reads happen at a few centimetres, and in everyday use you are touching the phone to the card. There is no realistic scenario where someone lifts your card's data from a queue behind you.
More importantly, look at what is actually on the tag. An NFC business card tag normally holds a single URL record — the address of your public profile. It does not hold your contact database, your login, or any payment credential. Someone who reads or clones the tag has obtained a link that you hand out on purpose. That is no worse than photographing your printed card.
Don't file NFC business cards alongside contactless payment cards, either. Payment cards run tokenised transactions with a bank; a business card tag is a pointer to a web page.
The NFC risks that are real
- Rewritable tags. A blank or unlocked NFC tag can be reprogrammed by anyone with a phone and a writer app. If your card's tag is left writable, someone with brief physical access could re-point it elsewhere. Ask your supplier whether tags ship locked or write-protected, and keep spare cards where you would keep spare keys.
- Tapping unknown tags. The quishing logic applies identically to a tag on a poster or a table. Read the URL preview before opening it.
- Lost physical cards. Covered below — and this is where digital genuinely beats paper.
For a fuller technical comparison of the two delivery methods, see NFC versus QR business cards.
How do the sharing methods compare on risk?
| Method | What is exposed | Main risk | Can you revoke it? |
|---|---|---|---|
| Paper card | Every printed detail, permanently | Copies circulate forever; lost cards leak your number to a stranger | No. Details are frozen at print time |
| QR code | A URL you control | Fake or overlaid codes sending people to a spoofed page | Yes, by editing or unpublishing the destination profile |
| NFC card or tag | A URL you control | Unlocked tags being rewritten; physical loss of the card | Yes, at the profile level. Lock the tag to prevent rewriting |
| Short profile link | A URL you control | Forwarding — assume anyone can end up with it | Yes, by editing or deactivating the profile |
| Lead form on the card | Other people's data, held by you and your provider | Weak retention, unclear deletion, or a provider breach | Depends entirely on the provider. Ask first |
The pattern is consistent: every digital method exposes a link rather than the data itself, and every digital method is revocable. Paper is the only row where you permanently lose control the moment you hand something over. That difference is the core argument in our piece on alternatives to paper visiting cards.
What happens to the leads your card collects?
This is the part people skip, and it is the part with actual legal weight. The moment your card includes an enquiry form, a booking flow or any lead capture, you are collecting other people's personal data — and under regimes such as the GDPR in Europe, the UK GDPR, and state privacy laws in the US, you are generally the party responsible for it, with your platform acting as a processor on your behalf. Requirements differ by jurisdiction, so check what applies where your contacts are, not just where you are.
In practice that means something modest but non-negotiable: collect only fields you need, say what you will use them for, don't quietly add form submissions to a marketing list, and be able to delete someone's record when they ask.
Visitor analytics deserve a note too. Aggregate view and tap counts tell you which cards and links are working. They are a business tool, not a surveillance tool — don't retain what you never look at.
Follow My Site includes enquiry forms, lead capture, appointment booking and visitor analytics on the profile, which is exactly why the questions in the next section are worth putting to us or to any provider you shortlist.
Checklist: what to ask any digital business card provider
Copy these into an email before you commit. A provider that answers plainly beats one with the longest feature list.
- Where is my data physically stored, and in which country?
- Is the card served over HTTPS on every page, including forms?
- Who at your company can view my leads, and under what circumstances?
- How long do you retain lead submissions and analytics by default, and can I change that?
- Can I export all of my data — profile, contacts, leads — in a standard format?
- If I cancel, what is deleted, when, and how do I confirm it happened?
- Can I delete an individual contact's record on request?
- Do you sell, share or use my data or my visitors' data for advertising?
- Which third-party subprocessors touch my data?
- Do you support two-factor authentication on my account login?
- If I use a custom domain, who controls the certificate and the DNS records?
- Do your physical NFC cards ship locked, and can I lock them myself?
- What is your process and timeline for notifying customers about a security incident?
- If my account lapses, does my public link keep working, redirect, or go dark?
That last question catches people out. Know the answer before you print the link on anything permanent. It is also one reason a one-time lifetime plan appeals to some people: there is no renewal date on which a shared link could quietly stop resolving. Follow My Site offers monthly, yearly and a genuine one-time lifetime option, which is unusual in a category that is mostly subscription-based — check any vendor's current pricing page for their own terms.
Should your card be private or password-protected?
For most professionals, no. The entire value of the format is that it opens instantly for someone you just met, with no app, no login and no friction. Adding a gate destroys that.
Restriction makes sense in narrower cases: a card carrying pricing you don't want indexed, an internal staff directory, or a recruiter-facing profile you'd rather not have circulating. If your provider offers private or password-protected profiles, that is where to use them.
Be realistic about what a gate achieves, though. Anything a person can view, they can screenshot and forward. Access controls limit casual discovery and search indexing; they do not stop deliberate copying. The more reliable pattern is layering: a lean public card with your contact routes and services, and anything sensitive sent directly once a conversation is real.
Use a business number, not your personal one
If you take one operational change away from this article, make it this. Your card is a public page with one-tap call and WhatsApp buttons on it. Those buttons are the point — they are also the reason the number on them will end up scraped, listed and dialled by people you never met.
Options that work: a dedicated business line, a second eSIM, a virtual number, or WhatsApp Business on a separate number. It costs little, keeps work calls out of your evenings, and it means you can hand the number to a colleague later without handing over your personal life.
The same logic applies to email: a business address is easier to filter, reassign and abandon.
What if you lose a card, or an employee leaves?
Losing a paper card is a small, permanent leak: your name, number and email are now in a stranger's pocket, and there is nothing you can do about it. Losing an NFC card is a different kind of event, because the card is only a pointer.
The fix happens in your account, not on the plastic. Edit the profile the tag points to, or deactivate it, and the lost card stops being useful. Nothing personal was ever stored on the tag itself. This is a real, checkable advantage of digital over print, and it is the same mechanism that makes the format work for teams.
Offboarding a team member cleanly
Get this right before you need it:
- Own the account. Cards for staff should be created under a company account, not a personal one. If a rep signs up with a personal email, the profile leaves when they do.
- Export the leads first. Pull their enquiries and contacts out before anything is deactivated.
- Decide the link's fate. Reassign the profile to their replacement, or update it to point to a general team contact. Old links live on in signatures and saved contacts for years.
- Collect physical cards as part of the standard offboarding list, alongside laptops and passes.
- Rotate shared logins. If several people touch one account, change the password on departure and enable two-factor authentication.
Teams sharing a customer base should read digital business cards for sales teams for how central ownership works in practice.
A short routine that covers most of the risk
- Publish business contact details only, and re-read the card once a quarter as a stranger would.
- Turn on two-factor authentication for the account that controls your profile.
- Preview every URL before you open it, whether it came from a scan, a tap or a message.
- Never authenticate or pay on a page you reached from a code.
- Lock NFC tags, and check printed codes for stickers.
- Know your provider's answers on retention, export and deletion.
Done consistently, that is a stronger position than any paper card holder has ever had, because paper offers no revocation and no way to correct a mistake after printing. When you are ready to publish, build the profile with a digital business card maker and set the privacy decisions before you print the link on anything.
Frequently Asked Questions
Are digital business cards safe to use?
Yes, for normal professional use. A digital business card publishes only the fields you enter, and it shares a link rather than a data file, so nothing is transmitted that you haven't chosen to make public. The two risks worth managing are fake QR codes that impersonate a legitimate link, and providers with unclear policies on storing and deleting the leads your card collects.
Can someone steal my information from an NFC business card?
They cannot pull personal data off the tag, because there is no personal data on it. An NFC business card tag normally stores one URL — the address of your public profile. Reading it at close range gives someone a link you hand out deliberately. The genuine precautions are locking the tag so it cannot be rewritten, and deactivating or editing the profile if the card is lost.
Are QR code business cards safe to scan?
Scanning is safe; the destination is what matters. A QR code is only an encoded URL and cannot run code by itself. The danger is quishing, where an attacker overlays a sticker or sends a code that leads to a spoofed page. Preview the URL before opening it, check the domain immediately before the first slash, and never enter passwords or payment details on a page reached from a code.
Is my personal phone number safe on a digital business card?
Assume it is not private. Your card is a public web page with tap-to-call and WhatsApp buttons, so the number on it can be found, scraped and reused. Use a dedicated business line, a second eSIM, a virtual number or WhatsApp Business instead. That keeps work calls separate, and it lets you hand the number to a colleague later without exposing your personal contacts.
What happens to the leads collected through my card?
They are stored by your platform and belong to you, but you are usually the party legally responsible for them under privacy laws such as the GDPR. Before choosing a provider, confirm where data is stored, how long submissions are retained, whether you can export everything, and how an individual record is deleted on request. Collect only the fields you actually need.
Can I make a digital business card private?
Some platforms offer private or password-protected profiles, which is useful for internal directories or pricing you do not want indexed. For everyday networking, a gate defeats the purpose, because the format works by opening instantly with no login. Remember that any page a person can view can also be screenshotted, so access controls limit casual discovery rather than deliberate copying.
What should I do if I lose my NFC business card?
Edit or deactivate the profile the card points to from your account dashboard. Because the tag holds only a URL, changing the destination makes the lost card useless without exposing anything personal. Then order a replacement. This is a concrete advantage over paper, where a lost card permanently puts your printed details in a stranger's hands with no way to revoke them.