Spreadly
Customer data on Hetzner in DE per the vendor, delivery via EU infrastructure (incl. Bunny CDN), ISO 27001:2022, full enterprise provisioning (SSO/SCIM/HRIS) - second-highest GDPR score in the test (92), but a young company without independently verified user reviews.
Spreadly is operated by Spreadly GmbH, headquartered in Baierbrunn near Munich, making it one of the most distinctly German competitors in the comparison. Founded in 2022 by Darius Göttert and Florian Theimer, the company positions itself consistently under a "Made in Germany" promise and targets SMBs and large enterprises in the DACH region that are looking for a centrally manageable solution for digital business cards, lead capture and email signatures with German hosting.
In our test, Spreadly achieves an overall score of 87 out of 100 points, placing it among the leaders. This result is driven above all by the second-highest GDPR score in the test field (92, behind oneVcard with 94) as well as a broad feature set (90).
Enterprise integration (84), team and admin management (86) and value for money (84) are also above average; only in the support-language profile (82) and - outside the scores - in market maturity does it become apparent that this is a comparatively young company. Spreadly is a proprietary SaaS solution, not an open-source product.
Strengths
- Consistent GDPR focus with customer-data hosting on Hetzner in Germany, ISO 27001:2022 certification and a provided DPA (further EU sub-processors such as Bunny CDN listed in the DPA) - a strong argument for German/EU B2B buyers
- Full enterprise provisioning: SSO (SAML 2.0), SCIM, bulk import via CSV/Azure AD/Google Workspace and HRIS connection (Personio, BambooHR) for automatic on-/offboarding
- Broad feature set including NFC, QR, Apple & Google Wallet, email signature management, AI business-card scanner, lead capture with CRM sync (Salesforce, HubSpot, Pipedrive, Dynamics) and REST API
- Generous free plan (unlimited contact data, Wallet, NFC, QR) and transparent EUR pricing with a team admin console and analytics
- German-language support including a phone hotline (+49 89) and purchase by invoice - well suited to the German mid-market
Weaknesses
- Hardly any independently verified reviews: Capterra profile with 0 reviews, G2/Trustpilot figures not substantiated; the advertised 4.8/5 is self-stated and not platform-verified
- No classic MDM (Intune/Jamf) documented for device rollout - provisioning runs via identity/HR systems (Azure AD, Google Workspace, SCIM), not via device management
- SLA only in the Enterprise plan (price on request); central enterprise features such as white-label are tailored to large organizations with roughly 1,000 employees or more
- No SOC 2 certification stated (only ISO 27001), which may be a gap in internationally/US-oriented procurement processes
- Not open source (proprietary SaaS) - no self-hosting/open-source availability for organizations with corresponding requirements
Data protection & server location
The GDPR score of 92 points ranks among the highest in the comparison (2nd place behind oneVcard with 94) and can be justified in a comprehensible way. According to the vendor, Spreadly stores customer data in Germany with Hetzner; the data is not supposed to leave the EU.
At the same time, the website advertises hosting by "European providers", and the DPA lists further sub-processors - including Bunnyway (CDN/infrastructure). The company is certified to ISO 27001:2022 and provides a data processing agreement (DPA) under Art. 28 GDPR.
Encryption is provided via TLS 1.3 in transit and AES-256 at rest; this is complemented by daily backups, role-based access control (RBAC), audit logs, regular penetration tests and a documented 72-hour notification deadline. Spreadly thus brings exactly the evidence that German and EU procurement processes typically require.
One limitation should be noted: a SOC 2 certification is not stated. For purely German/European tenders this is usually irrelevant; for internationally or US-oriented processes, however, SOC 2 may be required. The test winner oneVcard has no ISO 27001 certificate of its own - on this point Spreadly is ahead in terms of formal evidence.
Enterprise readiness & integration
For the B2B rollout, Spreadly covers the central requirements. Available are single sign-on via SAML 2.0 and OAuth 2.0, SCIM for automated provisioning, and bulk import via CSV, Azure AD and Google Workspace. HRIS connections to Personio and BambooHR enable automatic on- and offboarding directly from the HR system.
Via a REST API and CRM integrations with Salesforce, HubSpot, Pipedrive, Microsoft Dynamics and Zapier, captured leads can be transferred into existing sales processes. Added to this are a central admin console, email signature management, NFC, QR code, Apple and Google Wallet as well as custom branding.
This feature set supports the scores for enterprise integration (84) and team/admin management (86). Two points should be noted in the assessment from a German B2B perspective: first, no classic device MDM (Intune, Jamf) is documented - distribution runs via identity and HR systems, not via device management.
Second, central enterprise features such as white-label and an SLA are reserved for the individual Enterprise plan, which is tailored to organizations with roughly 1,000 employees or more. Large, named reference customers are not yet available, which makes it harder to assess the market maturity of a provider founded in 2022.
Pricing & plans
We deliberately do not list prices on digitale-visitenkarten.de: they change frequently and are not transparently and fully available for every provider. For Spreadly’s current terms, please refer directly to the provider’s website.
Verdict: Spreadly
Spreadly FAQ
Where is Spreadly's data hosted, and is the service GDPR-compliant?
According to the security page, Spreadly stores customer data in Germany with Hetzner; the data is not supposed to leave the EU. The website also speaks of hosting by "European providers", and the DPA lists further sub-processors (including Bunny CDN/infrastructure).
The company is certified to ISO 27001:2022 and provides a data processing agreement (DPA) under Art. 28 GDPR. Encryption is provided via TLS 1.3 in transit and AES-256 at rest, complemented by daily backups, RBAC, audit logs, regular penetration tests and a 72-hour notification deadline.
In our test, Spreadly thus achieves one of the highest GDPR scores (92 out of 100, 2nd place behind oneVcard). A SOC 2 certification is not stated.
Which enterprise and provisioning features does Spreadly offer?
Spreadly supports single sign-on via SAML 2.0 and OAuth 2.0, SCIM as well as bulk provisioning via CSV, Azure AD and Google Workspace. HRIS integrations with Personio and BambooHR enable automatic on- and offboarding.
Added to this are a REST API, CRM connections (Salesforce, HubSpot, Pipedrive, Microsoft Dynamics, Zapier) and a central admin console. A classic device MDM (Intune, Jamf) is not documented; SLA and white-label are reserved for the Enterprise plan, which is tailored to organizations with roughly 1,000 employees or more.
How much does Spreadly cost?
There is a permanently free plan with unlimited contact data, QR, NFC, Apple and Google Wallet as well as vCard. The Professional plan is paid with annual payment (with lower monthly and quarterly rates) and drops further with a three-year commitment.
A 7-day trial is available. The Enterprise plan is priced individually, including SSO, SLA and white-label; purchase by invoice is possible. A lower figure listed on Capterra is not confirmed on the official pricing page.
How reliable are Spreadly's user reviews?
Independently verified reviews are so far hardly available. The Capterra profile shows 0 reviews, and concrete figures on G2 and Trustpilot could not be substantiated. The 4.8/5 rating advertised on the website is the provider's own claim, not a platform-verified rating.
As a company founded in 2022, Spreadly also does not yet have any named large reference customers - a point that data-protection-focused buyers in the DACH region should weigh against the strong technical arguments.
Sources
- spreadly.app/en/prices
- spreadly.app/en/for-companies
- spreadly.app/en/security
- spreadly.app/en/legal/legal-notice
- spreadly.app/en/digital-business-card
- spreadly.app/en/company
- www.munich-startup.de/en/startups/spreadly
- www.startbase.com/organization/spreadly
- www.starting-up.de/news/news-investments/spreadly-digitales-visitenkarten-start-up-uebernimmt-bumpee.html
- www.capterra.com/p/276690/Spreadly
- www.g2.com/products/spreadly/reviews
- www.trustpilot.com/review/spreadly.app
- apps.apple.com/de/app/spreadly-digitale-visitenkarte/id6448201235
Find the right provider – free consultation
Planning a company-wide rollout of digital business cards? We’ll connect you with a suitable, GDPR-compliant provider. No sales pressure.