Who we are
Company legal name (“TapInfo”, “we”) is the data controller for personal data processed through tapinfo.io, the TapInfo apps and the TapInfo resolver. Registered in England and Wales, company number Company number, registered office Registered office address. ICO registration ICO registration number.
When an organisation issues TapInfo cards to its people, that organisation is the controller for work profile data it manages, and we process it on its behalf.
What we collect
- Account data: your name, email and sign-in records.
- Profile data: the fields you choose to publish.
- Tap records: time, which card or tag was used, and an approximate city derived from the network address, which we don’t store.
- Relationship data: details people choose to send you, and the notes you write.
- Order data: delivery address and order history. Checkout and payment are handled by Shopify; we never see full card numbers. A logo you upload for a custom card is kept for 180 days, then deleted.
- Website data: privacy-friendly, cookie-free analytics. See the cookie notice.
Why, and our legal basis
- To provide TapInfo to you: contract.
- To keep accounts and cards secure, and to prevent abuse: legitimate interests.
- To keep tax and accounting records: legal obligation.
- To send you marketing email, only if you ask for it: consent, which you can withdraw at any time.
Who we share it with
People who tap your card see the profile fields you’ve chosen. Organisation admins see work card activity for cards they issued, never personal notes. Our subprocessors are listed in the Trust Centre. We never sell personal data.
How long we keep it
Retention for each type of data is set out in the Trust Centre. When you delete your account, live data is erased within 30 days and backups within 35.
Your rights
You can ask to access, correct, delete, restrict or move your data, and object to how we use it. Most of this is self-serve in your account. Otherwise email [email protected]; we reply within one month. You can also complain to the Information Commissioner’s Office (ico.org.uk).
International transfers
Data is hosted in the UK or EU. If a subprocessor handles data outside the UK, we use UK-approved safeguards such as the International Data Transfer Addendum.
Changes
We’ll post changes here and email account holders about significant ones at least 30 days before they apply.