Last updated: 29 July 2026
Tappt Ltd ("Tappt", "we", "us", "our") provides a smart NFC card and link-in-bio platform that lets creators share their social links, contact details and content through a single tap or profile link (the "Service"). This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and the choices and rights you have.
This policy applies to our marketing site (tappt.io), our web app and dashboard (app.tappt.io), public profile pages (tappt.io/<handle>), our iOS and Android apps, and our NFC cards. By using the Service you agree to the collection and use of information as described here.
We are a company registered in England and Wales. Our registered address is 21 Montague Grove, Tockwith, York YO26 7AG, United Kingdom.
When you sign up, we collect your name, email address, chosen username/handle, and password (or, if you sign in with Google or Apple, the identifiers those providers give us). We never see or store your Google/Apple password.
Anything you choose to add to your profile: bio, avatar and header media, links, social handles, gallery images, "Moments" posts, product listings, and design/theme preferences.
If you enable "Exchange Contact" or lead forms, we store the details visitors voluntarily submit to you (name, email, phone, company, notes, and any custom fields you configure). This data belongs to you as the profile owner and is visible in your Connections/Leads dashboard.
Each physical card carries a unique code. When it's tapped or scanned, we log the timestamp, approximate location (derived from IP address), device/browser type, and which of your personas it resolved to — so you can see analytics on your dashboard.
We automatically collect profile views, link clicks, card taps, referral attribution, and similar interaction events to power your Analytics page. We use standard web technologies (IP address, user agent, cookies) to do this.
Payments for Tappt Pro subscriptions and NFC card purchases are processed by Stripe and/or Shopify. We do not store full card numbers on our servers. If you enable payouts (Stripe Connect) or accept tips/product sales, Stripe collects the verification information required to pay you.
If you contact support or submit a ticket, we keep a record of the conversation, including any files you attach, so we can help you and improve the Service.
Where UK GDPR or EU GDPR applies, we rely on: performance of a contract (running your account and the Service you signed up for), legitimate interests (securing the Service, preventing fraud, improving our product), consent (marketing emails, optional cookies), and legal obligation (tax and accounting records for payments).
We do not sell your personal data. We share information only with:
We use essential cookies to keep you signed in and remember your preferences (like light/dark theme). We use limited analytics to understand aggregate usage of the marketing site and to attribute NFC card referral codes. We do not use third-party advertising trackers. You can control cookies through your browser settings, though disabling essential cookies may break parts of the Service.
If you connect a Stripe account to receive payouts (referral commissions, tips, or product sales), Stripe acts as an independent data controller for the verification and banking information it collects from you directly during onboarding — see Stripe's Privacy Policy. Card purchases and Pro subscription checkout may be processed via Shopify — see Shopify's Privacy Policy.
We keep your account and profile data for as long as your account is active. If you delete your account, we delete or anonymise your personal data within a reasonable period, except where we're required to retain it for legal, tax, fraud-prevention or dispute-resolution purposes (for example, order and payout records).
We use industry-standard safeguards including encrypted connections (TLS), row-level security on our database, and restricted access to production systems. No method of transmission or storage is 100% secure, and we can't guarantee absolute security, but we work to protect your data and respond quickly to any incident.
Depending on where you live, you may have the right to:
To exercise any of these rights, contact us at the email below.
Tappt is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we'll delete it.
Our service providers may process data outside your home country, including in the United States. Where this happens, we rely on appropriate safeguards such as Standard Contractual Clauses, consistent with UK/EU data protection law.
We may update this Privacy Policy from time to time. If we make material changes, we'll notify you by email or an in-app notice. The "Last updated" date at the top shows when this policy was last revised.
Questions about this policy or your data? Email us at privacy@tappt.io, or write to:
Tappt Ltd
21 Montague Grove
Tockwith
York YO26 7AG
United Kingdom