1. Scope and contact
This policy covers Taply at taply.solutions, including visitors, customer wallets, merchant accounts, device orders and support. Taply operates the account, platform, ordering and support services described here. Contact info@taply.solutions for privacy questions or rights requests, or support@taply.solutions for account help.
Participating merchants decide how to run their loyalty programs and what rewards and marketing they offer. They are responsible for their independent uses of information and their own privacy notices. Where Taply acts on a merchant’s instructions, the applicable responsibilities depend on that activity and any required processing agreement.
2. Account information and Google sign-in
We process your email address, account ID, authentication and session records, sign-in provider and business access permissions. If you choose Google sign-in, Google and our authentication provider, Supabase, exchange the information needed to authenticate you. This may include your Google account identifier, email, verification status, name and profile picture in authentication metadata. Taply does not receive your Google password.
Google sign-in is used to authenticate you and provide your Taply account. The current sign-in flow does not request access to Gmail, Google Drive, contacts or calendar contents. Account information is processed by our authentication and hosting providers as needed to operate and secure the service; it is not used by Taply to target advertising.
You can review or remove Taply’s Google connection in your Google Account’s third-party connections settings. Removing that connection does not itself delete your existing Taply account or records; use account deletion or contact us for that purpose.
3. Information you provide and activity we record
Optional profile fields include your birthday and marketing preference. A birthday is not required to collect stamps. It can be used for birthday-related loyalty offers; entering it alone does not opt you into promotional emails. The interface restricts changing it after it is set, so contact us if it needs correction.
Loyalty records include the participating shop, stamp balance, tap times, device identifiers and counters used to prevent replay, rewards and redemptions, referrals and expiry events. These records can reveal interactions with a business and are personal information even when shown under a customer number rather than a name.
Business and order records include shop and contact details, branding, device locations, delivery address, plan and quantities, order notes, verification and agreement acceptance, provisioning and delivery milestones, and payment records. The current cash-on-delivery order flow does not ask for card details.
Support records include your message, reply address and correspondence. Hosting, authentication, storage and email providers also process technical information such as IP addresses, browser information, request times, error logs and email delivery events. Please avoid sending passwords, private links or unnecessary sensitive information.
4. Why we use information
We use information to create and secure accounts, maintain wallets, record valid stamps and redemptions, administer referrals, provide merchant tools, process orders, arrange delivery, respond to support and send necessary service communications. We also use relevant records to prevent fraud, investigate errors, resolve disputes and meet applicable legal obligations.
Where a legal-basis framework such as the GDPR applies, providing a service you request and taking requested steps before an order rely on contractual necessity; account security, fraud prevention and managing business relationships rely on legitimate interests, subject to your rights; legally required recordkeeping relies on the relevant legal obligation. Optional promotional emails rely on consent where required. Optional birthday-related functionality is provided at your request; contact us to remove the birthday or stop that use.
Required account and order fields are needed to provide the relevant service. You may leave optional fields blank and decline optional marketing without losing ordinary stamp collection. We do not use the service to make solely automated decisions producing legal or similarly significant effects about you.
5. What participating businesses can access
A merchant can access loyalty and referral activity associated with its program, including customer identifiers, stamp balances and visit or reward information. Current access permissions also permit associated customer profile information, including email, birthday if provided and marketing preference. This can include customers connected through that shop’s referrals. A field not displayed in a dashboard is not necessarily inaccessible to the merchant.
Merchants are not authorized to use these details for unrelated outreach or disregard marketing preferences. Their access should not include your loyalty history at unrelated shops. Ask the relevant merchant about its independent use of your information; contact Taply about platform access or a suspected exposure.
Authorized Taply administrators may access information needed for operations, support, security and legal responsibilities. Public shop branding and discoverable business locations can be visible to other users; individual customer wallets are not intended as public profiles.
6. Service providers and disclosures
Taply uses Supabase for database, authentication, storage and server-side functions; Vercel for website hosting; and Resend for transactional and merchant marketing email delivery. Google supports optional sign-in and directions links. OpenStreetMap services supply discovery map tiles; Nominatim may be used for business address geocoding during provisioning.
We provide delivery partners with information needed to deliver hardware. Providers receive information relevant to their work and may maintain operational and security logs. External sign-in and mapping services also have their own privacy policies. Information may be disclosed where required by law or a valid authority request, or where necessary and lawful to address fraud, security incidents or legal claims.
Providers may process information in countries other than your own. The processing locations and safeguards depend on the provider and service configuration; a database region does not mean all information stays in that country. Contact us for information about the providers and safeguards relevant to your data. Any legally required transfer safeguards must apply to the relevant transfer.
7. Location, maps and browser storage
If you allow browser location access, Discover uses your coordinates to center the map and calculate distances. The current page keeps these coordinates in memory rather than saving a personal location history in Taply’s database. You can deny or revoke location permission in your browser.
Map tile requests disclose your IP address and the requested map area to the map provider; the area may be near your location. Choosing directions opens Google Maps with the selected shop coordinates. Business locations displayed on the map are distinct from your device location.
Taply uses browser storage for sign-in sessions and preferences such as favorite cards, onboarding and the last selected shop. Clearing it can sign you out or reset preferences. The Cookie and Browser Storage Notice explains these uses. The application does not include an advertising-tracker SDK; external providers may maintain their own service and security records.
8. Email preferences and private links
Account verification, order, agreement, shipping and support communications are service messages, separate from optional promotions. You can disable marketing in profile settings or ask support to do so. This does not stop messages necessary for your account or order.
Anonymous support submissions do not receive an automatic confirmation. Signed-in users may receive a receipt at their verified account email. Order-verification emails are sent to the address supplied for the order, including anonymous orders.
Private order-progress links allow anyone holding the link to view a limited order summary and milestones without signing in. They do not currently expire automatically. Verification and agreement links have separate expiry and single-use rules. Keep these links private and contact support if one is exposed.
9. Retention and account deletion
Account and active loyalty information are kept while needed to provide the service. The Delete account option removes your login, profile, birthday, preferences and linked stamp-card, reward and referral records. Historical tap and audit records can remain with the account reference removed. Removal of that reference does not necessarily make every remaining record anonymous.
Order and agreement information, invoices, support emails and provider records are not automatically erased when you delete a wallet account. Their retention depends on order fulfillment, unresolved support issues, applicable accounting or tax obligations, fraud investigations and the establishment or defense of claims. Expiry of a verification token does not itself erase the associated request. We do not promise an automatic deletion deadline that the system does not enforce.
Backups and provider logs may persist according to their configured retention cycles rather than being removed immediately. Contact info@taply.solutions for a review of remaining personal information and the retention criteria that apply to your request. We will identify any reason for retaining information rather than treating every record as exempt from deletion.
Deleting a business owner’s account disconnects ownership but preserves the shop, shared business records and other customers’ information. Business logos may remain with the shop. Account deletion is not a subscription cancellation request or automatic bill settlement; contact support to arrange business closure or transfer.
10. Security and your rights
We use account authentication and database access controls to restrict unauthorized access. No internet service can guarantee absolute security. Protect your credentials and private links and report suspected exposure to support@taply.solutions without unnecessarily forwarding another person’s information.
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to certain processing. Where processing relies on consent, you can withdraw it without affecting prior lawful processing. You may also complain to the competent data-protection authority, including in your place of residence or work where applicable.
Email info@taply.solutions with the account or order concerned and your request. We may ask for proportionate information to verify your identity or authority. Do not send identity documents unless requested through an appropriate channel. We will respond within applicable legal time limits and explain any relevant exception or necessary extension.
11. Young users and changes to this policy
Taply is not designed to solicit information from children who cannot lawfully authorize the relevant use. Where parental or guardian authorization is required, it must be obtained. Contact us if you believe a child’s information has been provided without the authorization required by applicable law so we can review and address it.
We will update the date of this policy when it changes and communicate material changes appropriately. A revised policy does not itself authorize incompatible new uses of previously collected information. Questions and requests can be sent to info@taply.solutions.
Questions? info@taply.solutions