Privacy Policy
Who this is for
This policy covers two different groups, and the distinction matters:
- Businesses that subscribe to Taproved and use it to collect feedback about their branches.
- Customers of those businesses, who tap an NFC card or scan a QR code and leave a rating.
For a customer's feedback, the business is the party that decides why it is collected and what happens to it. We provide the software and store the data on that business's behalf.
What we collect when someone taps a card
Tapping a card does not require an account, and we do not ask for identity.
| Data | Why | Optional? |
|---|---|---|
| The star rating | The core measurement the business subscribes for | No, it is the reason for the page |
| Written comment | So the business can understand and fix a problem | Yes. A business can also switch the field off entirely |
| Name and phone number | So the business can follow up on a complaint | Yes, always. A customer may leave both blank and stay anonymous, and a business can switch collection off entirely |
| Which card was tapped, at which branch, and when | Attributing feedback to the right location, and counting scans | No |
| Browser user agent and referring page | Basic diagnostics, telling a real tap from a broken link | No |
| A one-way hash of the network address | Recognising repeated abuse, someone submitting hundreds of fake ratings, and nothing else | No, but it is a hash: it cannot be turned back into an address, and it is deleted after a day |
| A random session identifier | Grouping one visit's events together, and preventing a retried submission from being counted twice | No |
What we deliberately do not collect
- No account, login or password is required to leave feedback.
- No advertising or third-party tracking cookies on the customer-facing review page.
- No location beyond which branch's card was tapped. We do not request GPS.
- No payment details are ever collected on the customer-facing page.
Data stored on the customer's own phone
The review page can work without a connection. If a customer submits feedback while offline, that submission is stored in their browser (IndexedDB) and sent when the connection returns. It carries a random identifier so a retry cannot create a duplicate.
This copy lives only on that phone. Clearing browser data removes it. It is discarded automatically after seven days if it has never been able to send.
Clicking through to Google or social media
We record that a button was tapped, which button, when, and from which card, so a business can see which links people use. We do not follow the customer to the destination, and we cannot see what they do there.
In particular, recording that someone tapped “Leave a Google review” is not evidence that a review was published. Once a customer leaves our page, Google's own privacy policy applies.
What businesses see
A business sees the feedback left about its own branches, and nothing about any other business. A branch manager sees only the branches they have been assigned. This separation is enforced by the database itself, not just by hiding pages.
Business account data
For people who sign in, we store a name, an email address, a role, and which organization and branches they belong to. We record sign-in attempts for security review. Passwords are handled by our authentication provider and are never stored in readable form.
Who we share data with
We do not sell data. We share it only with:
- Supabase, database, authentication and file storage.
- Our hosting provider, serving the application.
- Our email provider, sending notifications and scheduled reports to business users, not to customers.
How long we keep it
Feedback, scans and reports are kept for as long as the business subscribes, because they are the historical record the business is paying for.
A subscription ending does not delete anything. Access is suspended; the data stays intact so it is all there if the business renews. Deleting an account is a separate, deliberate request, never a side effect of non-payment.
Your rights
If you left feedback at a business and want it removed or corrected, the quickest route is to ask that business directly, since it controls the record. You may also contact us and we will pass the request on and help action it.
Because feedback can be left anonymously, we may be unable to locate a specific submission without details such as the branch and rough date.
Security
- All traffic is served over HTTPS.
- Tenant separation is enforced in the database, and covered by an automated test suite that runs before every release.
- Card codes are random, not sequential, so they cannot be guessed to reach another business's page.
- API keys are stored only as a hash. If our database were exposed, the keys in it would not work.
- Submissions are rate-limited to limit abuse.
Children
The service is intended for businesses and their adult customers. We do not knowingly collect data from children.
Contact
Questions about this policy or your data? Email info@taproved.com or message +92 324 4843526 on WhatsApp.