Skip to content

Privacy policy

How Tapp ApS handles personal data about people who visit our website or contact us through it. If you use the Tapp app, the privacy policy you accept when you sign up covers that use.

Who we are

Tapp ApS (CVR 45241203), Gothersgade 14, 4. tv., 1123 København K, Denmark, is the data controller for the personal data described in this policy. You can reach us about anything in it at support@usetapp.io.

What this policy covers

This policy covers our website at tapp.shop, in every language and market version, and the enquiries you send us through it or by email. It does not cover:

  • the Tapp apps and the web dashboard, which are covered by the privacy policy you accept when you sign up;
  • the shop, booking and ordering pages that venues run on Tapp at their own tapp.shop addresses, which have their own privacy policy and terms.

What we collect

We only collect what you give us and what our servers need to deliver the website safely:

  • Details you enter in a form. When you send an enquiry, ask for a demo or pricing, or start signing up, we receive what you type in, such as your name, email address, business name, phone number, venue type, number of sites and your message, and whether you asked for product news.
  • Emails you send us: your email address, your message and anything you attach.
  • Technical and security data. When you load a page, the servers and firewall of our hosting provider process your IP address, your browser and device details, the page you asked for and when. This is used to deliver the page and to block abuse, not to build a profile of you.

This website has no analytics, no advertising cookies, no tracking pixels and no social media plugins, and we don’t buy personal data about you from anyone. Our cookie policy lists the little the site stores on your device. We never sell your personal data.

Why we use it, and our legal basis

  • To answer your enquiry and follow up on a conversation about Tapp, including sending you the information or pricing you asked for. Legal basis: steps you ask us to take before a possible contract (GDPR Article 6(1)(b)) and our legitimate interest in replying to businesses that contact us (Article 6(1)(f)).
  • To send you occasional product news, only if you ticked the box asking for it. Legal basis: your consent (Article 6(1)(a)), which you can withdraw at any time by writing to us or using the unsubscribe link in our emails.
  • To keep the website secure and working, and to stop spam and abuse. Legal basis: our legitimate interest in protecting the website and the people who use it (Article 6(1)(f)).
  • To meet our legal obligations, for example bookkeeping rules or lawful requests from authorities. Legal basis: legal obligation (Article 6(1)(c)).

Where we rely on legitimate interests, you can object at any time (see “Your rights”). We don’t make decisions about you by automated means, and we don’t profile you.

Who we share it with

We share personal data only with service providers who process it on our behalf, under a data processing agreement and our instructions:

  • Amazon Web Services, which hosts the website and runs the firewall that protects it;
  • the service providers we use to receive and manage enquiries, such as email and customer-relationship tools.

We also share data with authorities or advisers when the law requires it or when we need to establish or defend a legal claim. We don’t sell or rent your personal data to anyone.

Transfers outside the EU and the UK

If a service provider processes personal data outside the EU/EEA or the UK, we protect the transfer with the European Commission’s Standard Contractual Clauses (and the UK’s equivalent) or rely on an adequacy decision. Data can move between the EU and the UK because each recognises the other’s data protection as adequate. You can ask us for a copy of the safeguards we use.

How long we keep it

  • Enquiries and the conversation that follows: up to 36 months after your enquiry is resolved, unless the law requires us to keep them longer. If you become a customer, the privacy policy you accept at signup takes over.
  • Your product-news consent: until you withdraw it, together with a record of when you gave or withdrew it.
  • Security logs: for a limited period set by our hosting provider, after which they are deleted automatically.

Your rights

Under the GDPR, and the UK GDPR if you are in the UK, you have the right to:

  • access the personal data we hold about you and get a copy of it;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict how we use your data;
  • receive data you gave us in a portable format (data portability);
  • object to processing based on our legitimate interests, and to direct marketing at any time;
  • withdraw your consent at any time, without affecting what we did before you withdrew it.

To use any of these rights, email support@usetapp.io. We reply within one month and may first ask you to confirm who you are.

Complaints

If you’re unhappy with how we handle your data, please tell us first so we can put it right. You can also complain to a data protection authority: in Denmark, Datatilsynet (datatilsynet.dk), which supervises Tapp ApS; in the UK, the Information Commissioner’s Office (ico.org.uk); or the authority in the country where you live or work.

Changes to this policy

We update this policy when our website or the way we handle data changes. The date at the top shows the current version.

Contact

Tapp ApS, Gothersgade 14, 4. tv., 1123 København K, Denmark. Email: support@usetapp.io.