Privacy Policy
Effective: February 26, 2026 · Last updated: February 26, 2026
1. Information We Collect
We collect information you provide directly:
- Account data: name, email address, username, hashed password
- Profile data: bio, avatar, links, appearance settings
- Order data: shipping address, order details (payment data is handled exclusively by Stripe)
- Usage data: profile views, link clicks, NFC tap counts, referrer information, timestamps
We collect automatically: IP addresses (for rate limiting; not linked to personal profiles) and standard HTTP request headers.
2. How We Use Your Information
- To operate and improve the Service
- To process orders and send transactional emails
- To send weekly analytics digests and product updates
- To enforce our Terms of Service and prevent abuse
3. Data Processors
- Supabase — database and file storage. Privacy Policy
- Stripe — payment processing (PCI DSS compliant; we store only your Stripe customer ID). Privacy Policy
- Vercel — hosting and analytics. Privacy Policy
- Resend — transactional email delivery. Privacy Policy
- Upstash — rate limiting (IP addresses stored transiently, up to 1 minute). Privacy Policy
4. Data Sharing
We do not sell your personal data. We share data only with the processors above, as required to operate the Service, or as required by law.
5. Public Information
Your username, display name, bio, avatar, and active links are publicly visible at tapfolio.app/[username]. You can update or remove this content at any time from your dashboard.
6. Cookies
We use session cookies for authentication (managed by NextAuth.js). We do not use advertising or tracking cookies. Vercel Analytics uses a cookieless, privacy-preserving approach.
7. Data Retention
We retain your data while your account is active. Upon account deletion, data is removed within 30 days. Stripe retains payment records as required by financial regulations.
8. Your Rights
You have the right to access, correct, export, or delete your personal data. Email privacy@tapfolio.app and we will respond within 30 days.
9. Children
TapFolio is not directed to children under 13. We do not knowingly collect data from children under 13.
10. Changes
Material changes will be communicated via email. Continued use after changes constitutes acceptance.
11. Contact
Privacy questions? Email privacy@tapfolio.app.