Privacy Policy

Last updated: July 2026

1. Introduction

TapQ("we", "us", "our", or "Company") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the TapQ service at tapq.app(the "Service").

By using TapQ, you consent to the data practices described in this Privacy Policy. If you do not agree with these practices, please do not use the Service.

2. Information We Collect

2.1 Information You Provide

We collect information that you voluntarily provide when you:

  • Create an Account: Email address, password, and any profile information you choose to provide. If you sign in with Google, we receive your basic Google profile name and email to create and secure your operator account.
  • Create or Manage Queues: Business name, services, counters, join-form fields, and queue settings.
  • Join a Queue (customers): Only the fields the business configures on the join form (for example name, phone, party size, or a clinic record number). Customers do not need a TapQ account.
  • Contact Us: Name, email address, and any information you provide in support requests.
  • Subscribe: Payment-related information processed securely by our billing partner (Polar) when billing is enabled.

2.2 Automatically Collected Information

  • Technical data: IP address, browser type, and request logs used for security, rate limiting, and reliability.
  • Device identifiers: A local browser device identifier so operators and customers can return to their queues or tokens on the same device.
  • Queue activity: Token numbers, status, and related timestamps needed to run the waiting line.

2.3 Cookies and Local Storage

TapQ uses cookies and browser storage to maintain sessions, remember device access to queues, and keep the Service working. You can clear browser data at any time; doing so may require signing in again or re-entering an access code.

3. How We Use Your Information

  • Provide the Service: Run digital queues, display live status, sync staff devices, and show join-form details to authorized staff for that queue only.
  • Manage Accounts: Create and maintain operator accounts, protect queues across devices, and process subscriptions when billing is enabled.
  • Security: Prevent abuse through rate limits and access controls.
  • Support and Improvement: Respond to requests and improve the product.
  • Legal Compliance: Meet legal obligations and enforce our Terms of Service.

4. Roles and Access

Queue operators control who can manage a queue (signed-in owner or staff with the queue access code). Customer join data is visible to those operators for that queue. Other businesses and anonymous visitors cannot read another queue's customer details through the product APIs.

5. How We Share Your Information

We do not sell your personal information. We may share information with:

  • Infrastructure providers (including Supabase and Vercel) that host the Service.
  • Billing partner (Polar) when subscriptions are enabled.
  • Legal authorities when required by law or to protect rights, safety, or prevent fraud.

These providers are engaged to operate the Service and are expected to protect information and use it only for the purposes we specify.

6. Data Security

We implement industry-standard safeguards, including encryption in transit, access controls, and hashed queue access codes. No method of transmission or storage is 100% secure. You are responsible for keeping account credentials and access codes confidential.

7. Data Retention

We retain queue and customer records while the queue exists and as needed for operations, billing, and legal obligations. Deleting a queue permanently removes its customers, tokens, and related device permissions.

Signed-in account holders can download a copy of their account data or permanently delete their account from the Account page. Account deletion cancels billing with our payment partner (when configured), deletes all queues you own and their customer records, and removes your login. You may also contact us at info@tapq.app for help.

8. GDPR and Data Protection Measures

Where the EU General Data Protection Regulation (GDPR) or similar laws apply, we take the following measures to process personal data lawfully, fairly, and transparently. This section summarizes the controls built into TapQ; it does not replace your obligations as a business collecting guest information.

8.1 Roles under GDPR

  • Queue operators (businesses) decide what guest fields to collect on the join form and how that information is used at their location. For guest join data, the operator is typically the controller.
  • TapQhosts and processes that data to run the digital queue on the operator's instructions, and is typically a processor for guest join-form data.
  • For operator account data (email, login, billing status), TapQ acts as a controller.

8.2 Measures we have taken

  • Purpose limitation: Personal data is used to provide and secure the Service (queues, tokens, staff tools, billing, support) — not for sale to third parties.
  • Data minimisation: Guests do not need a TapQ account. Operators choose which join-form fields to collect, so only needed guest details are requested.
  • Access control:Customer join details for a queue are limited to that queue's owner and authorised staff (for example via access code). Other businesses cannot read another queue's customer details through the product APIs.
  • Confidentiality of secrets: Queue access codes are stored hashed. Sensitive columns are locked down so they are not exposed through public client access.
  • Security in transit: The Service uses HTTPS / TLS for traffic between browsers and our infrastructure.
  • Abuse prevention: Rate limiting and authentication controls help reduce unauthorised access and automated abuse.
  • Display hygiene: Lobby / TV displays show token and counter status, not full guest join-form details.
  • Right of access and portability: Signed-in operators can download a JSON export of their account, owned queues, and related customer join records from the Account page.
  • Right to erasure: Operators can permanently delete their account from the Account page. That cancels billing with our payment partner when configured (including anonymising billing customer records where supported), deletes owned queues, and removes associated customer records and the login.
  • Queue-level deletion: Deleting a queue removes its customers, tokens, and related device permissions for that line.
  • Subprocessors: We use infrastructure and service providers needed to run TapQ (including Supabase for data hosting, Vercel for application hosting, and Polar for billing when enabled). They process data only to provide those services to us.
  • No sale of personal data: We do not sell personal information.

8.3 Lawful bases (summary)

Depending on the activity, we rely on: performance of a contract (providing the Service you signed up for); legitimate interests (securing the Service, preventing abuse, improving reliability); and legal obligation where applicable. Where guest data is collected on a join form, the operator is responsible for having a lawful basis to collect and use that information at their location.

8.4 How to exercise GDPR rights

Operators: use Export data and Delete account on the Account page, or email info@tapq.app. Guests: contact the business that collected your details first; you may also contact us and we will help route or action requests we can fulfil as processor. We may need to verify identity before completing a request.

9. Your Privacy Rights

Depending on your location (including the EEA, UK, and similar jurisdictions), you may have rights to access, correct, delete, restrict or object to processing, and receive a portable copy of personal information, and to lodge a complaint with a supervisory authority. Use the export and delete controls on your Account page, or contact us at info@tapq.app. See also Section 8 for GDPR-specific measures.

10. Children's Privacy

TapQ is not intended for individuals under 18. We do not knowingly collect personal information from children. If you believe we have, contact us and we will delete it.

11. International Transfers

Your information may be processed in countries other than your own, including where our hosting and service providers operate. By using the Service, you understand that information may be transferred as needed to operate TapQ, with appropriate safeguards from us and our providers.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated date. Continued use of the Service after changes take effect constitutes acceptance.

13. Contact Us

Questions about this Privacy Policy, GDPR requests, or our data practices: info@tapq.app.

TapQ is a product of sheet2nest.

Terms of Service · Back to home