Taprs
Features Back to Taprs
Taprs Legal

Privacy Policy

This Privacy Policy explains how Taprs collects, uses, discloses, retains, and otherwise processes personal information in connection with the Taprs Services.

Effective Date: August 7, 2026 Last Updated: September 4, 2026
On this page
1. Scope 2. Taprs' Role 3. Information Taprs Currently Collects 4. Information Taprs May Collect as Services Expand 5. Sources of Information 6. Purposes for Collection and Use 7. Consent 8. Business Customers and Their Customers 9. Service Providers and Subprocessors 10. Payment Information 11. Cookies and Session Technologies 12. Cross-Border Processing 13. Security 14. Security Incidents and Privacy Breaches 15. Data Retention 16. Access, Correction and Privacy Requests 17. Privacy Officer 18. Marketing Communications 19. Children 20. Aggregated and De-identified Information 21. Artificial Intelligence and Automated Features 22. Google and Other Third-Party Services 23. Business Transfers 24. Legal Disclosures 25. Changes to this Privacy Policy 26. Contact

This Privacy Policy explains how Taprs, an Ontario-based business operated by its sole proprietor ("Taprs," "we," "us," or "our") collects, uses, discloses, retains, and otherwise processes personal information in connection with the Taprs website, software services, business dashboards, NFC-enabled services, review-management tools, analytics, communications, subscriptions, and related products and services collectively, the "Services".

Taprs operates from Ontario, Canada.

This Privacy Policy is intended to describe Taprs' practices in accordance with applicable Canadian privacy law, including the Personal Information Protection and Electronic Documents Act ("PIPEDA") where applicable.

Nothing in this Privacy Policy limits a right or obligation that cannot legally be limited under applicable law.

1. Scope

This Privacy Policy applies to personal information processed by Taprs in connection with:

  • the Taprs website;
  • business dashboards;
  • NFC cards and stands;
  • Taprs-managed links;
  • analytics relating to NFC interactions;
  • customer accounts or dashboard access;
  • subscriptions and billing administration;
  • sales and demo requests;
  • customer support;
  • review-management functionality;
  • future authorized third-party integrations;
  • future artificial-intelligence-supported functionality; and
  • other Taprs Services that reference this Privacy Policy.

This Privacy Policy does not govern the independent privacy practices of Google, Stripe, review platforms, websites, payment processors, or other third parties.

When a person leaves Taprs and interacts directly with a third-party service, that third party's terms and privacy policy may apply.

2. Taprs' Role

Taprs primarily provides Services to businesses.

Depending on the circumstances, Taprs may process personal information:

  1. for Taprs' own reasonable business purposes; or
  2. on behalf of a subscribing business in accordance with that business's instructions.

A subscribing business is responsible for ensuring it has appropriate authority, consent, and notices necessary to provide personal information to Taprs.

Nothing in this Policy attempts to exclude privacy responsibilities imposed directly on Taprs by law.

3. Information Taprs Currently Collects

A. Contact and Demo Information

When a person requests a Taprs demonstration or contacts Taprs, we may collect:

  • name;
  • business name;
  • business type;
  • email address;
  • phone number where provided;
  • messages submitted through the website; and
  • related communications.

B. Business Information

Taprs may collect or store information required to configure and provide Services, including:

  • business name;
  • business type;
  • business review destination;
  • Google or other review-platform link;
  • business contact information;
  • dashboard configuration; and
  • information provided by the subscribing business.

Some information relating solely to a business may not constitute personal information under applicable law.

C. NFC Interaction and Analytics Information

Taprs currently records information associated with NFC interactions, including:

  • NFC tap counts; and
  • the date and time associated with taps.

This information may be used to produce dashboard analytics showing customer interaction activity.

Taprs does not currently represent that it collects precise geographic location, browser fingerprints, device fingerprints, referring URLs, or similar expanded analytics unless such functionality is introduced and this Privacy Policy is updated accordingly.

D. Dashboard and Account Information

Customer dashboards are currently accessed through private tokenized dashboard URLs.

Customers do not currently create separate dashboard usernames and passwords.

Taprs' administrative area is separately protected through authentication and session controls.

E. Subscription and Transaction Information

Taprs may process information concerning:

  • subscription tier;
  • billing status;
  • transaction identifier;
  • payment amount;
  • payment date;
  • payment status;
  • cancellation status; and
  • other information reasonably required to administer subscriptions.

Payment processing is currently handled through Stripe.

Taprs does not intentionally store customers' full payment-card numbers in its own application infrastructure.

F. Communications

We may retain:

  • customer-support communications;
  • sales communications;
  • demo communications;
  • complaints;
  • questions;
  • requests; and
  • voluntary feedback.

4. Information Taprs May Collect as Services Expand

Taprs may introduce additional functionality in the future, including:

  • additional Google Business Profile capabilities;
  • additional review-related integrations;
  • QR-code analytics;
  • stronger or additional account authentication;
  • additional website analytics; and
  • additional artificial-intelligence-supported features.

Taprs will update its privacy disclosures where appropriate before materially expanding the categories of personal information it processes.

Taprs currently supports Google Business Profile connection functionality through Google and/or integration service providers, and uses AI-supported features for review responses and Pro SEO recommendations.

5. Sources of Information

Taprs may obtain information:

  • directly from users;
  • from subscribing businesses;
  • automatically through NFC interactions;
  • through Taprs dashboards;
  • from Stripe;
  • through communications with Taprs;
  • through authorized third-party integrations when introduced; and
  • from publicly available business information where lawful.

6. Purposes for Collection and Use

Taprs may process information for purposes reasonably connected to its Services, including:

  • responding to demo requests;
  • communicating with customers;
  • providing Taprs Services;
  • configuring NFC links;
  • operating dashboards;
  • counting NFC interactions;
  • displaying interaction times;
  • generating analytics;
  • administering subscriptions;
  • processing payments through third-party providers;
  • providing support;
  • troubleshooting;
  • preventing fraud or abuse;
  • maintaining security;
  • improving Taprs;
  • developing new features;
  • maintaining reasonable business records;
  • enforcing agreements;
  • complying with applicable law; and
  • protecting Taprs, customers, users, or others.

Taprs seeks to limit collection and use to purposes that are reasonable in the circumstances.

7. Consent

Where applicable law requires consent, Taprs will seek consent appropriate to:

  • the type of information;
  • the sensitivity of the information;
  • the purpose for processing; and
  • the surrounding circumstances.

Consent may be express or implied where legally appropriate.

Where legally available, a person may withdraw consent by contacting Taprs.

Withdrawal may affect Taprs' ability to continue providing a Service where the information is reasonably necessary to provide that Service.

8. Business Customers and Their Customers

Businesses using Taprs independently determine how they interact with their customers.

Each subscribing business is responsible for:

  • complying with applicable privacy law;
  • providing required privacy notices;
  • obtaining required consent;
  • lawfully collecting personal information;
  • ensuring it has authority to provide information to Taprs;
  • complying with review-platform rules; and
  • ensuring its instructions to Taprs are lawful.

Taprs does not assume responsibility for a subscribing business's independent conduct except where applicable law imposes responsibility directly on Taprs.

9. Service Providers and Subprocessors

Taprs currently relies on third-party providers to operate parts of the Service.

Current providers include:

Cloudflare

Taprs uses Cloudflare infrastructure, including Cloudflare Workers and KV-related functionality, to operate parts of its website, NFC functionality, dashboards, and data storage.

Stripe

Taprs uses Stripe to process payments and administer payment-related functionality.

Future Providers

Taprs may introduce additional providers for:

  • email;
  • authentication;
  • databases;
  • communications;
  • cybersecurity;
  • analytics;
  • artificial intelligence;
  • monitoring;
  • infrastructure;
  • customer support; and
  • other operational functions.

Any artificial-intelligence provider that processes customer data will be added to Taprs' applicable disclosures before or when such processing begins.

10. Payment Information

Stripe processes payments for Taprs.

Stripe may directly collect:

  • payment-card information;
  • billing information; and
  • other information needed to process a transaction.

Taprs may receive transaction-related information from Stripe but does not intentionally store full payment-card numbers itself.

Stripe's independent privacy practices also apply to its processing.

11. Cookies and Session Technologies

Taprs may use cookies or similar browser technologies that are necessary for:

  • authentication;
  • administrative sessions;
  • security;
  • website functionality; and
  • maintaining user sessions.

Taprs does not currently represent that it uses Google Analytics, Meta Pixel, TikTok Pixel, Hotjar, or similar advertising-tracking technologies.

If Taprs introduces material analytics or advertising tracking technologies, this Policy and any required consent mechanisms will be updated as appropriate.

12. Cross-Border Processing

Taprs operates from Canada but uses technology providers that may process information in Canada, the United States, or other jurisdictions.

Information processed outside Canada may be subject to the laws of those jurisdictions, including lawful access by courts, regulators, governments, or law-enforcement authorities.

Taprs does not represent that all information is stored exclusively in Canada.

13. Security

Taprs uses administrative and technical measures intended to restrict unauthorized access to its systems.

At present:

  • administrative functionality is protected through authentication and session controls;
  • administrative access is currently limited to the Taprs owner/operator; and
  • customer dashboards use private tokenized URLs.

Taprs does not currently claim SOC 2, ISO 27001, PCI DSS certification, independent penetration-test certification, or another formal security certification.

Taprs also does not represent that it operates a separate proprietary backup system.

No internet-based system, cloud provider, database, credential, network, or security mechanism can guarantee absolute security.

Taprs therefore cannot guarantee that every:

  • cyberattack;
  • unauthorized access event;
  • software vulnerability;
  • infrastructure failure;
  • credential compromise; or
  • other security incident

will be prevented.

Nothing in this section excludes obligations Taprs cannot legally exclude.

14. Security Incidents and Privacy Breaches

Taprs intends to take reasonable steps to:

  • identify;
  • investigate;
  • contain;
  • document; and
  • respond

to suspected security incidents affecting personal information under its control.

Where required by applicable Canadian privacy law, Taprs will maintain applicable breach records and make required notifications or reports.

Taprs does not contract out of statutory breach obligations that cannot legally be waived.

15. Data Retention

Taprs applies the following general retention approach:

Active Customers

Customer information may be retained for the duration of the active business relationship.

Former Customers

Personal information associated with a former customer account or dashboard will generally be retained for up to 24 months after termination or cancellation, unless longer retention is reasonably necessary for:

  • legal obligations;
  • accounting records;
  • fraud prevention;
  • security;
  • dispute resolution;
  • enforcement of agreements; or
  • other legitimate purposes permitted by law.

Cancellation of a Taprs subscription does not automatically result in immediate deletion of all associated information.

Demo and Contact Requests

Demo-request and contact information from individuals who do not become customers will generally be retained for up to 24 months.

Transaction Records

Payment, accounting, and transaction-related records may be retained for longer periods where reasonably necessary to comply with applicable tax, accounting, or legal obligations.

Aggregated Information

Properly aggregated or de-identified information that is not treated as identifiable personal information may be retained for longer periods where legally permitted.

Taprs will delete, destroy, or appropriately de-identify personal information when it is no longer reasonably necessary and no lawful basis for continued retention applies.

16. Access, Correction and Privacy Requests

Subject to applicable Canadian privacy law, individuals may contact Taprs to:

  • request access to personal information relating to them;
  • request correction of inaccurate information;
  • ask questions regarding Taprs' privacy practices;
  • withdraw consent where legally available; or
  • make a privacy complaint.

Taprs may verify identity before fulfilling a request.

Legal exceptions may apply.

17. Privacy Officer

Taprs has designated the following privacy contact:

Privacy Officer:
Privacy Officer, Taprs

Email:
admin@taprs.ca

Taprs does not currently publish a separate public business mailing address.

Privacy requests may currently be submitted electronically using the address above.

18. Marketing Communications

Taprs may communicate with users regarding:

  • requested demonstrations;
  • accounts;
  • purchases;
  • subscriptions;
  • support;
  • Service updates; and
  • matters reasonably related to an existing business relationship.

Submitting a Taprs demo request does not automatically constitute consent to receive unrelated promotional communications where Canadian law requires separate consent.

Taprs will seek to comply with applicable Canadian anti-spam requirements when sending commercial electronic messages.

19. Children

Taprs is designed as a business service.

Taprs is not specifically designed for children.

20. Aggregated and De-identified Information

To the extent permitted by applicable law, Taprs may create aggregated or appropriately de-identified information for:

  • analytics;
  • benchmarking;
  • product development;
  • research;
  • service improvement;
  • security analysis; and
  • other legitimate business purposes.

Taprs will not describe information as anonymous or de-identified unless that characterization is reasonably supportable.

21. Artificial Intelligence and Automated Features

Taprs uses artificial-intelligence-supported features in parts of the Service, including review-response assistance and Pro SEO recommendations.

When a user invokes an AI-supported feature, Taprs may transmit only the information reasonably needed to generate the requested output to a third-party AI service provider, including OpenAI where configured.

  • review rating and review text supplied for a response;
  • business name and selected response settings;
  • target SEO keywords;
  • bounded evidence from public website pages; and
  • technical findings needed to generate an SEO recommendation.

Taprs does not intentionally send website passwords, private CMS credentials, payment-card information, or private website administration content to the SEO AI recommendation feature. Public website evidence is treated as untrusted data and recommendations are validated by Taprs rules before being shown.

AI-generated information may contain errors or omissions.

AI output must not be treated as guaranteed business, legal, financial, accounting, tax, or other professional advice.

22. Google and Other Third-Party Services

Taprs may direct users to third-party services including Google.

Taprs supports Google Business Profile connection functionality through Google APIs and/or third-party integration providers where configured and authorized by the Customer.

Taprs is not Google and does not control Google's:

  • review platform;
  • APIs;
  • privacy practices;
  • rankings;
  • algorithms;
  • policies; or
  • functionality.

Third parties maintain their own privacy policies.

23. Business Transfers

To the extent permitted by law, information may be disclosed or transferred as part of an actual or proposed:

  • incorporation;
  • financing;
  • merger;
  • acquisition;
  • restructuring;
  • corporate reorganization;
  • asset sale;
  • due diligence process; or
  • insolvency-related transaction.

Appropriate confidentiality protections will be used where required.

24. Legal Disclosures

Taprs may disclose information where reasonably necessary or legally permitted to:

  • comply with applicable law;
  • comply with legal process;
  • respond to lawful governmental requests;
  • enforce Taprs agreements;
  • investigate fraud or abuse;
  • investigate security incidents;
  • protect Taprs;
  • protect customers or others; or
  • establish, exercise, or defend legal claims.

25. Changes to this Privacy Policy

Taprs may update this Policy to reflect changes in:

  • Services;
  • technologies;
  • vendors;
  • processing practices;
  • business operations; or
  • legal requirements.

Where applicable law requires notice or renewed consent, Taprs will seek to provide it.

26. Contact

Privacy questions may be directed to:

Privacy Officer, Taprs
admin@taprs.ca

Home Privacy Policy Contact
© 2026 Taprs. Smart NFC connections and reputation management.