Privacy Policy

Last updated: 16 July 2026

Tapback is operated by Ross Duggan, a sole trader based in Ireland, who is the data controller for the personal data described here. Contact: hello@tapback.party.

Two very different groups of people touch Tapback: readers, who tap reactions on pages that embed it, and account holders, who sign up and configure it. Readers come first because that's where we collect the least.

1. Readers — people who react on a page

There are no reader accounts and no reader logins. When you react on a page that embeds Tapback:

Our legal basis for this processing is legitimate interest: keeping counts honest and the service abuse-resistant, using the least data that achieves it.

2. Account holders — people who sign up

We store:

Legal basis: performing our contract with you, and legal obligations for whatever billing records tax law requires us to keep.

3. Payments

Paid plans are sold through Paddle.com, our Merchant of Record. Paddle collects and processes your payment details, billing address, and tax information under Paddle's privacy policy; we never see your card number. Paddle tells us which account has which plan, which is all we need.

4. Where data lives

Tapback runs on Cloudflare's network (Cloudflare, Inc., our infrastructure sub-processor). Account and configuration data is stored in Cloudflare's distributed storage. Reaction data lives where the site owner chose when creating the Tapbar: the default placement, or pinned to the European Union. Signup uses Cloudflare Turnstile to filter bots, which processes the signup request under Cloudflare's privacy policy. Where processing happens outside the EEA, it is covered by the European Commission's standard contractual clauses in our providers' data processing terms.

5. Error and operations telemetry

When something breaks, we record an error report with the technical context needed to fix it. Reports are scrubbed of secrets and stored in our own infrastructure — there is no third-party analytics or error-tracking vendor. Operational metrics are sampled aggregates kept for three months.

6. Your rights

Under the GDPR you can ask for access to, correction of, export of, or deletion of your personal data, and object to or restrict processing. Email hello@tapback.party and we will respond within a month. Reaction data and configuration are also self-service: export runs from the console, one click, JSON or CSV. You can also complain to the Irish Data Protection Commission (dataprotection.ie) or your local supervisory authority.

A caveat on reader data: because reader records are pseudonymous and IP linkage is destroyed within 48 hours, we usually cannot tell which reaction rows are yours even if you ask — the design that protects you also prevents us from looking you up.

7. Changes

If this policy changes materially, we will email account holders before the change takes effect and update the date at the top.