Privacy Policy
Last updated: 16 July 2026
Tapback is operated by Ross Duggan, a sole trader based in Ireland, who is the data controller for the personal data described here. Contact: hello@tapback.party.
Two very different groups of people touch Tapback: readers, who tap reactions on pages that embed it, and account holders, who sign up and configure it. Readers come first because that's where we collect the least.
1. Readers — people who react on a page
There are no reader accounts and no reader logins. When you react on a page that embeds Tapback:
- The widget stores a random identifier in your browser's localStorage. It contains nothing about you, and because localStorage is scoped per site, it cannot connect your activity on one site to another. It exists to enforce per-person reaction limits (for example "one heart per person").
- Your IP address is used in memory for rate limiting and abuse control, and is stored only as a truncated keyed hash. The hashing key rotates daily and the previous key is destroyed after 48 hours, after which stored hashes can no longer be linked to any IP — by us or anyone else. The hash rows themselves are deleted after three days.
- Reaction records are kept against the random identifier, never a name or address, and are swept on a retention schedule (by default about 13 months). Aggregate counts — "this page has 421 hearts" — contain no personal data and are kept indefinitely.
- No cookies are set, and there is no cross-site tracking, advertising, or sale of data.
Our legal basis for this processing is legitimate interest: keeping counts honest and the service abuse-resistant, using the least data that achieves it.
2. Account holders — people who sign up
We store:
- Your email address and a hash of your password. The email is used to verify your account, reset passwords, and send transactional notices — usage alerts you've enabled, cap and billing notices, and replies to your support messages. No marketing lists.
- Your configuration and usage data: your Tapbars, uploaded icons, and daily reaction statistics — the product itself.
- Support email: if you write to us, the thread is kept in our support inbox, subject to periodic retention enforcement, and you can ask us to delete it.
Legal basis: performing our contract with you, and legal obligations for whatever billing records tax law requires us to keep.
3. Payments
Paid plans are sold through Paddle.com, our Merchant of Record. Paddle collects and processes your payment details, billing address, and tax information under Paddle's privacy policy; we never see your card number. Paddle tells us which account has which plan, which is all we need.
4. Where data lives
Tapback runs on Cloudflare's network (Cloudflare, Inc., our infrastructure sub-processor). Account and configuration data is stored in Cloudflare's distributed storage. Reaction data lives where the site owner chose when creating the Tapbar: the default placement, or pinned to the European Union. Signup uses Cloudflare Turnstile to filter bots, which processes the signup request under Cloudflare's privacy policy. Where processing happens outside the EEA, it is covered by the European Commission's standard contractual clauses in our providers' data processing terms.
5. Error and operations telemetry
When something breaks, we record an error report with the technical context needed to fix it. Reports are scrubbed of secrets and stored in our own infrastructure — there is no third-party analytics or error-tracking vendor. Operational metrics are sampled aggregates kept for three months.
6. Your rights
Under the GDPR you can ask for access to, correction of, export of, or deletion of your personal data, and object to or restrict processing. Email hello@tapback.party and we will respond within a month. Reaction data and configuration are also self-service: export runs from the console, one click, JSON or CSV. You can also complain to the Irish Data Protection Commission (dataprotection.ie) or your local supervisory authority.
A caveat on reader data: because reader records are pseudonymous and IP linkage is destroyed within 48 hours, we usually cannot tell which reaction rows are yours even if you ask — the design that protects you also prevents us from looking you up.
7. Changes
If this policy changes materially, we will email account holders before the change takes effect and update the date at the top.