1. Who we are
Tapped provides booking, client, calendar, team, payment-connection, and reporting tools for beauty and personal-service businesses. In this policy, “Tapped,” “we,” and “us” refer to the operator of tappedbooking.com and the Tapped web application.
2. Information we collect
We collect account information such as names, email addresses, phone numbers, authentication identifiers, and account roles. Shops may provide business names, contact details, addresses, operating hours, services, pricing, staff profiles, photos, and availability.
When customers book, we process appointment details, selected services and professionals, names, phone numbers, email addresses, notes, booking history, and payment status. We may also process waitlist preferences, product orders, notification subscriptions, approximate location or a location selected by the user, and technical information such as IP address, browser, device, and security logs.
Tapped does not store complete card numbers or card security codes. Payment details are tokenized and processed by the shop’s connected processor, such as Square or Clover. Stripe may process a shop’s Tapped subscription.
3. How we use information
We use information to create and secure accounts; provide booking, scheduling, client, team, reporting, discovery, notification, and payment-connection features; prevent duplicate or fraudulent activity; provide support; maintain and improve Tapped; enforce our agreements; and comply with legal obligations.
4. Shops and customer information
Each shop controls the client and appointment information it receives through its booking page. We make that information available to authorized shop owners and team members according to their permissions. Customers should contact the applicable shop about its services, appointments, refunds, and its own use of customer information.
5. When we share information
We share information only as needed to operate Tapped: with the shop a customer books; with authorized team members; with infrastructure, authentication, database, hosting, communications, analytics, and support providers; and with payment processors selected by the shop. Current service providers may include Supabase, Vercel, Google, Square, Clover, Stripe, and notification or email providers.
We may also disclose information to comply with law, protect users and Tapped, investigate fraud or security incidents, or as part of a merger, financing, acquisition, or sale of assets. We do not sell personal information for money.
6. Retention and security
When a verified account-deletion request is submitted, Tapped permanently deletes or de-identifies the account and associated personal data within 30 days. If the requester is the only owner of a shop, this includes the shop's Tapped appointments, client records, team access, services, products, reports, and stored payment-connection credentials.
Limited information may be retained longer when required by law, to establish or defend legal claims, prevent fraud or security abuse, or complete financial and tax obligations. Payment processors and other third parties retain information under their own policies, and encrypted backups may remain until they cycle out under our backup-retention schedule.
Before a deletion request, we retain information for as long as reasonably necessary to provide Tapped, maintain business and transaction records, resolve disputes, enforce agreements, and meet legal requirements. We use access controls, encryption in transit, restricted administrative credentials, and other safeguards, but no online service can guarantee absolute security.
7. Your choices and rights
You can update many account or shop details in Tapped, decline location and push-notification permissions, disconnect a payment processor, unsubscribe from optional communications, or schedule account deletion from Settings. A scheduled deletion can be cancelled from Settings before the 30-day deadline. Depending on where you live, you may have rights to access, correct, delete, restrict, or obtain a copy of personal information, or object to certain processing.
To make a privacy request, email Tappedbooking@gmail.com. We may need to verify your identity. Customers may also need to contact the shop that collected their booking information.
8. Children and international use
Tapped is not directed to children under 13, and children may not create shop accounts. Businesses are responsible for obtaining any consent required before entering information about a minor. Information may be processed in countries other than the country where it was collected, subject to appropriate legal safeguards.
9. Changes and contact
We may update this policy as Tapped changes. We will post the revised policy with a new effective date and provide additional notice when required. Questions can be sent to Tappedbooking@gmail.com.