1. Introduction
This Privacy Policy describes how OneTap (“we”, “us”, or “our”) collects, uses, and shares personal information when you use our digital business card platform and related services (the “Services”), accessible at https://onetap-card.com.
By using the Services, you acknowledge this Policy. If you do not agree, please do not use the Services.
Controller: OneTap
Address: Available upon request via privacy contact
Privacy & data protection inquiries: privacy@onetap-card.com
Data protection contact (where applicable): privacy@onetap-card.com
2. Data we collect
We collect information that you provide directly, automatically when you use the Services, and in some cases from third parties such as payment providers.
Account & authentication
- Contact and identity details (e.g., name, email address, username)
- Phone number where you choose to provide it
- Authentication data processed by our service providers (we do not store your password in plain text)
- Consent and preferences (e.g., marketing opt-in where offered; terms and privacy acknowledgement metadata at registration)
Profile & digital card content
- Profile and card configuration (sections, branding, links, social handles, downloadable assets)
- Media you upload or connect (e.g., images hosted via our media vendor)
- Public-facing content displayed to visitors who view your card
Lead capture & visitor interactions
- Information submitted through forms or flows on digital cards (e.g., name, email, phone, custom fields you configure)
- Associated metadata such as timestamps, card route or identifier, and technical context needed to operate lead features
Billing
- Subscription and checkout data processed by our payment partner (merchant of record). Typically includes billing status, receipts, customer identifiers, and limited payment metadata — not full payment card numbers on our infrastructure.
Usage & technical data
- Device and browser information, and general geographic region. Raw IP addresses are not stored in our application database; when IPs are needed for abuse prevention they are used in-memory (e.g. rate limits) or masked before durable logging.
- Diagnostics, logs, and security signals needed to operate, secure, and improve the Services
3. How we use data & legal bases (GDPR)
Depending on applicable law (including the GDPR where it applies), we rely on one or more of the following bases:
- Contract: to provide the Services you request (accounts, profiles, lead capture, analytics for account holders)
- Legitimate interests: to secure our systems, prevent abuse, troubleshoot, measure product performance at an aggregated level, and improve the Services — balancing these interests against your rights
- Consent: where required for optional communications (e.g. marketing email preferences). Product analytics for the authenticated dashboard are disclosed in this Policy and accepted with the Terms/Privacy acknowledgement at registration
- Legal obligation: to comply with laws, lawful requests, and corporate compliance duties (including retention of certain billing records)
4. Third-party services & subprocessors
We engage vendors that process personal information on our behalf or provide integrated functionality. These may include:
- Supabase — authentication, database, and storage services for accounts and application data
- Lemon Squeezy — payment processing and subscription management as merchant of record for paid plans
- Vercel — application hosting and related edge infrastructure for the web app (we do not load the Vercel Web Analytics SDK in this application)
- Cloudinary (or equivalent configured media CDN) — delivery and transforms for user-uploaded or linked imagery
- Resend (or equivalent email vendor) — transaction and operational emails such as verification and security notices
- PostHog — product analytics for the dashboard app, used to operate and improve the Services as disclosed in this Policy and accepted when you agree to the Terms and Privacy Policy at registration
This list may evolve as we onboard or replace subprocessors. We evaluate vendors for security and contractual safeguards appropriate to the risks involved.
5. First-party product analytics
We collect certain usage events through first-party pipelines (for example route or product interaction events submitted to protected application endpoints such as /api/analytics/events) and through PostHog on the dashboard app, to operate, secure, troubleshoot, and improve the Services.
By creating an account and accepting our Terms and this Privacy Policy, you acknowledge this product analytics processing. We do not use a separate in-app cookie banner for dashboard analytics. Cookie or tracking notices for anonymous visitors on our public marketing website are handled on that site.
Unless separately disclosed and consented where required by law, we do not integrate Google Analytics (GA4) or Meta / Facebook Pixel advertising technology as part of these Services. If our practices materially change in the future, we will update this Policy and notices as applicable.
6. Cookies & local storage
We use cookies and browser storage technologies in these classes:
- Strictly necessary — maintain secure sessions when you authenticate (Supabase auth cookies).
- Product / service analytics — PostHog product analytics (
localStoragepersistence), campaign attribution (UTM / click IDs inlocalStoragefor signup attribution), and limited first-party pageview beacons on app routes. These are part of operating the Services and are disclosed here; acceptance of the Terms and Privacy Policy at registration covers this processing for account holders.
You can control browser cookies via your browser settings. Blocking essential cookies may limit sign-in functionality. You can also clear site data for https://onetap-card.com in your browser settings. For questions about analytics or to object where applicable law allows, contact privacy@onetap-card.com.
7. International data transfers
We may process and store personal information in the United States, the European Economic Area, the United Kingdom, Israel, or other regions where our providers operate data centres. Laws in those jurisdictions may differ from your home jurisdiction.
Where GDPR applies and transfers leave the UK/EEA, we endeavor to rely on lawful transfer mechanisms such as adequacy decisions, Standard Contractual Clauses (“SCCs”), supplementary measures as appropriate, and vendor agreements that require equivalent protection. Obtain details or copies via privacy@onetap-card.com where mandated by law.
8. Retention
We keep personal information for as long as your account remains active or as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce terms.
When you request account deletion, we soft-delete your profile and owned cards and retain them for 30 days before hard purge (support restore only during that window). Public card URLs are deactivated immediately on soft-delete. Slugs remain locked during the retention window.
Exceptions: subscription and billing ledger records are retained as required for tax, accounting, and fraud prevention and are not cascade-deleted with account purge. Lead data associated with cards may remain available until you delete it or as otherwise described for CRM features, subject to legal holds and backup retention.
9. Security
We maintain administrative, technical, and organisational measures designed to safeguard personal information (including encryption in transit, access restrictions, separation of environments, vendor reviews). No transmission or storage method is fully secure — please use strong passwords and report suspected incidents to privacy@onetap-card.com.
10. Your GDPR rights
Where GDPR applies and we act as controller, you may:
- Access the personal information we hold about you
- Rectify inaccurate information
- Request erasure (“right to be forgotten”) subject to lawful exceptions (e.g., billing/legal holds)
- Request restriction of processing while we verify objections or rectify data
- Data portability for information you supplied that we process automatically by contract/consent where technically feasible
- Object to processing grounded in legitimate interests (including profiling when applicable)
- Withdraw consent where processing relied on consent (for example marketing emails), without affecting lawful processing beforehand. For product analytics covered by your registration acknowledgement, contact us to object where applicable law allows
- Lodge a complaint with your supervisory authority
To exercise rights email privacy@onetap-card.com with your request and verification details we require to protect your account data. We aim to respond within 30 days where GDPR applies.
11. Your CCPA / CPRA rights
If California law applies (CCPA / CPRA as amended), you may request to know/access, delete, or correct categories and specific pieces of personal information we collected, and to opt out of sale or certain sharing for cross-context behavioural advertising.
We do not sell personal information for money, and we do not share personal information for cross-context behavioural advertising as those terms are commonly defined. If practices change materially, we will update this disclosure and notices as legally required.
You may designate an authorised agent consistent with regulation; we verify requests to deter fraud. Contact privacy@onetap-card.com to submit a request. We aim to respond within 45 days where CCPA applies (extendable as permitted by law).
12. Israel Privacy Protection Authority expectations
Pursuant to the Israeli Privacy Protection Act and related regulation, individuals may request access to databases containing their personal information, request corrections, and seek information about how data flows to third parties. We provide clear contact channels noted above and limit collection to lawful, transparent purposes communicated in this Policy.
Residents may contact privacy@onetap-card.com regarding rights and complaints. Guidance from the IPA may apply to lawful processing justification and onward transfer controls.
13. Children
The Services are not directed toward children under 16. We do not knowingly collect personal information from children. If you believe we received such data inadvertently, notify us promptly at privacy@onetap-card.com for deletion.
14. Changes to this policy
We may update this Policy materially as our Services evolve or legal requirements shift. We will post the updated version on this page and revise the “Last updated” date. Where mandated, we’ll provide additional notice before changes take effect.
15. Contact us
Privacy questions — privacy@onetap-card.com
Website — https://onetap-card.com