← Tap-to-It

Privacy Policy

Last updated: not yet published.

TODO: review by a lawyer. The data inventory below reflects what Tap-to-It actually stores today. The surrounding legal framing (your rights, our obligations, how disputes are handled) is a structural placeholder and must not be treated as final until reviewed for the Australian Privacy Act and any other jurisdiction Tap-to-It operates in.

What we collect, and why

  • Guest ordering a table's bill: nothing that identifies you is required to order or pay. If you choose to add an email to receive a copy of your receipt, that's stored against the bill.
  • Guest requesting assistance (water, cutlery, the bill) from the table screen: only the table and request type — no personal details.
  • Venue owner/staff: the email used to sign in (via Supabase Auth), and for floor/kitchen staff using a shared-terminal PIN, a name and a hashed PIN — never the PIN itself in readable form.
  • Venue owner phone verification: a mobile number and a short-lived one-time code, used once to confirm the owner controls that number.
  • Payments: card details never reach Tap-to-It's servers. TODO once live processors are connected: confirm this statement still holds for both Stripe (Payment Element, tokenised client-side) and Square (Web Payments SDK, tokenised client-side) — it's the intended architecture, not yet live.

How long we keep it

A paid bill is a tax invoice. Australian tax law requires businesses to keep records like this for five years, so Tap-to-Itretains bill, payment and receipt data — including any name, phone or email attached to it — for at least that long on the Venue's behalf, even if the Venue later asks for their account to be closed.

Everything else (an assistance request, an unpaid draft order) is only kept as long as it's useful for running the venue.

Where it's stored

Tap-to-It's database and file storage run on Supabase, hosted in Australia (ap-southeast-2). TODO: confirm and state this precisely once infrastructure is finalised, including any subprocessor (email, payment providers) that sees a slice of this data to do its job (Resend for email, Stripe/Square for payments).

Your rights

TODO: Australian Privacy Act rights (access, correction) and how a Venue owner or a Guest exercises them — see Support in the meantime. A Venue owner can request an export or deletion of their venue's account data from Settings in the dashboard.

Changes to this policy

TODO: how Venues and Guests are notified of material changes.