Tapinion
Privacy Policy

Tapinion Privacy Policy

Last updated: 11 September 2026

This policy covers Tapinion — NFC stickers that redirect to a Google review screen, plus an optional dashboard with scan analytics. It covers, separately, businesses using the service and people who tap a sticker at such a business.

Who is responsible for the data

The data controller is SG Software Development (Szymon Gaweł), based in Poland. For any privacy question, contact tapinion@sgsoftware.pl.

People tapping a sticker

We generally do not collect personal data from people who tap their phone on an NFC Review sticker — the sticker simply redirects to the review page run by Google LLC, whose own privacy policy then applies and is outside our control. The dashboard used by the business shows only aggregate scan counts over time (and, with named tags, which sticker/employee a scan belongs to) — it does not identify the person who scanned.

Data from business customers

Businesses using the stickers and dashboard provide us with:

DataWhyLegal basis (GDPR Art. 6)
Contact and dashboard account details (email, password as a hash)Dashboard access and communication about the servicePerformance of a contract — Art. 6(1)(b)
Company and billing details (name, tax ID, address)Order fulfilment and invoicingContract and legal obligation — Art. 6(1)(b) and (c)
Scan statistics (count, time, tag)Displaying analytics in the dashboardPerformance of a contract — Art. 6(1)(b)
IP address, request metadata and server logsSecurity, abuse prevention and debuggingLegitimate interest — Art. 6(1)(f)

Who we share data with

We share data only with service providers needed to run Tapinion, under data processing agreements — including our hosting provider and our payment processor for subscriptions. We provide the specific list of providers on request. We may also disclose data where required by law.

How long we keep data

  • Business account data — kept for the duration of the relationship, and afterwards for as long as tax and accounting rules require.
  • Scan statistics — kept for the duration of the dashboard subscription; deleted or anonymised within a reasonable time after it ends.
  • Server logs — typically 30–90 days.

Your rights

If you represent a business using Tapinion, you have the right to access, correct, delete, restrict or object to processing of your data, and to receive it in a portable form. Contact tapinion@sgsoftware.pl.

If you believe we have handled data unlawfully, you may lodge a complaint with your local supervisory authority. In Poland this is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.

Security

Dashboard passwords are stored only as salted hashes. Data is encrypted in transit with TLS. Access to production systems is limited to what is needed to operate the service.

Changes to this policy

We may update this policy. The “Last updated” date always reflects the current version; we will notify business customers by email of material changes.

Contact

SG Software Development (Szymon Gaweł) tapinion@sgsoftware.pl