Tapinion Privacy Policy
Last updated: 11 September 2026
This policy covers Tapinion — NFC stickers that redirect to a Google review screen, plus an optional dashboard with scan analytics. It covers, separately, businesses using the service and people who tap a sticker at such a business.
Who is responsible for the data
The data controller is SG Software Development (Szymon Gaweł), based in Poland. For any privacy question, contact tapinion@sgsoftware.pl.
People tapping a sticker
We generally do not collect personal data from people who tap their phone on an NFC Review sticker — the sticker simply redirects to the review page run by Google LLC, whose own privacy policy then applies and is outside our control. The dashboard used by the business shows only aggregate scan counts over time (and, with named tags, which sticker/employee a scan belongs to) — it does not identify the person who scanned.
Data from business customers
Businesses using the stickers and dashboard provide us with:
| Data | Why | Legal basis (GDPR Art. 6) |
|---|---|---|
| Contact and dashboard account details (email, password as a hash) | Dashboard access and communication about the service | Performance of a contract — Art. 6(1)(b) |
| Company and billing details (name, tax ID, address) | Order fulfilment and invoicing | Contract and legal obligation — Art. 6(1)(b) and (c) |
| Scan statistics (count, time, tag) | Displaying analytics in the dashboard | Performance of a contract — Art. 6(1)(b) |
| IP address, request metadata and server logs | Security, abuse prevention and debugging | Legitimate interest — Art. 6(1)(f) |
Who we share data with
We share data only with service providers needed to run Tapinion, under data processing agreements — including our hosting provider and our payment processor for subscriptions. We provide the specific list of providers on request. We may also disclose data where required by law.
How long we keep data
- Business account data — kept for the duration of the relationship, and afterwards for as long as tax and accounting rules require.
- Scan statistics — kept for the duration of the dashboard subscription; deleted or anonymised within a reasonable time after it ends.
- Server logs — typically 30–90 days.
Your rights
If you represent a business using Tapinion, you have the right to access, correct, delete, restrict or object to processing of your data, and to receive it in a portable form. Contact tapinion@sgsoftware.pl.
If you believe we have handled data unlawfully, you may lodge a complaint with your local supervisory authority. In Poland this is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.
Security
Dashboard passwords are stored only as salted hashes. Data is encrypted in transit with TLS. Access to production systems is limited to what is needed to operate the service.
Changes to this policy
We may update this policy. The “Last updated” date always reflects the current version; we will notify business customers by email of material changes.
Contact
SG Software Development (Szymon Gaweł) — tapinion@sgsoftware.pl