Legal

Privacy notice

Updated 28 September 2026

Who the Data Fiduciary is

TAPSYNC processes digital personal data to run NFC + QR cards and stands in India, and the free profile at tapsync.in/p/. GSTIN 10AANCT6567F1Z7. Contact for this notice, rights and grievances: hello@tapsync.in.

This page is the standalone notice. It is written in English. If you need it in another Eighth Schedule language, write to that address and we will send it.

What we collect, and why

We only collect what the product needs. Each row is a purpose. We do not sell this data. We do not run ads on the public page.

  • Account — email and password, so you can sign in and manage TAPSYNC.
  • Profile — name, title, photo, phone, location, and the connections you add (WhatsApp, Instagram, website, Google and the rest), so the public page and the tap open what you set.
  • Orders — name, email, phone, shipping address, optional GSTIN, and the card or stand configuration, so we can encode, ship and invoice.
  • Smart Wi-Fi — network name (SSID) and the password you type at checkout or in the dashboard, so we can encode the face. The password is not stored in the browser cart. A guest join does not hit TAPSYNC servers — the phone reads the chip or QR.
  • Support — whatever you write to hello@tapsync.in, so we can answer.
  • Session cookies — so you stay signed in. Required for account, dashboard and checkout. No marketing or analytics pixel. Cookies.

Who a tap does not collect

We do not put an app on the other person’s phone. We do not log who tapped you. Their browser or the app they already have opens. Do not put secrets on the public TAPSYNC page — anyone with the link, QR or a tap can open it.

Who we use to run this

Account and order data sit in India on Supabase (ap-south-1). The site is hosted on Vercel. Mail to hello@tapsync.in is forwarded by ImprovMX. They process data only to run TAPSYNC — sign-in, the database, the page, and mail. We do not hand your profile to an ad network.

How long we keep it

Profile and account stay until you ask us to erase them, or you delete what you can from the dashboard. Order, GST and shipping records stay as long as Indian tax and delivery law needs them. Wi-Fi passwords stay only while we need them to encode or re-encode that object.

Your rights

You can ask for a copy of your personal data, a correction, an update, or erasure — write to hello@tapsync.in from the email on the account. You can withdraw consent the same way: that address, or by deleting connections and profile fields yourself. Withdrawal does not unwind a card we already encoded and shipped.

We will answer a grievance at that address. If you are not satisfied, you may complain to the Data Protection Board of India once that channel is open for your case.

Children

TAPSYNC is not for anyone under 18. We do not knowingly take an account from a child. If one was created, write to hello@tapsync.in and we will delete it.

Security

Sign-in is through Supabase Auth. The public page is public by design. Wi-Fi passwords are stored for encoding, not shown in the cart. If we become aware of a personal-data breach, we will write to affected accounts and, when the Rules require it, to the Board.

Questions — write to hello@tapsync.in. Also see About, NFC cards in India, Privacy, Terms and Shipping, Returns, Help.