Legal
Privacy Policy
Last updated: July 3, 2026
The short version: We collect only what we need to run Tappa, and we process it under the NDPR, the Nigeria Data Protection Act 2023, and the GDPR. We never sell your data. Your public profile shows only what you choose to share. You can access, correct, export, or delete your data at any time.
1. Who we are and about this policy
Tappa ("Tappa", "we", "our", or "us") provides an NFC-based digital business card and networking service through the Tappa mobile application and the tappa.me website (together, the "Service"). Tappa is the "data controller" responsible for the personal data described in this policy.
This Privacy Policy explains how we collect, use, share, and protect your personal data, and the rights you have. We are committed to processing your data lawfully, fairly, and transparently.
We comply with the Nigeria Data Protection Act 2023 (the "NDPA") and the Nigeria Data Protection Regulation 2019 (the "NDPR"), and, where they apply to you, the EU General Data Protection Regulation (the "GDPR") and the UK GDPR. If you do not agree with this policy, please stop using the Service.
Questions or requests about your data can be sent to fixit@tappa.me or via tappa.me/contact.
2. Personal data we collect
Information you provide directly: • Account data: your name, email address, and a password (which we store only in hashed form via our authentication provider). • Profile data: job title, company, phone number, website, social and payment links, username, profile photo, and banner image that you choose to add. • NFC device data: the names, types, and tag identifiers you assign to the NFC cards, rings, stickers, or tags you register. • Payment data: when you subscribe or shop on the web, payment is processed by Paystack; on mobile, by the Apple App Store or Google Play. We receive transaction status, plan, and limited billing metadata. We never receive or store full payment card numbers. • Support and communications: messages you send us through the in-app support chat (including our AI assistant), the contact form, or email.
Information collected automatically: • Usage data: features you use, screens you visit, profile view counts, and NFC tap counts associated with your account. • Device and technical data: device type, operating system and app version, access times, error and log data, and IP address. • Security data: a bot-protection token generated by Google reCAPTCHA on the website. • Push notification tokens, if you enable notifications.
NFC data: We read NFC tags only when you actively initiate a scan within the app. We never read NFC data in the background. Content you scan is processed on your device to display results and is not transmitted to us unless you take an action on it (such as opening a Tappa profile).
3. Lawful bases for processing
Under the NDPA, NDPR, and (where applicable) the GDPR, we only process your personal data where we have a lawful basis to do so:
• Performance of a contract: to create and manage your account, display your public profile, and provide the features you request. • Consent: for optional activities such as marketing emails, push notifications, and choosing which profile fields to make public. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out. • Legitimate interests: to secure the Service, prevent fraud and abuse, debug problems, and improve our features, balanced against your rights and freedoms. • Legal obligation: to comply with applicable law, tax, accounting, and lawful requests from authorities.
We do not carry out solely automated decision-making that produces legal or similarly significant effects on you. Where we process the data of a child or any sensitive category of data, we rely on explicit consent (including verifiable parental or guardian consent for minors).
4. How we use your personal data
We use your personal data to: • Create, secure, and manage your account and profile. • Display your public profile when someone views your Tappa link or taps your NFC device. • Provide analytics on profile views and NFC device taps. • Process subscriptions and shop orders (via Paystack, Apple, or Google). • Provide customer support, including responding through our AI assistant and human team. • Send transactional messages (verification, password reset, receipts, security notices). • Send optional product updates and marketing, where you have consented. • Detect, prevent, and investigate fraud, abuse, and security incidents. • Improve the Service through aggregated, and where possible anonymised, analytics. • Comply with our legal obligations.
We do not sell your personal data, and we do not use it for third-party or cross-context behavioural advertising.
5. Service providers and international data transfers
We share personal data only with the service providers ("data processors") that help us run the Service, under contracts that require them to protect your data and use it only on our instructions:
• Google Firebase / Google Cloud (Google LLC / Google Ireland): authentication, database (Cloud Firestore), file storage, push messaging, and reCAPTCHA. • Vercel Inc.: hosting of the tappa.me website. • Paystack: payment processing for web subscriptions and shop orders. • Apple App Store and Google Play: subscription billing on mobile. • Resend: sending transactional and account emails. • Anthropic (Claude): powering our AI support assistant. When you use the support chat, the content of your messages is processed to generate a reply. Please do not share sensitive personal data in the chat.
Some of these providers are located outside Nigeria and the European Economic Area (for example, in the United States). When we transfer personal data across borders, we rely on a lawful transfer mechanism, such as an adequacy decision, Standard Contractual Clauses, the provider's binding data protection commitments, or your explicit consent, so that your data continues to be protected to NDPA and GDPR standards.
We may also disclose personal data where required by law, to enforce our Terms, or to protect the rights, safety, and property of Tappa, our users, or the public.
6. Your public profile
When you create a Tappa profile, the fields you choose to make public (such as name, photo, job title, company, contact details, and links) become publicly accessible at your profile URL (tappa.me/yourusername).
You control what appears on your public profile. You can update or remove any field at any time from within the app, and you can set different visibility for individual NFC devices. Removing a field removes it from your public profile immediately.
Your profile URL may be indexed by search engines. If you delete your account, your profile is removed and the URL becomes unavailable, although cached copies may persist briefly in third-party search indexes outside our control.
7. Cookies and similar technologies
The tappa.me website uses only strictly necessary cookies and local storage, for example to keep you signed in, to secure forms (reCAPTCHA), to remember a referral code, and to store your cookie choices. We do not use advertising cookies or cross-site tracking pixels. Analytics and marketing cookies are opt-in and off by default; if we ever introduce them, they will run only after you allow them. See our Cookie Policy at tappa.me/cookies for the full list, and use the "Cookie preferences" control in the footer to review or change your choices at any time.
You can control or delete cookies through your browser settings. Disabling strictly necessary cookies may prevent parts of the Service from working.
8. Data retention
We retain your account and profile data for as long as your account is active. If you delete your account, we delete your profile data, uploaded images, and associated analytics within 30 days, except where we are required to retain certain records (for example, transaction records for tax and accounting) for the period required by law.
Support messages are retained for as long as needed to resolve your query and for a reasonable period afterwards. Log and security data is retained for up to 90 days. Aggregated or anonymised statistics that cannot identify you may be retained for service improvement.
9. Your data protection rights
Subject to the conditions and exemptions in the NDPA, NDPR, and (where applicable) the GDPR, you have the right to:
• Access: obtain confirmation of, and a copy of, the personal data we hold about you. • Rectification: have inaccurate or incomplete data corrected. • Erasure: request deletion of your account and associated data ("right to be forgotten"). • Restriction: ask us to limit how we process your data in certain circumstances. • Portability: receive your data in a structured, commonly used, machine-readable format. • Objection: object to processing based on our legitimate interests, and to direct marketing at any time. • Withdraw consent: withdraw any consent you have given, at any time.
To exercise any of these rights, email fixit@tappa.me. We may need to verify your identity, and we will respond within 30 days (extendable where the law permits). Exercising your rights is free unless the request is manifestly unfounded or excessive.
You also have the right to lodge a complaint with a supervisory authority. In Nigeria, this is the Nigeria Data Protection Commission (NDPC). In the EEA or UK, you may complain to your local data protection authority (in the UK, the Information Commissioner's Office).
10. Children's privacy
The Service is intended for users aged 16 and over. Where you are below the age of digital consent that applies in your country (but at least 13), you may use Tappa only with the verifiable consent of a parent or guardian. Under the NDPA, a child is a person under 18, and the processing of a child's data requires parental or guardian consent.
We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data without the required consent, contact us at fixit@tappa.me and we will delete it promptly.
11. How we protect your data
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, loss, or destruction. These include encryption of data in transit (TLS), database access controls (Firebase Security Rules), hashed credential storage, least-privilege access for our team, and optional two-factor authentication on your account.
No method of transmission or storage is completely secure. While we work hard to protect your data, we cannot guarantee absolute security, and you are responsible for keeping your password confidential.
12. Data breach notification
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Nigeria Data Protection Commission (and, where the GDPR applies, the relevant supervisory authority) without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to you, we will also notify you without undue delay.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through an in-app or on-site notice. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
14. Contact us
If you have questions about this Privacy Policy, wish to exercise your rights, or want to reach our data protection contact, please contact us:
Email: fixit@tappa.me Website: tappa.me/contact
Supervisory authority (Nigeria): Nigeria Data Protection Commission (NDPC), ndpc.gov.ng.
We aim to acknowledge privacy enquiries within 5 business days and to resolve them within the timeframes required by law.