Privacy Policy

Last updated: September 7, 2026

Back to home

1. Introduction

This Privacy Policy describes how onetap-card.com (“we”, “us”, or “our”) collects, uses, and shares personal information when you use our digital business card platform and related services (the “Services”), accessible at https://onetap-card.com and https://app-dev.onetap-card.com.

By using the Services, you acknowledge this Policy. If you do not agree, please do not use the Services.

Data controller: onetap-card.com | app-dev.onetap-card.com
Registered address: TLV, IL.
Privacy & data protection inquiries: privacy@onetap-card.com
Data protection contact (where applicable): privacy@onetap-card.com

2. Data we collect

We collect information that you provide directly, automatically when you use the Services, and in some cases from third parties such as payment providers.

Account & authentication

  • Contact and identity details (e.g., name, email address, username)
  • Phone number where you choose to provide it
  • Authentication data processed by our service providers (we do not store your password in plain text)
  • Consent and preferences (e.g., marketing opt-in where offered; terms and privacy acknowledgement metadata at registration)

Profile & digital card content

  • Profile and card configuration (sections, branding, links, social handles, downloadable assets)
  • Media you upload or connect (e.g., images hosted via our media vendor)
  • Public-facing content displayed to visitors who view your card

Lead capture & visitor interactions

  • Information submitted through forms or flows on digital cards (e.g., name, email, phone, custom fields you configure)
  • Associated metadata such as timestamps, card route or identifier, and technical context needed to operate lead features

Controller vs. processor for lead data:
When you use OneTap to collect leads or contact details from visitors of your digital cards, you determine the purposes and means of that processing. In this context, you are the data controller and OneTap acts as a data processor on your behalf, providing the technical platform to capture, store, and manage those leads.

Billing

  • Subscription and checkout data processed by our payment partner (merchant of record). Typically includes billing status, receipts, customer identifiers, and limited payment metadata — not full payment card numbers on our infrastructure.

Usage & technical data

  • Device and browser information, and general geographic region. Raw IP addresses are not stored in our application database; when IPs are needed for abuse prevention they are used in-memory (e.g. rate limits) or masked before durable logging.
  • Diagnostics, logs, and security signals needed to operate, secure, and improve the Services

Marketing & communications

  • When you opt in, we may send product updates, newsletters, and promotional content via email. You can unsubscribe at any time via the link in the email or in Account Settings → Notifications.
  • UTM parameters and click IDs stored in localStorage for signup attribution and campaign measurement.

Depending on applicable law (including the GDPR where it applies), we rely on one or more of the following bases:

  • Contract: to provide the Services you request (accounts, profiles, lead capture, analytics for account holders)
  • Legitimate interests: to secure our systems, prevent abuse, troubleshoot, measure product performance at an aggregated level, and improve the Services — balancing these interests against your rights
  • Consent: where required for optional communications (e.g. marketing email preferences). Product analytics for the authenticated dashboard are disclosed in this Policy and accepted with the Terms/Privacy acknowledgement at registration. For users in the EEA/UK, where local law requires opt-in consent for non-essential cookies or analytics, we will present a cookie preference interface before loading such technologies in the app. Until then, dashboard analytics are operated under legitimate interests with an easy objection mechanism via privacy@onetap-card.com.
  • Legal obligation: to comply with laws, lawful requests, and corporate compliance duties (including retention of certain billing records)

4. Third-party services & subprocessors

We engage vendors that process personal information on our behalf or provide integrated functionality. These may include:

  • Supabase — authentication, database, and storage services for accounts and application data
  • Lemon Squeezy — payment processing and subscription management as merchant of record for paid plans
  • Vercel — application hosting and related edge infrastructure for the web app (we do not load the Vercel Web Analytics SDK in this application)
  • Cloudinary (or equivalent configured media CDN) — delivery and transforms for user-uploaded or linked imagery
  • Resend (or equivalent email vendor) — transaction and operational emails such as verification and security notices
  • PostHog — product analytics for the dashboard app, used to operate and improve the Services as disclosed in this Policy and accepted when you agree to the Terms and Privacy Policy at registration

This list may evolve as we onboard or replace subprocessors. We evaluate vendors for security and contractual safeguards appropriate to the risks involved.

5. First-party product analytics

We collect certain usage events through first-party pipelines (for example route or product interaction events submitted to protected application endpoints such as /api/analytics/events) and through PostHog on the dashboard app, to operate, secure, troubleshoot, and improve the Services.

By creating an account and accepting our Terms and this Privacy Policy, you acknowledge this product analytics processing. We do not use a separate in-app cookie banner for dashboard analytics. Cookie or tracking notices for anonymous visitors on our public marketing website are handled on that site.

Unless separately disclosed and consented where required by law, we do not integrate Google Analytics (GA4) as part of these Services.

After you create an account, we load the Meta / Facebook Pixel and send hashed conversion events to Meta's Conversions API so we can measure and improve ads on Facebook and Instagram. Event parameters do not include your email, phone, or name; Meta receives a hashed identifier for matching. Anonymous visitors on our marketing website see a cookie banner before any Meta Pixel loads there.

Advertising measurement opt-out:
You can disable advertising measurement in your Account Settings → Privacy → “Allow advertising measurement (Meta Pixel & Conversions API)”. Disabling this will stop future events from being sent to Meta. If you do not have access to this setting or prefer to contact us, email privacy@onetap-card.com.

6. Cookies & local storage

We use cookies and browser storage technologies in these classes:

  • Strictly necessary — maintain secure sessions when you authenticate (Supabase auth cookies).
  • Product / service analytics — PostHog product analytics (localStorage persistence), campaign attribution (UTM / click IDs in localStorage for signup attribution), limited first-party pageview beacons on app routes, and Meta Pixel cookies (_fbp / _fbc) after registration when ads measurement is enabled. These are disclosed here; acceptance of the Terms and Privacy Policy at registration covers this processing for account holders.
  • Marketing — Meta Pixel cookies for conversion measurement and ad optimization after registration, unless disabled in your Account Settings.

You can control browser cookies via your browser settings. Blocking essential cookies may limit sign-in functionality. You can also clear site data for https://onetap-card.com in your browser settings. For questions about analytics or to object where applicable law allows, contact privacy@onetap-card.com.

7. International data transfers

We may process and store personal information in the United States, the European Economic Area, the United Kingdom, IL, or other regions where our providers operate data centres. Laws in those jurisdictions may differ from your home jurisdiction.

Our core infrastructure providers (including Supabase, Vercel, PostHog, Cloudinary, and Resend) operate data centres primarily in the United States and the European Economic Area. Where personal data is transferred from the EEA or UK to countries without an adequacy decision, we rely on EU/UK Standard Contractual Clauses together with supplementary technical measures (such as encryption in transit and access controls).

Obtain details or copies via privacy@onetap-card.com where mandated by law.

8. Retention

We keep personal information for as long as your account remains active or as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce terms.

When you request account deletion, we soft-delete your profile and owned cards and retain them for 30 days before hard purge (support restore only during that window). Public card URLs are deactivated immediately on soft-delete. Slugs remain locked during the retention window.

Exceptions: subscription and billing ledger records are retained as required for tax, accounting, and fraud prevention and are not cascade-deleted with account purge. Lead data associated with cards may remain available until you delete it or as otherwise described for CRM features, subject to legal holds and backup retention.

9. Security

We maintain administrative, technical, and organisational measures designed to safeguard personal information (including encryption in transit, access restrictions, separation of environments, vendor reviews). No transmission or storage method is fully secure — please use strong passwords and report suspected incidents to privacy@onetap-card.com.

10. Your GDPR rights

Where GDPR applies and we act as controller, you may:

  • Access the personal information we hold about you
  • Rectify inaccurate information
  • Request erasure (“right to be forgotten”) subject to lawful exceptions (e.g., billing/legal holds)
  • Request restriction of processing while we verify objections or rectify data
  • Data portability for information you supplied that we process automatically by contract/consent where technically feasible
  • Object to processing grounded in legitimate interests (including profiling when applicable)
  • Withdraw consent where processing relied on consent (for example marketing emails), without affecting lawful processing beforehand. For product analytics covered by your registration acknowledgement, contact us to object where applicable law allows
  • Lodge a complaint with your supervisory authority

To exercise rights email privacy@onetap-card.com with your request and verification details we require to protect your account data. We aim to respond within 30 days where GDPR applies.

11. Your CCPA / CPRA rights

If California law applies (CCPA / CPRA as amended), you may request to know/access, delete, or correct categories and specific pieces of personal information we collected, and to opt out of sale or certain sharing for cross-context behavioural advertising.

We do not sell personal information for money, and we do not share personal information for cross-context behavioural advertising as those terms are commonly defined. If practices change materially, we will update this disclosure and notices as legally required.

You may designate an authorised agent consistent with regulation; we verify requests to deter fraud. Contact privacy@onetap-card.com to submit a request. We aim to respond within 45 days where CCPA applies (extendable as permitted by law).

12. IL Privacy Protection Authority expectations

Pursuant to the IL Privacy Protection Act, 5741-1981, and related regulation, individuals may request access to databases containing their personal information, request corrections, and seek information about how data flows to third parties. We provide clear contact channels noted above and limit collection to lawful, transparent purposes communicated in this Policy.

Under the IL Privacy Protection Act, individuals have the right to request access to their personal information held in our databases, to request correction, and to be informed about the purposes of processing and recipients of their data. Where applicable, we maintain registrations with the IL Privacy Protection Authority as required by law.

Residents may contact privacy@onetap-card.com regarding rights and complaints. Guidance from the IPA may apply to lawful processing justification and onward transfer controls.

13. Children

The Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. In jurisdictions where the age of digital consent is lower, the minimum age is that specified by local law.

If you believe we received such data inadvertently, notify us promptly at privacy@onetap-card.com for deletion.

14. Changes to this policy

We may update this Policy materially as our Services evolve or legal requirements shift. We will post the updated version on this page and revise the “Last updated” date. Where mandated, we'll provide additional notice before changes take effect.

15. Contact us

Privacy questions: privacy@onetap-card.com
Website: https://onetap-card.com
App (Dashboard): https://app-dev.onetap-card.com