Tap4Go · Bimbiamore LLC
Privacy Notice
This Notice explains how Bimbiamore LLC processes personal data in Tap4Go and how to exercise privacy rights. It applies to visitors, customers, account users, people identified on hosted business cards and people who send contact requests.
1. Controller and contact
Bimbiamore LLC, 30N South Gould Street, Ste N, Sheridan, WY 82801, USA is the controller for accounts, orders, service administration, security, support and Tap4Go’s own analytics. Email privacy requests to info@tap4go.com with the subject “Privacy Request”. For a lead sent through a hosted page, the page owner shown by that page normally controls the follow-up use and Tap4Go acts as its processor. For user-uploaded information about other people, the account user normally determines the purpose and must provide the required notice and lawful basis.
2. Data we process
- Account and authentication: email, language, user ID, verification status, login time, role and permissions; a one-way bcrypt password hash (never the readable password); hashed verification/reset tokens, token expiry and use time; session identifiers and CSRF tokens.
- Orders and support: name, email, phone, billing and delivery address, order/product details, tax and payment status, last four card digits where supplied by Stripe, returns, messages and support history. Full card data is entered with Stripe and is not stored by Tap4Go.
- NFC and pages: NFC/tag identifier, activation and binding records, page ID and public slug, page title, settings, HTML/editor data, publication and consent records.
- Business/contact profile data: names, prefix, nickname, professional photograph, company, title, role, phone numbers, emails, website, business addresses, social links, professional notes, QR/vCard data and uploaded backgrounds.
- Contact requests: name, email, phone, message, source page/tag, language, time, page owner, referrer, browser/user-agent and a pseudonymised IP hash.
- Technical and security: IP address in transient hosting/security logs and rate-limit processing, purpose-specific IP hashes where documented, consent and language choices, necessary session ID, request time, page/path, referrer and browser/user-agent data in ordinary restricted server logs.
- First-party aggregate interaction statistics: account/card/tag ID, calendar date, event category (visit, NFC scan, phone, email, website, map, save-contact, contact-form or other content click), social-network category, coarse country code and device class. New events are added directly to daily counters. Tap4Go does not store the visitor IP or IP hash, session identifier, full user-agent, city, referrer, destination URL or contact value in these counters.
- Optional Google Analytics: if configured and accepted, Google may process users, sessions, approximate location, browser/device data and events as described in the Cookie Notice.
- Legal evidence: accepted document versions, timestamp, context, user ID and pseudonymised email/IP hashes and user-agent.
3. Sources
We receive data directly from you, from an account user who creates or manages a business-card page, automatically from your device and hosting/security infrastructure, from Stripe during payment, and from a page owner to whom you submit a request. If someone publishes your data without authority, contact us immediately.
4. Purposes and legal bases
| Purpose | GDPR basis |
|---|---|
| Create, verify and secure accounts; activate NFC; host pages; deliver orders; respond to requested support. | Contract and steps requested before contract (Art. 6(1)(b)); legitimate interests in reliable service and fraud prevention (Art. 6(1)(f)). |
| Invoices, tax, accounting, sanctions, lawful requests and legal claims. | Legal obligation (Art. 6(1)(c)); legitimate interests in establishing and defending claims (Art. 6(1)(f)). |
| Publish profile content selected by the user. | Contract for the account holder; consent where the account holder publishes their own optional personal data; the publishing user must establish the basis for third-party data. |
| Transmit a contact request to the chosen page owner. | Your affirmative request and steps taken at your request (Art. 6(1)(b)); consent where required (Art. 6(1)(a)). |
| Security logs, rate limits, abuse prevention and audit. | Legitimate interests in protecting users and systems (Art. 6(1)(f)); legal obligations where applicable. |
| Produce first-party daily aggregate counts of business-card visits, scans and interactions, detect obvious bots and protect event ingestion. No analytics cookie or visitor identifier is used for the counters. | Legitimate interests in measuring and improving the requested business-card service and providing card owners with performance totals (Art. 6(1)(f)), subject to minimisation and the right to object. |
| Google Analytics and optional third-party measurement. | Your consent (Art. 6(1)(a)) and applicable ePrivacy consent. Google Analytics does not load before consent. |
5. Public information and page owners
Published business cards are accessible to anyone with the URL or NFC tag. Recipients may copy or redistribute the information beyond our control. Account users must minimise data, keep it accurate and obtain authority from every person identified. Do not publish health, child, government-identity or other sensitive data: the current Service is not designed for it. A page owner receiving a contact request may use it to respond and is independently responsible for any later CRM, marketing or sharing.
6. Recipients and service providers
Data may be available to the selected page owner; authorised Bimbiamore personnel and contractors under confidentiality; Hostinger for hosting, database, backups and SMTP email; Stripe for payments and fraud prevention; Google for consented Analytics and consented YouTube content; advisers, insurers, acquirers and authorities where lawfully necessary. Details and provider links appear in our Subprocessor List. We do not sell personal data. We do not share personal data for cross-context behavioural advertising as those terms are defined by applicable US state law. We do not use sensitive data for advertising.
7. International transfers
Bimbiamore is established in the United States and service providers may process data in the United States, EEA and other locations. Where Chapter V GDPR or similar transfer rules apply, we use an adequacy decision, applicable Data Privacy Framework participation, Standard Contractual Clauses, a UK Addendum, provider DPA or another lawful mechanism, together with supplementary safeguards where appropriate. Hostinger’s DPA incorporates the 2021 EU SCCs for covered transfers and its UK transfer addendum. You may request information about the relevant safeguard.
8. Retention
- Account and hosted content: while active, then normally deleted from live systems within 30 days after a verified deletion request, subject to legal holds; rolling backups may persist up to 90 days.
- Orders, invoices, tax and payment records: up to 7 years or the longer period required by applicable law.
- Legal acceptance records: 7 years after account termination or the relevant transaction.
- Unused verification/reset tokens: up to 30 days after expiry; security/rate-limit records: normally up to 12 months.
- First-party daily aggregate interaction counters: 14 months. Google Analytics retention follows the configured Google property settings.
- Contact requests: up to 24 months unless the page owner deletes them earlier or law/claims require longer.
- Support communications: normally 24 months after closure; active disputes and abuse evidence for the limitation period.
These periods may be shortened by deletion or extended only for a documented legal obligation, security investigation or legal claim. We anonymise data where feasible when identifiable data is no longer needed.
9. Security
We use TLS in transit; infrastructure encryption at rest represented by Hostinger; bcrypt password hashing; one-way token and IP hashing; secure, HttpOnly, SameSite session cookies; session rotation; CSRF protection; prepared database statements; role-based access; rate limiting; upload validation and re-encoding; content sanitisation; backups and restricted administrative access. Hashing is pseudonymisation, not encryption, and authorised systems may need readable access to profile and contact data to provide the Service. No system is risk-free. See Security & Trust.
10. Your rights
Depending on location, you may request access, correction, deletion, restriction, portability, objection, withdrawal of consent, and information about recipients or transfers. EEA/UK users may complain to their local supervisory authority. Applicable US state laws may provide rights to know/access, correct, delete and obtain a portable copy, and to opt out of sale, sharing, targeted advertising or qualifying profiling. We do not discriminate for exercising rights. Because we do not currently sell/share data for targeted advertising, no opt-out link is required for that practice; contact us if you believe otherwise.
Send requests to info@tap4go.com. State the account/page and right requested. We will verify identity and authority proportionately, respond within the applicable deadline, and explain any lawful refusal. An authorised agent may submit a request with proof of authority. Consent can also be withdrawn through cookie settings; a page owner can remove or overwrite published content.
11. Children
The account and contact-request services are offered only to adults and are not directed to children. We do not knowingly collect account, profile or lead data directly from a child. If we learn that a child submitted personal data, we will delete it.
12. Automated decisions and marketing
Tap4Go does not make decisions producing legal or similarly significant effects solely by automated processing. We do not send promotional email from account registration or lead submission without a separate lawful basis. Operational verification, security and password messages are service communications.
13. Changes
We may update this Notice to reflect law, providers or features. We will post the new date and provide additional notice or seek consent where required for a materially different use.