Privacy notice
A plain-language description of the information StarTaps needs to operate NFC products, business accounts, analytics, and fulfillment.
Information StarTaps uses
- Business-account identity, membership, authentication, and security state.
- Business profile, managed NFC destinations, locations, branding, and account settings.
- Signed payment-provider identifiers and status, subscription state, order status, shipping details, fulfillment, and QA evidence.
- Qualified NFC interaction timestamps, product and location identifiers, limited truncated request context, and aggregate reports.
- Support, privacy-request, notification, automation, and security-incident records.
Information StarTaps does not intentionally collect
StarTaps does not receive payment-card details from Whop and does not intentionally store customer tap IP addresses, precise tap locations, device fingerprints, passwords, MFA secrets, or provider API credentials in business records. StarTaps records qualified NFC interactions; it does not claim that a specific tap caused a review.
Why the information is used
- Authenticate users and keep each business workspace isolated.
- Program, test, fulfill, support, and secure the physical StarTaps product.
- Operate managed redirects and provide private business analytics and reports.
- Reconcile signed payment, refund, cancellation, and dispute events.
- Prevent abuse, investigate failures, comply with law, and respond to export or deletion requests.
Service providers and disclosure
StarTaps expects to use Supabase for application data and authentication, Netlify for hosting, Whop for checkout and subscription records, and an approved email provider for transactional messages. Each provider receives only the information needed for its role. Final processor disclosures, locations, and contractual terms must be approved before this notice becomes effective.
Retention and deletion
Authenticated business owners can request an export or reviewed deletion from the account page. Deletion is not automatic because payment, dispute, tax, fraud, security, fulfillment, shipping, and backup records may need to be preserved. Exact retention periods, legal bases, backup tails, and anonymization methods remain a launch-blocking decision and will be published before commercial checkout opens.
Security and choices
StarTaps uses tenant-scoped database policies, server-side authorization, administrator MFA, signed webhooks, encrypted transport, private storage, and restricted operational logging. No internet service can promise perfect security. Businesses should use unique passwords, enable available MFA, keep account access current, and report suspected misuse promptly.
A monitored support address will be published here before checkout opens. Do not send sensitive information to an unverified address.