Privacy Policy

TacTile is an NFC and QR platform: our customers program NFC tags and generate QR codes that route to destinations they create — digital business cards, menus, forms, documents, videos, Wi-Fi credentials, and links. This policy explains what we collect, why, and what happens to it, across this website (tactile-connect.com), the TacTile dashboard and apps (tactile.to), and our iOS and Android apps. TacTile is operated by [legal entity name and address — placeholder for counsel].

Two kinds of people use TacTile

Customers create an account, program tags, and build destinations. For customers, we are the data controller: we decide how account and billing data is handled, and this policy applies directly.

End users are the people who scan a customer's tag or QR code — a diner opening a menu, someone saving a contact card. End users are the customer's audience, not ours. We process scan data and anything submitted through a customer's destination (for example, a form response) on that customer's behalf, as a processor. If you scanned a TacTile-powered tag and have questions about how your information is used, the customer who deployed the tag is the right first contact — though you can also reach us at the address below and we will help route your request.

Information we collect

Account data. When a customer signs up we collect an email address, a password (stored only as a hash by our authentication provider, Supabase) or a social-login identity, and optionally a name and profile details. We never see plaintext passwords.

Billing data. Payments are handled by Stripe. Your card number goes directly from your browser or app to Stripe and never touches TacTile's servers. We store what we need to run your subscription: your plan, billing status, and a Stripe customer reference.

Tap and scan analytics. When someone scans a tag or QR code, we record an analytics event so customers can see how their tags perform. Each event includes:

Content customers upload. Destinations can contain whatever a customer puts in them — contact details, menu files, documents, videos, Wi-Fi credentials, form questions. Customers control this content; we store and serve it. Responses that end users submit through a customer's form belong to that customer, and we process them only to deliver them to the customer.

Support and correspondence. If you email us, we keep the thread so we can help you and improve the product.

How we use information

To run the service: authenticate you, route scans to the right destination, show customers their analytics, bill subscriptions, respond to support requests, and keep the platform secure (including abuse and fraud prevention). We do not sell personal information, and we do not use customer content or end-user scan data for advertising.

Cookies and local storage

The dashboard uses cookies and browser local storage for one job: keeping you signed in (session tokens from our authentication provider) and remembering basic preferences. There are no third-party advertising trackers on this site or in the product.

Subprocessors

We run on a small set of infrastructure providers, each of which processes data only to provide their service to us:

We will update this list when it changes. If your organization requires a data processing agreement covering these subprocessors, [DPA availability and terms — placeholder for counsel].

Data retention

Account and content data is kept while your account is active. If you delete your account, we delete your account data, destinations, and uploaded content within a reasonable period, except where we must keep records to meet legal or accounting obligations (for example, billing records). Scan analytics are retained while the associated account is active so customers keep their history; deleting a destination or account removes its analytics. [Specific retention windows — placeholder for counsel.]

Your rights

Depending on where you live (including under the GDPR in the EU/UK and the CCPA in California), you may have the right to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to not be discriminated against for exercising these rights. We do not sell personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of on that front. To exercise any of these rights, email us at the address below; we may need to verify your identity first. If you are an end user, we may refer your request to the customer who controls the data, and we will help them fulfill it.

Children

TacTile is not directed at children under 13, and we do not knowingly collect personal information from them. Customers may not use TacTile destinations to collect information from children. If you believe a child has provided us information, contact us and we will delete it.

Security

Data is encrypted in transit, passwords are hashed, and card data never reaches our servers. No system is perfectly secure; if a breach affects your data, we will notify you as required by law.

Changes

We may update this policy as the product evolves. Material changes will be noted here with an updated date, and for significant changes affecting customers we will give notice in the dashboard or by email.

Contact

Questions about this policy? Email privacy@tactile-connect.com. [Postal address for privacy requests — placeholder for counsel.]

Draft — under legal review.