Privacy Policy

Last updated: 2026-05-09

1. Introduction & Scope

Welcome to TapReview. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our website, business dashboard, customer-facing scan flow, and related services (collectively, the "Service"). By using the Service, you agree to the practices described in this policy. This policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023 ("DPDP Act").

2. Information We Collect

We collect three categories of information. First, business owner information when you create an account or contact us. including your name, email address, phone number, business name, and details about your business (such as your Google Business Profile link). Second, end-customer contact information collected via your scan-flow lead-capture form. including name, phone number, and email address. but only with the explicit consent of the end customer at the moment of collection. Third, usage data collected automatically when you or your customers use the Service. including IP addresses (used for rate limiting and abuse prevention), browser and device information, access logs, scan events, and rating submissions. Payment information is processed by our third-party payment processor; we do not store credit card numbers or full bank details on our systems.

3. How We Use Information

We use the information we collect to deliver and operate the Service, process subscriptions and payments, provide customer support, prevent abuse and fraud (including rate limiting and AI-credit protection), comply with legal obligations, and improve the Service through aggregate, non-identifying analytics. We do not sell, rent, or share personal information with third parties for advertising or marketing purposes.

4. Legal Basis for Processing

Under the Digital Personal Data Protection Act, 2023, we process personal data on the basis of: (a) explicit consent given by the data principal (the business owner for account data, the end customer for lead-form data), (b) legitimate uses such as fraud prevention, security, and compliance with legal obligations, and (c) contractual necessity to deliver the Service you have purchased.

5. How Long We Keep Your Data

Account data is retained while your account is active and for 180 days after account deletion or your written deletion request. End-customer lead contact information follows the same 180-day retention after deletion. Hard deletion is performed by an automated daily process. Financial records (subscription invoices, payment receipts) are retained for 8 years as required by Indian tax law and the Income Tax Act, even where you have requested account deletion. Aggregate, non-identifying analytics may be retained indefinitely.

6. Sharing With Third-Party Service Providers

We use trusted third-party providers for hosting infrastructure, payment processing, transactional email delivery, AI generation, customer support tools, and analytics. These providers process data only as needed to deliver their services to us and are contractually bound by confidentiality and data-protection commitments. We do not sell, rent, or share your data with third parties for advertising or marketing purposes. Where required by applicable law, we may disclose information in response to valid legal process, to protect our rights and the safety of our users, or to comply with regulatory obligations.

7. Security

We implement industry-standard security measures to protect personal information against unauthorized access, alteration, disclosure, or destruction. These include encryption in transit (TLS), encryption of sensitive data at rest, role-based access controls with least-privilege principles, audit logging of administrative actions, and incident response procedures. No method of transmission over the internet or electronic storage is 100% secure; we work continuously to improve our security posture but cannot guarantee absolute security.

8. Your Rights Under the DPDP Act, 2023

You have the right to access the personal data we hold about you, correct inaccuracies, request erasure, withdraw your consent, and seek redress with the Data Protection Board of India if you believe we have violated your rights. To exercise any of these rights, email us at privacy@tapreview.in. We respond to all rights requests within 30 days, as required by the DPDP Act. You may also nominate another individual to exercise your rights in the event of your death or incapacity.

9. Cookies & Tracking

We use only functional cookies necessary to operate the Service. including authentication session cookies and user-preference cookies. We do not use third-party advertising cookies or behavioral tracking cookies. You can configure your browser to refuse cookies, but this may impair functionality of authenticated features.

10. International Data Transfers

Some of our service providers may be located outside India. Where personal data is transferred internationally, the transfer is conducted under standard contractual safeguards consistent with the requirements of applicable Indian law, including the DPDP Act. We do not transfer personal data to jurisdictions specifically restricted by the Government of India.

11. Children's Data

The Service is not directed at minors under 18 years of age, and we do not knowingly collect personal information from minors. If you believe we have collected information from a minor without verifiable parental consent, contact us at privacy@tapreview.in and we will delete the information promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify business owners via the dashboard banner and/or email at least 14 days before the changes take effect. Continued use of the Service after the effective date of any update constitutes acceptance of the revised policy.

13. Contact Us

For privacy-related questions, requests, or complaints, contact us at privacy@tapreview.in. We aim to respond to all inquiries within 5 business days and to formal rights requests within 30 days as required by the DPDP Act.

14. Trademark Notice

TapReview is independent and is not affiliated with, endorsed by, or sponsored by Google LLC. Google, Google Maps, and Google Business Profile are trademarks of Google LLC. Our platform facilitates and encourages the submission of reviews to Google's services on behalf of our customers. All other trademarks referenced on the Service are the property of their respective owners.