Policy
Privacy Policy
What is held about you, why it is held, how long it stays, and how to have it removed. Written to be read rather than scrolled past.
The short version. If you buy a card we keep your business name, your mobile number and the review link you chose. That is what makes the card work.
A customer who taps your card is not identified, not tracked and not asked for anything. They are simply sent to your Google review page.
Nothing is sold to anyone, ever. Ask and your details are deleted.
Who is responsible
Tap2Review is run by Arjun Shailesh Bumb from Pune. Under the Digital Personal Data Protection Act 2023 that makes us the data fiduciary for everything described here, which is the legal way of saying the responsibility is ours and there is a named person to complain to.
Two very different people appear in this policy, so they are kept apart all the way through. A merchant is a shop, salon or clinic that buys a card. A visitor is a customer of that shop who taps it.
What we hold about merchants
All of it comes from you directly or is created when your card is made. None of it is bought, scraped or taken from anywhere else.
| What | Why we need it |
|---|---|
| Business name | To print your card and to show you which card is yours |
| Mobile number | To send the code that proves the card is yours, and to reach you about your own card |
| Google review link | To send your customers to the right place |
| Delivery address, and email if you give one | To ship your plate, and to send your receipt and tracking number when you order. If a payment at checkout does not go through, one email to remind you, and no more. On Pro, if you switch it on, to send your plate’s monthly report, which you can stop from any of those emails or from your dashboard |
| Card key | To tie the physical card in your hand to its record, so only you can change it |
| Dates and changes | To know when a card was claimed or edited, which is how a problem gets untangled later |
| Help messages | To fix an activation when the code does not arrive |
The lawful basis for all of it is your consent, given when you enter the details, together with what is needed to perform the sale you made.
Customers who tap a card
This is the part most people actually care about, so it is worth being blunt. When someone taps or scans a card, their phone asks our server where that card points and their browser goes there. That is the entire interaction.
- No account, no sign in, nothing to install
- No advertising cookie and no tracking pixel
- No profile is built and nothing follows them to another site
- We do not know who they are, and we do not learn what they wrote in their review. That happens on Google, not here
A merchant cannot see a list of who tapped their card, because no such list exists.
What the server records on its own
Three things, all narrow, and none of them about who anybody is.
- Ordinary server logs kept by our hosting provider, which record requests the way every web server has since the web started.
- A short lived note of the network address a request came from, used only to stop one person hammering the code sending endpoint. Indian mobile networks put thousands of customers behind a single address, so this is deliberately coarse, it is not used to identify anyone, and it expires by itself.
- A count of taps on each card, by day, by hour of the day and by kind of phone (Android or iPhone), so a shop can see when its card is used. To tell one phone tapping again and again from many phones, each tap also carries a short scrambled code made from the connection. The code changes every day and cannot be turned back into an address or a phone, so it cannot follow anyone from one day to the next.
How long things are kept
The Act asks that data goes once the reason for having it has passed, rather than being kept because storage is cheap. So:
- Your card record is kept while the card is in use. The card stops working without it, which is the whole reason it exists.
- Your mobile number is kept for as long as the card is in use, and goes when you ask.
- Help messages are cleared once the problem behind them is fixed.
- Rate limiting notes are short lived and expire by themselves. They are never looked at by a person.
Ask for deletion and the record goes. Your card stops redirecting when it does. That is the honest trade and it is better said here than discovered later.
Your rights
The Digital Personal Data Protection Act gives you these, and there is no form to fill in and no fee for any of them.
- A copy of everything held about you
- A correction to anything wrong or out of date
- Deletion
- The names of anyone your data was shared with
- To name someone who can exercise these rights for you if you die or become unable to act yourself
You can also withdraw consent whenever you like. The Rules require withdrawing to be as easy as giving it was, and one message is enough.
Who else touches it
Your data is never sold and never shared for anybody’s marketing. These companies handle it only because the service cannot run without them.
- Google Cloud Firestore, in the Mumbai region, where card records are stored
- Vercel, which serves the website and counts page visits without cookies
- Our messaging providers, which deliver the verification code to the number you enter
- Razorpay, which takes payment when you order. Your card or bank details go to Razorpay and never reach us
- Google Maps, which suggests your shop as you type its name at checkout and fills in its address when you pick it. It is sent what you type and roughly which city you are in, worked out from your internet connection. Never your name or number
- The courier that delivers your plate, which is given your name, mobile number and delivery address and nothing else
- Resend, which sends order receipts, shipping emails, the one reminder about an unpaid checkout, one email when a sold out product you asked about is back, offers and news if you tick that box at checkout (every one has a link to stop), and, if you switch them on, monthly reports to the address you give
- Anthropic, which writes a draft reply when a Pro shop pastes one of its Google reviews into the reply writer. It is sent the review, its stars and the shop’s name. We keep neither the review nor the reply
- Moonshot AI (Kimi), which writes the plain words of a Pro shop’s monthly report. It is sent the shop’s name and the month’s figures for its plate: counts of taps and scans by day, hour and kind of phone. Never anything about the shop’s customers. The words it writes are kept with that month’s report
Some of these are companies based outside India and may process data outside India while running their own infrastructure. The Act permits this except to countries the Central Government has restricted, and none of the above are on that list.
Data is also handed over if a court or the law requires it. That has not happened, and if it ever does you will be told unless we are forbidden from telling you.
Keeping it safe
- The site is served over an encrypted connection only
- Your card key is what authorises a change to your link, which is why it is printed on your insert rather than emailed, and is not shown again afterwards
- The database refuses connections from browsers entirely. Everything goes through the server, so nobody can read other merchants’ records by poking at the site
- The admin side sits behind a separate login that a card key cannot reach
No system is perfect and it would be dishonest to claim otherwise. If personal data is ever exposed, the merchants affected and the Data Protection Board of India will be told, with a full report to the Board inside seventy two hours as the Rules require.
Children
Cards are sold to businesses and the service is not aimed at anyone under eighteen. We do not knowingly collect a child’s data. If a child’s details have ended up here by accident, say so below and they will be removed.
Complaints
Anything at all about your data goes to the person named here, who is a person and not a ticket queue.
Arjun Shailesh Bumb
- Role
- Grievance officer, Tap2Review
- tap2review.help@gmail.com
- [to be filled in]
- Post
- Flat No. 1, Plot No. 5, Sr. No. 103/126 Nagar Road, near Park Ornate Hotel, Yerwada Pune, Maharashtra 411006
A complaint is acknowledged within forty eight hours, which is the E-Commerce Rules timeline, and answered well inside ninety days, which is the Data Protection Act one. In practice it is one person reading them and it is usually the same day.
If the answer is unsatisfactory, you can take it to the Data Protection Board of India.
In another language
The Rules give you the right to have this explained in any language in the Eighth Schedule of the Constitution. Ask on the number below and you will get it in Marathi or Hindi. This is a Pune business and that is a reasonable thing to want.
Changes to this page
Changes are posted here with a new date at the bottom. Anything that changes what we collect or why will also be sent to affected merchants directly, rather than left here to be noticed.
Last updated 6 October 2026.