Privacy policy
Draft for review by a solicitor before launch. Last updated: July 2026.
Who we are
TapFound ("we") provides NFC emergency-ID tags and the web service behind them. We are the data controller for account data and a processor/controller for the emergency profile data you choose to store. Contact: privacy@tapfound.example · ICO registration: [number after registration].
What we collect, and why
- Account data (your email, name, hashed password), to provide the service. Lawful basis: contract.
- Emergency profile data (name, age, contacts, and any medical fields you fill in), to display to a finder in an emergency. Lawful bases: contract; explicit consent for medical (special-category) data, which you give via a dedicated checkbox; and vital interests at the moment of an emergency.
- Scan events (time, device user-agent, a one-way hash of the IP, never the raw IP), so you can see when your tag was used. Deleted after 12 months.
- Call requests (the finder's phone number), solely to place the masked relay call. Deleted after 12 months.
- Approximate scan area, estimated from the internet connection of whoever scans a tag (city level at best, and often inaccurate on mobile networks). It is included in the alert we send the family so they know roughly where the tag was tapped, and is deleted with the scan log. Lawful basis: vital interests, and the legitimate interest of reuniting a lost or injured person with their family.
- Finder location, only if the person who scans a tag taps "share my location" and approves their phone's permission prompt. This is precise, unlike the estimate above. It is shown to the tag owner and deleted with the scan log.
- Chat messages between a finder and the family, tied to the scan session. Visible only to those two parties, and deleted with the scan log.
Children
Accounts are held by adults only. A child's information is entered and controlled by their parent or guardian, who decides exactly which fields are visible. We follow the ICO Age Appropriate Design Code: minimal data, no profiling, no advertising, no trackers on tag pages.
What a stranger can see
Only the fields you have explicitly switched on, on an unguessable link that exists only on your physical tag. Phone numbers are never shown unless you enable that option, calls are relayed through our platform number so neither party sees the other's number.
Who we share data with
- Hosting: Vercel (UK/EU region). Database: EU-region Postgres.
- Twilio: only the phone numbers needed to bridge a masked call or send a scan-alert SMS to your chosen contact.
- Resend, only your email address, to send scan alerts.
- Nobody else. No advertising, no analytics trackers, no data sales. Ever.
Your rights
Access, rectification, erasure, portability, restriction, objection, and withdrawal of consent, all self-service from your dashboard: edit any field, export everything as JSON, or delete a profile or your whole account instantly and permanently. You can also complain to the ICO (ico.org.uk).
Security
TLS on every connection, bcrypt-hashed passwords, signed httpOnly session cookies, encrypted database at rest in production, unguessable profile links, rate-limited calling endpoints, and no personal data stored on the NFC chip itself.