TapFound

Privacy policy

Draft for review by a solicitor before launch. Last updated: July 2026.

Who we are

TapFound ("we") provides NFC emergency-ID tags and the web service behind them. We are the data controller for account data and a processor/controller for the emergency profile data you choose to store. Contact: privacy@tapfound.example · ICO registration: [number after registration].

What we collect, and why

Children

Accounts are held by adults only. A child's information is entered and controlled by their parent or guardian, who decides exactly which fields are visible. We follow the ICO Age Appropriate Design Code: minimal data, no profiling, no advertising, no trackers on tag pages.

What a stranger can see

Only the fields you have explicitly switched on, on an unguessable link that exists only on your physical tag. Phone numbers are never shown unless you enable that option, calls are relayed through our platform number so neither party sees the other's number.

Who we share data with

Your rights

Access, rectification, erasure, portability, restriction, objection, and withdrawal of consent, all self-service from your dashboard: edit any field, export everything as JSON, or delete a profile or your whole account instantly and permanently. You can also complain to the ICO (ico.org.uk).

Security

TLS on every connection, bcrypt-hashed passwords, signed httpOnly session cookies, encrypted database at rest in production, unguessable profile links, rate-limited calling endpoints, and no personal data stored on the NFC chip itself.