Privacy Policy
Last updated: January 18, 2025
1. Introduction
Welcome to TapNN, operated by Hobbl Ltd trading as WebDev Wales ("we", "our", or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our QR code generation service.
We are registered in England and Wales (Company No. 14517138) and comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Information We Collect
Information You Provide
- Account Information: When you create an account, we collect your email address, name, and password (encrypted).
- QR Code Content: The data you input to create QR codes (URLs, contact information, etc.).
- Payment Information: For Pro subscribers, payment is processed by Stripe. We do not store your full card details.
- Communications: When you contact us, we collect the information you provide.
Information Collected Automatically
- Usage Data: Pages visited, features used, time spent on the Service.
- Device Information: Browser type, operating system, device type.
- QR Scan Analytics: For Pro users, we collect scan data including approximate location (city-level), device type, and timestamp.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process transactions and send related information
- Send you technical notices, updates, and support messages
- Respond to your comments, questions, and requests
- Monitor and analyze usage patterns and trends
- Detect, prevent, and address technical issues
- Protect against harmful or unlawful activity
4. Legal Basis for Processing (GDPR)
Under the UK GDPR, we process your data based on:
- Contract: Processing necessary to provide the Service you requested
- Legitimate Interests: Improving our Service, security, and fraud prevention
- Consent: Where you have given explicit consent (e.g., marketing emails)
- Legal Obligation: Compliance with applicable laws
5. Data Sharing
We do not sell your personal information. We may share data with:
- Service Providers: Third parties that help us operate the Service (hosting, analytics, payment processing)
- Legal Requirements: When required by law or to protect our rights
- Business Transfers: In connection with a merger, acquisition, or sale of assets
Third-Party Services We Use
- Clerk: Authentication services
- Convex: Database and backend services
- Stripe: Payment processing
- Vercel: Hosting and analytics
6. Data Retention
We retain your personal information for as long as necessary to provide the Service and fulfill the purposes described in this policy. Specifically:
- Account data: Until you delete your account
- QR code data: Until you delete it or your account
- Analytics data: 2 years from collection
- Support communications: 3 years from resolution
7. Your Rights (GDPR)
Under UK GDPR, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your personal data
- Restriction: Request limited processing of your data
- Portability: Receive your data in a portable format
- Object: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent at any time
To exercise these rights, contact us at [email protected].
8. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption of data in transit (TLS/SSL)
- Encryption of sensitive data at rest
- Regular security assessments
- Access controls and authentication
- Employee training on data protection
9. International Transfers
Your data may be transferred to and processed in countries outside the UK. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK Information Commissioner's Office.
10. Children's Privacy
The Service is not intended for children under 16. We do not knowingly collect personal information from children under 16. If you become aware that a child has provided us with personal data, please contact us.
11. Cookies
We use cookies and similar technologies. For details, see our Cookie Policy.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.
13. Contact Us
For privacy-related inquiries:
- Email: [email protected]
- Address: Hobbl Ltd, 28 Whitting Street, Glynneath, Neath, Wales, SA11 5DH
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.