Privacy notice
In effect from September 13, 2026.
OneTap is run by Innovations Beyond, a small company in the United States. This page says what we keep, why, and how to reach us about it: [email protected].
If you tap a card
When you tap a card, we record that a tap happened: the time, which card, whether the phone is an iPhone, an Android or something else, which page you were shown, and, if you picked one, which review site you went on to. That is what the business sees as its tap counts. It does not identify you.
We also keep a scrambled version of your network address. It cannot be turned back into the address, it changes every day, and we use it only to notice one phone tapping the same card over and over.
Tapping a card sets no cookie, except the one that protects the private-feedback form from forgery. We show no ads and run no tracking.
If the business has turned on the "How was your visit?" question and you send a message, we email it to the business owner, along with the email address or phone number you typed, if you gave one. A copy of that email stays in the owner's OneTap account for 365 days, then it is deleted; nobody else can read it.
Once you are on Google, Yelp or wherever the business sends you, that site's own privacy rules apply.
If you own cards
What we keep. Your email address, your business name, the name you give each card, the links you set on it, and, if you use branding, your logo, tagline and social links. We keep the tap records described above for each of your cards for as long as the card is yours. The one-time links we email you for signing in and setting up a card are deleted soon after they are used or expire.
Payments. Stripe handles them. Your card number is entered on Stripe's pages and stays with Stripe; we never see or store it. Stripe gives us a customer reference and the card's brand and last four digits, so your account can say which card is charged. What Stripe holds is covered by Stripe's privacy policy.
Email. Our emails are sent through SendGrid. We send only the emails the service needs: sign-in links, setup confirmations, order and billing notices, payment problems and private feedback from your customers. A copy of every email we send you is kept in your account's Inbox, with the one-time sign-in links removed, for 365 days and then deleted. There is no newsletter and no marketing list.
Cookies. A session cookie while you are signed in, and a cookie that protects forms from forgery. Nothing for advertising or tracking.
Cloudflare. The site sits behind Cloudflare, which may set its own security cookie and gives us anonymous visit counts that use no cookies.
Errors. When something breaks, an error report may go to Sentry, with addresses, cookies and links stripped out first.
Where. OneTap runs on our own server in the United States. Cloudflare, Stripe, SendGrid and Sentry are companies based in the United States.
What we do not do
We do not sell anyone's data. We share it only with the providers named above, to run the service, or when the law requires it.
OneTap is for businesses. It is not meant for anyone under 18 to sign up, and we do not knowingly keep anything about a child.
Your choices
Email us for a copy of what we hold about you, to correct it, or to delete your account. Deleting your account removes your settings, your plans and the copies of emails we sent you, and unlinks your cards so they stop pointing anywhere. Tell us if you also want their tap records erased.
Changes
If this notice changes, we update this page and the date at the top.
