Go4Tap

Legal

Privacy Policy

Last updated 7 September 2026

Go4Tap is built so that the person who taps your card never has to give up anything about themselves, and so that you stay in control of your own data.

What we collect from you

Account data: your name, email address, phone number and password hash. Your email is the unique identifier for your Go4Tap account.

Profile data: anything you choose to publish — photo, designation, company, bio, links, sections and contact details. You decide what goes on your public page and can remove it at any time.

Card data: which Go4Tap cards are linked to your account, their status and their activation history.

What we collect from visitors

When someone taps your card or opens your profile, we record the event type, a coarse device category, browser, and country or city where the hosting provider supplies it.

To separate unique visitors from returning ones, we compute a salted hash of the visitor's IP address and user agent. That hash rotates every day and is never reversible. We do not store raw IP addresses against analytics events.

We do not sell visitor data, run advertising trackers, or build cross-site profiles.

Leads you receive

If you enable lead capture, visitors can send you their name and contact details voluntarily. That information belongs to you, is visible only to you, and is exported or deleted with your account.

You can switch lead capture off at any time from Settings.

Your controls

Export: download everything on your account as JSON from Settings at any time.

Visibility: set your profile to public, unlisted or private, or unpublish it entirely without losing your content.

Analytics: turn off analytics collection for your profile from Settings.

Deletion: delete your account permanently. Your profile, links, leads and analytics are removed. Physical cards return to Go4Tap inventory as unassigned.

Retention

Account and profile data is kept while your account is open. Analytics events are retained for the period configured by Go4Tap and then purged.

Authentication codes and sign-in links expire within minutes and are deleted once used.

Indian data protection

Go4Tap is operated from India and is designed to meet the requirements of the Digital Personal Data Protection Act, 2023 — purpose limitation, data minimisation, consent for lead capture, and the right to access, correct and erase your data.

The architecture supports adding regional requirements later without changing how the product works for you.

Questions about this document? Write to privacy@go4tap.com. This page describes how the platform works today; it is not legal advice, and you should have your own counsel review it before launch.