Legal
Privacy policy
Plain English, no legalese-for-the-sake-of-it. This is what SmartTap collects, why, where it lives, and how to get it removed.
Last updated: 31 July 2026
Who we are
SmartTap (smarttap.ie) is operated by Henrique Pasquetto, based in Dublin, Ireland. For anything privacy-related, email support@smarttap.ie.
SmartTap wears two hats under GDPR, and it matters which one applies to you:
- If you run a business on SmartTap — we are the data controller for your account (your name, email, business details, billing).
- If you tapped a SmartTap stand in a shop — the shop is the data controller and we are its data processor. We only hold your details on the shop's behalf and on its instructions. Requests about your data can go to the shop or directly to us — either works.
- If you left a business a Google review — the business is the data controller and we are its data processor. We receive and store the review on the business's behalf and help it draft a reply. Requests about your data can go to the business or directly to us — either works.
If you run a business on SmartTap and need a data processing agreement (DPA) covering the customer data we process on your behalf, it's available on request — email us.
What we collect
When a customer taps a stand: the tap itself (which stand, when, device type). That's it — a tap alone is anonymous. Contact details (phone or email, name, optionally a birthday) are only stored if the customer fills in the join form and ticks the consent box. No pre-ticked boxes, no collection in the background.
For business accounts: name, email, business name and type, Google review link, and billing details (card data is held by Stripe — it never touches our servers).
Reviews the business works on: when a business connects its Google Business Profile or pastes a review into the dashboard, we store the review text, the reviewer's public name, and the reply — including replies the business approves, which are kept as examples so future AI drafts match the business's own tone.
On this website: anonymous product analytics (PostHog, hosted in the EU) and error reports (Sentry). No advertising trackers, no data sold to anyone, ever.
Why we collect it (legal bases)
- Consent — a customer's contact details and any messages the shop sends them (loyalty updates, review reminders). Withdrawable at any time, one tap.
- Contract — running the service for businesses: accounts, billing, transactional email.
- Legitimate interest — keeping the service secure and working: rate-limiting, fraud prevention, error logs, anonymous usage analytics.
Where the data lives
The database runs on Supabase in AWS eu-west-1 — that's Ireland. Customer records never leave the EU as part of normal operation. A small number of subprocessors below operate globally; where data leaves the EEA it is covered by EU Standard Contractual Clauses.
Subprocessors we use
Supabase
Database and authentication. Hosted in AWS eu-west-1 (Ireland).
Vercel
Hosts this website and the dashboard.
Railway
Hosts the SmartTap API.
Stripe
Subscription billing for businesses. Card details are stored by Stripe only.
Resend
Transactional email — receipts, reports, thank-you notes.
Twilio
SMS delivery of one-time verification codes (account recovery). Phone numbers are used for the code only — never added to any marketing list.
Anthropic
AI drafting — turns a shop's questions and public review text into draft replies. Processing takes place in the United States under EU Standard Contractual Clauses. Not used to train AI models.
Business Profile integration — reads a shop's public reviews when the shop connects its Google account.
PostHog (EU)
Anonymous product analytics, hosted in the EU.
Sentry
Error reporting so we can fix bugs quickly.
How long we keep it
- Customer loyalty records: for as long as the shop uses SmartTap. Shops can delete any customer record from the dashboard at any time; deletion is immediate.
- SMS verification codes: stored hashed, expire after 10 minutes.
- Business account data: for the life of the account, then removed after closure once billing/tax obligations allow.
- Stored reviews and approved reply examples: for the life of the business account, then removed with the rest of the business's data.
- Error logs and analytics: automatically expire on the providers' standard retention windows (typically 90 days).
Cookies
We use essential cookies only: a session cookie on the loyalty page so a returning customer keeps their stamps, and login cookies on the business dashboard. No third-party advertising cookies.
Your rights
Under GDPR you can ask for access, correction, deletion, a portable copy, or restriction of your data — whether you're a business or a customer who tapped a stand. Email support@smarttap.ie and we'll respond within 30 days (usually much faster). The fastest route for deletion is described on our Data deletion page — no account or login needed. If you're unhappy with how we handle it, you can complain to the Irish Data Protection Commission (dataprotection.ie).