Legal

Privacy policy

Plain English, no legalese-for-the-sake-of-it. This is what SmartTap collects, why, where it lives, and how to get it removed.

Last updated: 6 July 2026

Who we are

SmartTap (smarttap.ie) is operated by Henrique Pasquetto, based in Dublin, Ireland. For anything privacy-related, email support@smarttap.ie.

SmartTap wears two hats under GDPR, and it matters which one applies to you:

  • If you run a business on SmartTap — we are the data controller for your account (your name, email, business details, billing).
  • If you tapped a SmartTap stand in a shop — the shop is the data controller and we are its data processor. We only hold your details on the shop's behalf and on its instructions. Requests about your data can go to the shop or directly to us — either works.

What we collect

When a customer taps a stand: the tap itself (which stand, when, device type). That's it — a tap alone is anonymous. Contact details (phone or email, name, optionally a birthday) are only stored if the customer fills in the join form and ticks the consent box. No pre-ticked boxes, no collection in the background.

For business accounts: name, email, business name and type, Google review link, and billing details (card data is held by Stripe — it never touches our servers).

On this website: anonymous product analytics (PostHog, hosted in the EU) and error reports (Sentry). No advertising trackers, no data sold to anyone, ever.

Why we collect it (legal bases)

  • Consent — a customer's contact details and any messages the shop sends them (loyalty updates, review reminders). Withdrawable at any time, one tap.
  • Contract — running the service for businesses: accounts, billing, transactional email.
  • Legitimate interest — keeping the service secure and working: rate-limiting, fraud prevention, error logs, anonymous usage analytics.

Where the data lives

The database runs on Supabase in AWS eu-west-1 — that's Ireland. Customer records never leave the EU as part of normal operation. A small number of subprocessors below operate globally; where data leaves the EEA it is covered by EU Standard Contractual Clauses.

Subprocessors we use

Supabase

Database and authentication. Hosted in AWS eu-west-1 (Ireland).

Vercel

Hosts this website and the dashboard.

Railway

Hosts the SmartTap API.

Stripe

Subscription billing for businesses. Card details are stored by Stripe only.

Resend

Transactional email — receipts, reports, thank-you notes.

Twilio

SMS delivery of one-time verification codes (account recovery). Phone numbers are used for the code only — never added to any marketing list.

Meta (WhatsApp)

WhatsApp message delivery — the owner assistant, and review reminders to customers who opted in.

Anthropic

AI drafting — turns a shop's questions and public review text into draft answers. Not used to train AI models.

Google

Business Profile integration — reads a shop's public reviews when the shop connects its Google account.

PostHog (EU)

Anonymous product analytics, hosted in the EU.

Sentry

Error reporting so we can fix bugs quickly.

How long we keep it

  • Customer loyalty records: for as long as the shop uses SmartTap. Shops can delete any customer record from the dashboard at any time; deletion is immediate.
  • SMS verification codes: stored hashed, expire after 10 minutes.
  • Business account data: for the life of the account, then removed after closure once billing/tax obligations allow.
  • Error logs and analytics: automatically expire on the providers' standard retention windows (typically 90 days).

Cookies

We use essential cookies only: a session cookie on the loyalty page so a returning customer keeps their stamps, and login cookies on the business dashboard. No third-party advertising cookies.

Your rights

Under GDPR you can ask for access, correction, deletion, a portable copy, or restriction of your data — whether you're a business or a customer who tapped a stand. Email support@smarttap.ie and we'll respond within 30 days (usually much faster). If you're unhappy with how we handle it, you can complain to the Irish Data Protection Commission (dataprotection.ie).