Privacy Policy
Last updated 2 August 2026
The short version. When someone taps your Tap2Grow product, we do not record who they are. No IP address, no cookie, no advertising identifier, no device fingerprint — we store the country, the broad region, and whether the phone was iOS, Android or a desktop. That is all.
We do not sell data, we do not run advertising, and there are no third-party trackers or analytics scripts on the pages your visitors see.
Who we are
Tap2Grow is operated by Tap2Grow. We decide how the information described here is handled, and we are the people to contact about it: hello@tap2grow.com.
This policy covers two different people
Tap2Grow has account holders — people who own a product and publish a profile — and visitors, who tap someone else's product and read what is on it. We hold very different amounts of information about each, so they are described separately.
If you have an account
What you give us
- Your email address and password. The password is stored only as an Argon2 hash. We cannot read it, and neither can anyone who obtains the database.
- Your name, and the date you accepted these terms.
- Whatever you put on a profile — job title, organisation, photos, phone numbers, links, and any custom sections you add. You choose all of this, and it is published deliberately: a profile exists to be shown to whoever taps your card.
- WiFi passwords, if you add a WiFi section. These are encrypted at rest with a key held separately from the database.
What we record as you use it
- Signed-in devices, so you can see and revoke active sessions. We store a label and a hash of the session token — not the token itself.
- Your products and which profile each one points at.
- Counts of taps on your own products, described below.
If you tapped someone's product
You are not asked to identify yourself and you are not asked to sign up. We record one row so the owner can see that a tap happened:
| What we store | Example | Why |
|---|---|---|
| Country | IN | So the owner sees roughly where interest comes from |
| Region | Maharashtra | Same, one level finer |
| Device class | ios | One of iOS, Android, desktop or other |
| Time | 2 Aug 2026, 14:32 | To count taps per day |
| What you tapped or clicked | "saved contact" | So the owner knows the card is working |
We do not store your IP address, set any cookie, assign you an identifier, or attempt to recognise you across visits or across different people's cards. Two taps by the same person are indistinguishable from two taps by two people.
Lost and found
If a product is marked lost, whoever finds it can leave a message for the owner.
- We ask the finder for nothing about themselves — no name, no phone number, no email, no IP address.
- The browser may ask the finder to share their location. This is optional: declining still sends the message. If it is shared, we store the coordinates and pass them to the owner so they know where the item turned up.
- That location is where the finder's phone was when they tapped. It is not tracking. There is no battery or radio in the chip, and nothing about a product's whereabouts is known between taps.
- The owner is never shown who the finder is, and the finder is never shown who the owner is.
Cookies
Visitor profile pages set no cookies at all. The staff admin panel and the company portal each set one session cookie so you stay signed in. Those are strictly necessary for sign-in and are not used for tracking or advertising.
Who else sees this information
- Amazon Web Services hosts the service. Data is stored on servers in the United States.
- Resend delivers verification and notification emails, and receives the email address a message is sent to.
That is the complete list. We do not sell or rent personal information, we do not share it for advertising, and we have no analytics or tracking scripts from anyone else. The homepage's typeface is served from our own servers rather than a font network, specifically so that visiting this site does not disclose you to a third party.
How long we keep it
- Account and profile information — until you delete the account.
- Tap and interaction records — these carry nothing identifying a visitor, and are aggregated into daily totals.
- Finder messages — until the owner deletes them or closes the account.
Your rights, and deleting your account
You can ask us to show you what we hold about you, correct it, or delete it. Email hello@tap2grow.com from the address on the account and we will action it within 30 days.
Deleting your account. Write to hello@tap2grow.com with the subject "Delete my account".
We erase your account, your profiles and their contents, your device sessions, and any finder messages sent to you. Products registered to you are released so they can be activated again by someone else. Tap records are already anonymous and cannot be traced back to you, so they remain in the daily totals.
Children
Tap2Grow is not intended for children under 13, and we do not knowingly create accounts for them. A profile made about a child or a pet is the responsibility of the adult who publishes it — please think about what you are putting on a page a stranger can open.
Security
Traffic is encrypted in transit. Passwords are hashed with Argon2 and never stored in a readable form. WiFi passwords are encrypted at rest. Sessions can be revoked per device from the app. No system is perfectly secure, and we will tell affected users promptly if something goes wrong.
Changes
If this policy changes materially we will update the date at the top and, for account holders, say so in the app before the change takes effect.
Contact
Questions or complaints: hello@tap2grow.com.