TapBack's privacy approach
TapBack is a family lost-property QR tag service available directly to customers in Australia. It is designed to collect only the personal information needed for purchase, tag activation, fulfilment, found-item alerts, support, security, and optional product feedback.
TapBack does not need student dates of birth, student ID numbers, medical information, school passwords, school system access, class lists, or family contact details printed on labels. A family can optionally invite a secondary recipient for found-item alerts using a nickname and age band; the recipient supplies and verifies their own email address or mobile number.
Information TapBack collects
- For customers: the adult purchaser's email address entered before checkout, the name supplied to Stripe Checkout, and the Australian delivery address supplied during private setup. We send a code to verify control of the email before creating a payment checkout, check it against existing purchase and account records, then use it to create the Stripe customer and send purchase and setup information.
- Plan choice, terms consent, checkout status, activation and service end dates, renewal history, and payment reference information from Stripe. TapBack does not store card numbers.
- Private setup codes, tag codes, optional item nicknames, and tag status such as active, lost, inactive, or reissued.
- For optional family alerts: a recipient nickname, relationship, age band, selected tag routes, masked contact destination, verification status, and records of the account owner's authority and consent. TapBack records an exact date of birth only if the law later requires it; the current service does not ask for one.
- An optional recipient's email address or mobile number after the recipient enters it through a private invitation and verifies control of it. The full destination is kept separately from ordinary family and administration summaries.
- Finder messages, where-found details, and optional finder contact details entered by the person scanning a tag.
- Product feedback a family chooses to submit.
- Basic technical records needed to operate and secure the website.
How TapBack uses information
- To confirm purchases and send private setup instructions.
- To create and manage private QR tags.
- To deliver family tag packs and setup instructions.
- To send found-item alerts to the adult account owner and, if the family has enabled it, to verified secondary recipients selected for that tag.
- To respond to support requests and fix product issues.
- To understand whether the service is useful, clear, reliable, and safe enough to improve.
Optional family alerts and children
The adult account owner is the family's authority and is always the primary alert recipient. A secondary recipient cannot sign in to the family account, change labels, cancel or reactivate the service, or replace the account owner. Adding one is optional and never blocks fulfilment.
For a student under 15, TapBack requires an authenticated parent or guardian to attest parental responsibility and give specific consent before creating the invitation. For a student aged 15 to 17, guardian consent and the recipient's own consent are required. The recipient must then enter and verify an email address or mobile number through a time-limited private invitation. TapBack does not use a minor's destination for marketing.
Secondary alerts contain less information than the account owner's alert. They identify the relevant item and where it was found, but do not include the finder's name, contact details, or private message. The recipient or account owner can stop the secondary alerts without cancelling the family service.
If mobile alerts are enabled, an SMS recipient can use the private withdrawal link or reply STOP. A STOP request disables every pending or verified TapBack secondary SMS contact using that mobile number and removes its live destinations and tag routes. Replying START to Twilio does not restore TapBack consent; receiving alerts again requires a new family invitation and verification.
What finders can see
A finder who scans an active TapBack label with current service sees a private message form. A label awaiting activation or with paused service shows an unavailable notice without revealing billing dates or family details. The family's email addresses and phone numbers, including optional secondary-recipient details, are not shown on the public finder page or printed on the label.
TapBack does not require a child name, school name, class, school system connection, or organisation-managed account. TapBack does not claim that a school, club, or other organisation endorses a family's independent use of the service.
Storage and service providers
TapBack stores service records in TapBack's Supabase database. As at 30 July 2026, that database is hosted in Tokyo, Japan. TapBack's server-side Vercel Functions are configured for Sydney, while static website delivery uses Vercel's global network. TapBack also uses Resend for email delivery and Stripe for payments. If mobile alerts are enabled, TapBack uses Twilio to deliver transactional verification and found-item messages. These providers may process service data outside Australia under their published privacy and security terms. Stripe handles payment card details; TapBack does not store card numbers.
TapBack does not collect a delivery address before payment. The Australian address supplied during private setup is used for fulfilment. It is not shown on public finder pages or printed on tags. Access to TapBack administration data is limited to authorised people helping run and support the service.
Remembering a checkout attempt
When you request a purchase verification code, this browser saves the selected pack, referral code, a random checkout reference, the attempt time and a cryptographic hash of the purchase email in local storage. The email itself and payment card details are not saved there. This record lets TapBack retry the same payment session after an interrupted connection instead of starting a second one.
Purchase verification uses a random emailed code, stored on the server only as a hash together with hashes of the email and request source, the selected pack and checkout terms. An unused code expires after 15 minutes; a code already used for the same verified purchase can support retries for that purchase’s original 23-hour window. Request limits reduce abuse. Verification records older than two days are removed when new codes are requested; attempt-rate records older than one day are removed during verification checks. A request for a code does not create a paid account or subscribe anyone to marketing.
Manual renewals save a separate random request reference, email hash, selected plan, service period version, terms version and attempt time in local storage. The renewal record does not contain the email, private setup code or card details. It keeps interrupted renewal requests tied to the same payment. A paid renewal is recorded separately from the original pack entitlement.
After email verification, TapBack also keeps a server record linking your purchase email, checkout reference, pack and a hash of the checkout terms. It prevents separate browsers from creating conflicting first-pack purchases. An expired or interrupted attempt is retained for payment reconciliation and requires support review; clearing browser storage does not remove that server record.
The saved attempt can be retried for up to 23 hours. Once an attempt has started, its pack, email and referral choice stay fixed. The record is not automatically deleted when that retry period ends or when you leave the page; contact info@tapback.school if an attempt has expired or you need to change it. Clearing browser data removes the local record but does not cancel a payment session already created with Stripe.
Affiliate applications and referral attribution
Affiliate applications are sent from your email account to TapBack. We use the adult applicant's name, email, public channel and audience description to assess the application and administer the programme. Applying does not subscribe you to general marketing. Do not send details about children, followers or customers. Unsuccessful or inactive applications are deleted within 12 months unless a dispute or legal obligation requires longer retention.
A referral link or a code you enter stores only the affiliate code and its expiry in this browser tab's session storage for up to 24 hours. Before starting checkout, the latest code replaces the previous one; use “Remove code” to clear it. Once checkout starts, the chosen code is also saved with that checkout attempt as described above and cannot be changed for the same payment attempt. No advertising cookies or cross-site tracking are used for this programme. If storage is blocked, the code lasts only on the current page. Referral links may also appear in ordinary website request logs.
At checkout, an approved code and programme terms are recorded with Stripe payment records so TapBack can review the commission. Private commission records contain payment references, a non-public customer identifier and fulfilment/refund checks. Affiliates receive their own commission statements, never family contact details, tag identities or finder messages. Payment and commission records are retained for five years after the transaction. Access or deletion requests can be made using the contact below.
Access, correction, and deletion
Families can ask TapBack to access, correct, delete, or de-identify their information by emailing info@tapback.school. The account owner can remove a secondary recipient in the setup portal, and a recipient can use the private withdrawal option supplied during verification. Removal immediately stops that secondary route and removes its live destination.
A family can also cancel from the member setup portal. Cancellation immediately deactivates its labels, stops new found-item alerts, revokes optional family-alert consent, and removes secondary-recipient destinations and routes. Reactivation is not automatic: the account owner must ask TapBack, an administrator must record the review, TapBack rotates the private setup code, and the family provides fresh consent. Secondary recipients are never restored automatically.
Retention schedule
- Historical first-release list: any email and update-consent record collected before public sales opened is kept until the person unsubscribes or the record has been inactive for 12 months.
- Active account and label records: kept while the account is active. After cancellation, TapBack deletes or de-identifies operational personal information within 30 days, except for the records listed below that must be kept longer.
- Optional family-alert invitations: an unopened invitation expires after seven days. A supplied destination must be verified within 24 hours. Expired invitations and unverified destinations are disabled and removed from live alert routing.
- Verified minor recipients: consent expires no later than 12 months after it is given and must be renewed before alerts continue. Withdrawal, removal, or account cancellation stops alerts immediately and removes the live destination and tag routes. Limited lifecycle evidence may be retained where reasonably needed to prove consent, withdrawal, account security, or compliance.
- Delivery address: deleted 90 days after the pack is handed over or dispatched.
- Finder messages: message, where-found details, and optional finder contact details are kept for 12 months after submission, then deleted or de-identified.
- Optional product feedback: identifiable feedback is kept for up to 24 months after submission, then deleted or de-identified. De-identified findings may be kept for product research.
- Payment, receipt, and corresponding consent records: kept for five years after the transaction.
- Unsubscribe suppression: the minimum email address or irreversible email hash needed to honour an opt-out may be retained for as long as necessary to prevent further marketing email.
If a dispute, investigation, or law requires a record for longer, TapBack keeps only the information needed for that purpose and deletes or de-identifies it when the reason ends.
Contact
Questions about privacy can be sent to info@tapback.school.