Privacy Notice
How Siliconstation Software handles information when providing taaap.
- Effective
- September 25, 2026
- Version
- 1.5
1. Who is responsible
Siliconstation Software operates taaap and is responsible for the account, security, support, and service information it controls. Contact our Privacy Lead at [email protected].
Customers decide what their Forms ask and why. We process those responses to provide the service under the customer's instructions, while each party keeps its own legal responsibilities.
2. Information we process
When you accept legal documents, we record the account, organization, document versions, acceptance time, and record time. This record does not include your IP address, raw user-agent string, residential address, or telephone number.
A business card stays private to the workspace until an authorized user publishes it. Publishing makes the selected card details and images available to anyone who has its public address, including through its QR code, NFC link, vCard, or Apple Wallet pass. Unpublishing removes the public card from ordinary access without changing its permanent address.
Unpublishing cannot recall vCards, Wallet passes, screenshots, contact records, or other copies that recipients already downloaded or saved.
New tap-event rows do not store raw visitor IP addresses, raw user-agent strings, browser or operating-system names, region, or referrer. Network and security providers may still process connection information to deliver and protect the service.
- Account and organization details, authentication records, legal-document acceptance records, sessions, and security events.
- Service configuration, including Tags, destinations, Pages, Forms, domains, campaigns, and related settings.
- Digital business-card details you choose to provide, including names, professional profile information, biography, email address, telephone number, website, location text, social links, portrait or logo images, visual settings, publication state, and the permanent card address.
- Support correspondence and information needed to investigate a request or incident.
- Customer Form responses, including the fields selected by the Form owner, consent evidence, Form version, and approved source context.
- Minimized public Tag activity, such as time, Tag and organization references, QR or NFC source, coarse country, device class, and configured campaign or routing attribution.
- Stripe Checkout, customer, subscription, invoice, and refund references; the selected plan and billing interval; the selected province or territory; personal-or-business purchase purpose and confirmation; and legal-document versions.
- For a completed live subscription, taaap stores the final CAD subtotal, final tax amount, total charged, completion time, exact accepted Terms and Billing text, and a SHA-256 digest in an immutable contract record. Stripe handles purchaser names, billing addresses, telephone numbers, full payment-card information, purchaser tax identifiers, and detailed tax-calculation inputs used in Checkout; taaap does not copy those fields into its application database.
3. Why we use information
- Create and operate accounts and organizations.
- Deliver requested QR, NFC, Page, Form, digital business-card, vCard, Apple Wallet, routing, and analytics functions.
- Authenticate users, prevent abuse, protect tenants, and investigate incidents.
- Respond to support and privacy requests.
- Create and administer customer-authorized subscriptions, reconcile payment status, provide a retainable contract record, provide billing support, and maintain records required by law.
4. Service providers and international processing
We use service providers for infrastructure, public traffic delivery, domain and security services, transactional email, optional sign-in, and Stripe billing. Current providers can include IONOS, Cloudflare, Resend, Google, Apple, and Stripe, depending on the feature you use.
Providers may process information outside Canada, where it can be subject to foreign law and lawful access. We do not promise Canada-only processing. We do not sell personal information or use customer Form contents to train AI models.
Customer exports and third-party destinations are controlled by the customer and are subject to their own practices.
5. Retention and deletion
Form submissions receive a retention deadline from the workspace plan when accepted. Public Tag analytics are retained according to the current plan and operational cleanup schedule. Expired records are removed by scheduled bounded cleanup jobs.
Completed subscription contract records are kept while needed to administer the subscription, provide the purchaser's transaction record, meet accounting or legal obligations, or handle a dispute. They are immutable and cannot be edited or deleted through ordinary product controls. Contact our Privacy Lead about applicable access, correction, or deletion rights.
Account, organization, business-card content and media, configuration, security, support, and audit records are kept while needed to provide and protect the service, meet documented legal obligations, or handle a dispute. Authentication tokens and sessions use shorter operational expiry periods.
Deletion from backups and provider systems may take longer than deletion from active systems, and providers may keep limited records for security or legal obligations. We do not promise same-day deletion from every backup or provider system.
6. Your choices and requests
Contact [email protected] to request access, correction, information about processing, withdrawal of consent where applicable, or deletion. We verify authority using proportionate steps and do not request identity-document copies by default.
For information submitted to a customer's Form, contact that organization first where practical. We assist within our role and meet our own obligations. You may also complain to the applicable privacy regulator.
Marketing requires separate voluntary consent and a working unsubscribe method. Necessary account, security, and service messages are handled separately.
7. Safeguards, children, and changes
We use organizational and technical safeguards designed for the sensitivity of the information and restrict access to people who need it. No system is risk-free. We assess incidents and provide legally required notices.
Account holders must be adults where they live. Customers must have authority to publish the names, contact details, images, logos, and other business-card content they provide. Customers must not deliberately use taaap Forms to collect children's information. Report suspected inappropriate collection to [email protected].
We will update this notice when our practices materially change and request consent where required.