Privacy policy
What TapCub collects on this website and inside the product, why, for how long, who processes it, and the rights you have — for account holders and for visitors of the sites our customers measure.
Last updated Effective
1. Who we are and the two roles we play
TapCub ("we") operates this website, the console at app.tapcub.com and the Analytics, Insights and Chat products. You can reach our privacy contact at [email protected].
We act in two different roles, and your rights depend on which one applies to you:
- Controller — for people who register an account, are invited as members or agents, contact us, or browse this website. We decide why and how that data is processed.
- Processor — for visitors of the websites, apps and mini-programs our customers measure or chat with ("Visitor Data"). The customer is the controller; we process Visitor Data only on the customer's instructions, under these terms and a data processing agreement available on request.
If you are a visitor of a site that uses TapCub and want to exercise your rights, contact the operator of that site first. We help our customers respond within the statutory deadline.
2. Data we collect as controller
Account data. Email address, password hash, display name, optional avatar, language and time-zone preferences, multi-factor settings, sign-in timestamps and the IP address and user agent of each sign-in (kept for security). Members you invite give us their email and name.
Billing data. Plan, order and invoice history, the payment provider used (Stripe, PayPal, Alipay or WeChat Pay), the amount, the provider's transaction reference and, for card payments, the card brand and last four digits returned by Stripe. We never see or store full card numbers.
Support and contact data. Messages you send through the contact form, the partner form, email or the chat on this website, together with your name and email so we can reply.
Product usage. Which console features you use, aggregated into counts that help us prioritise work. We do not run third-party analytics or advertising pixels on the console or on this website; this website is measured with our own cookieless script.
3. Data we process on behalf of customers
Analytics data. For each pageview or event: the page URL and referrer, UTM and ad click-ID parameters present in the URL, user agent, screen-size bucket, language, coarse country or region derived from the IP address, custom events and their properties, and an anonymous visitor identifier. In the default anonymous mode the identifier is computed on our servers as a keyed hash of a daily-rotating salt, the site key, the IP address and the user agent. The full IP address is used in memory for geolocation, rate limiting and bot detection and is never written to the database; at most a truncated form is kept. Because the salt rotates, the same visitor cannot be linked from one day to the next.
Identification mode. A customer can switch a site to identification mode to build user profiles that persist across days. The script then stores a random first-party device identifier in the browser (see the cookies page), and for visitors in regions where the customer's settings require it — the EEA and UK by default — only after the visitor has consented through the customer's banner. If a customer calls identify with their own user ID, or sends profile fields such as a name or email, those are stored as the customer instructs; email and phone fields are encrypted at rest and decrypted only on the profile page or for a data-subject export. Customers must only do this where they have a lawful basis, and the console lets them delete a person and everything linked to them.
Chat data. Message text, image attachments, the email a visitor leaves for an offline reply, the consent record written with the visitor's first message, the visitor context shown to agents (country or region, device type, current page, referrer and the pages viewed in this visit), ratings, and the translation or AI reply produced for a message.
Heatmaps. Click and scroll positions aggregated per page. Heatmaps contain no text the visitor typed and no identifier.
4. How cookieless analytics works
In its default mode the tracking script writes no cookies and nothing to localStorage, sessionStorage or IndexedDB. It sends a request for each pageview or event; everything that identifies "the same visitor" happens on the server and is derived from values the browser sends anyway. Nothing is stored on the visitor's device, which is why the script falls under the "strictly necessary" exemption of ePrivacy Article 5(3) and similar national rules, and why it can run without a consent banner on most sites.
The compliance centre offers two presets per site. The consent-free preset locks the anonymous mode, truncates IP addresses further, limits geography to city level and caps retention. The full identification preset turns on identification mode and requires consent for EEA and UK visitors by default; customers can adjust the region rules. Both presets honour the browser's Do Not Track and Global Privacy Control signals: when either is set, the pageview is counted in aggregate and no visitor identifier is computed or stored.
Being cookieless has a cost that we show honestly in the product: "unique visitors" is an estimate within a day, and it will not match tools that use persistent identifiers. We explain why in detail.
5. Live chat specifics
The chat launcher writes nothing to the device while it is closed. When a visitor opens the window and sends a first message, the widget writes one opaque session token to sessionStorage so the conversation survives a page refresh; the token encodes nothing about the visitor and expires when the tab closes. Visitors can opt in to a 30-day "remember this conversation" setting, which moves the token to localStorage; it is off by default.
Conversation content is personal data by nature. Before the first message, the widget shows a notice naming the site operator and linking to the operator's privacy policy; the notice version is stored with the conversation as a consent record. Agents see the context described in section 3. Sensitive patterns such as card numbers are masked in the inbox by default.
When translation or AI replies are enabled, the current message and the matched knowledge-base snippets are sent to the model provider; the full history is not. The provider is contractually prohibited from training on that data. AI replies are labelled, and a visitor can ask for a human at any time. The chat privacy page explains the legal basis in depth.
6. Cookies and local storage
This website sets no cookies. It writes two localStorage keys only after you act: your language choice and whether you dismissed the announcement bar. The console uses one strictly necessary, httpOnly session cookie to keep you signed in, plus a few interface preferences in localStorage. The analytics script writes nothing; the chat widget writes the session token described above. The complete list with names and durations is on the cookies and local storage page.
7. Purposes and legal bases
Where the GDPR, the UK GDPR or similar laws apply, we rely on:
- Performance of a contract — creating and running your account, billing, support, delivering the features you turn on.
- Legitimate interests — securing the Service (sign-in logs, rate limiting, abuse and bot detection), understanding aggregate usage, defending legal claims. We balance these interests against your rights and keep the data minimal.
- Legal obligation — tax and accounting records, responding to lawful requests.
- Consent — optional product emails, and anything else we ask you about explicitly. You can withdraw consent at any time.
For Visitor Data we process on behalf of customers, the legal basis is the customer's to establish. Under China's Personal Information Protection Law, the customer is the personal information handler and we are the entrusted party; our obligations are set out in the data processing agreement.
8. How long we keep data
Analytics data is kept for the retention period of the customer's plan — 6 months on Free, 12 months on Pro and 24 months or more on VIP plans — or shorter if the customer configures it. Expired data is deleted automatically.
Chat conversations are kept for 30 days on Free, 90 days on Pro, 180 days on VIP 1 and 12 months on VIP 2, then messages, attachments and consent records are deleted together. Customers can delete any conversation immediately.
Account data is kept while the account exists and for 30 days after deletion so the owner can change their mind and export. Billing records are kept as long as tax law requires. Server and security logs are kept for up to 90 days. Backups roll over within 35 days of the data being deleted from production.
9. Sharing and categories of sub-processors
We do not sell personal data and we do not share it with advertisers. We use the following categories of service providers, each bound by a contract that limits them to acting on our instructions:
- cloud infrastructure, databases and object storage used to run the Service and store attachments;
- content delivery for the script, widget and this website;
- payment processors — Stripe, PayPal, Alipay and WeChat Pay — which receive what they need to take your payment;
- transactional email delivery for sign-in, alerts and invoices;
- AI model providers for translation, automatic replies and natural-language questions, under no-training terms;
- notification channels you connect yourself, such as Slack, Telegram or a webhook endpoint.
A current list of sub-processors is available on request, and customers with a data processing agreement are notified before a sub-processor is added. We disclose data to authorities only when legally required, and we tell the affected customer unless the law forbids it.
10. International transfers
Customers can choose the region where a site's data is stored when they create it. Where data leaves the region in which it was collected — for example when a member signs in from another country, or a model provider is located elsewhere — we rely on recognised safeguards such as standard contractual clauses or an adequacy decision, and on encryption in transit. Enterprise customers can require that all processing stays in one region.
11. Your rights
Depending on where you live, you may have the right to access, correct, export, delete or restrict the processing of your personal data, to object to processing based on legitimate interests, to withdraw consent, and to complain to a supervisory authority.
Account holders can exercise most rights directly in the console: edit profile data, download analytics data and chat transcripts, and delete the account. For anything else, write to [email protected]; we respond within 30 days and may ask you to verify your identity.
Visitors of customer sites should contact the site operator. Customers can delete a visitor or an identified person from the console, export their data as JSON, and we support them in meeting the deadline that applies to them. We do not use personal data for automated decisions that have legal or similarly significant effects.
12. Security
All traffic is encrypted in transit. Passwords are stored as salted hashes; multi-factor authentication is available to every account and single sign-on to enterprise accounts. Access inside TapCub is role-based and tenant-isolated, administrative actions are written to an audit log, and production access is limited to staff who need it. Raw IP addresses are never written to the analytics database. We test backups regularly and we notify affected customers of a personal data breach without undue delay and, where the GDPR applies, within 72 hours of becoming aware of it. More detail is on the privacy and security page.
13. Children
The Service is not directed at children under 16, and we do not knowingly collect their personal data as controller. Customers whose sites are directed at children are responsible for complying with the rules that apply to them, including obtaining parental consent where required, and should use the strict privacy preset.
14. Changes to this policy
We update this policy when the product or the law changes. Material changes are announced by email or in the console before they take effect, and the "Last updated" date at the top of this page tells you when it last changed. Earlier versions are available on request.
15. Contact
Questions about this document go to [email protected] or through the contact page. If you are not satisfied with our answer, you can complain to the data protection authority in your country.
Also read