Data security & privacy Accurate data. And respect for every user's privacy.
Analytics sets no cookies. The compliance centre handles consent, export and deletion. The product is designed for compliance — this page lists only measures that exist and claims no certification it has not earned.
- No analytics cookies
- GDPR / CCPA baseline, China mode on top
- Encrypted in transit, sensitive fields encrypted at rest
International rules as the baseline, China mode on top
GDPR, ePrivacy, CCPA and the GPC signal form the baseline; switch on China mode (PIPL) when you need it, with revocable consent. Consent, opt-outs and data subject requests live in one place.
- Respects the Global Privacy Control signal
- Consent records are timestamped and exportable
- One person's data can be looked up, exported and deleted
- GDPR and ePrivacyThe baseline for consent, purpose limitation and data subject rights.
- CCPA and GPCHonours the Global Privacy Control signal and opt-out choices.
- PIPL (China)Switch on China mode above the baseline, including revocable consent.
- Export and deleteLook up, export or delete one person's data in the compliance tools.
Compliance centre · acme-web
ConfiguredApplicable mode
Collection and consent
- Cookieless analyticsNo analytics cookies, always on
- Respect GPC signalNo identification when the browser opts out
- Identification (logged-in users)Requires you to pass a user ID
- Encrypt contact detailsPhone and email encrypted at rest
- Chat session recordingOff
Each project states where its data lives
The privacy documents generated for your site reference this region. It is a project setting, not a certification; this page names no city and no audit number.
Your own servers
The machines an on-premise deployment runs on. See enterprise.
European Union
The project region referenced in privacy documents.
United States
The project region referenced in privacy documents.
Mainland China
The project region referenced in privacy documents.
Encryption, masking, retention, export and deletion
Designed for compliance. Only measures that exist are listed.
Encrypted in transit
Traffic between browsers, SDKs and the service is TLS-encrypted end to end.
Sensitive fields encrypted at rest
Phone numbers, emails and other contact details on a profile are encrypted before storage. You switch this mode on.
Masking by role
Sensitive values can be hidden or partially shown depending on who is looking.
Export and deletion
The compliance centre can look up, export or delete everything about one person, and records the action.
Data retention
Analytics data is kept according to plan. It is cleared automatically at the end and can be exported beforehand.
| Plan | Retention | Notes |
|---|---|---|
| Free | 6 months | Cleared automatically |
| Pro | 12 months | Export to CSV or via API |
| VIP | 24 months+ | Enterprise by contract |
- 1Enter a user ID or email in the compliance centre
- 2The person's events and properties are found
- 3Export as JSON, or delete with one click and a logged record
Five roles, with an exportable audit log
Viewers read reports. Agents handle chat only and never open analytics. Owners and admins manage members and compliance actions.
Owner and admin
Manage the project, members, chat settings, and compliance exports or deletions.
Analyst
Builds reports and segments, and can enter the chat workspace.
Viewer
Reads reports. Viewers do not take conversations.
Agent
The chat workspace only, with no analytics reports.
Audit log
Member actions can be exported. This is an operating record, not a certification.
Chat data
Conversation content is retained separately and visitors can ask for deletion. See the chat privacy notice.
Need self-hosting?
Keep your data on your own servers. TapCub Enterprise is quoted separately for your security and compliance needs.
About privacy and security
Still have a question?
Chat with the team behind TapCub — we usually reply within a few hours on business days.
Does analytics set cookies?
No. Visits are told apart by a hash that rotates daily and belongs to one site. The browser stores no analytics identifier. See the cookie policy.
Do you publish certification numbers?
No. This page does not claim a completed audit. Controls are designed for compliance; contact sales for current documentation.
Where is the data stored?
Each project has one data region: your own servers, the EU, the US or mainland China. Privacy documents reference it. On-premise deployment is discussed under enterprise.
How long is analytics data kept?
Free 6 months, Pro 12 months, VIP 24 months or more. Chat retention is separate. See pricing.
Can I delete one person?
Yes. The compliance centre can look up, export or delete one person's data. The legal wording is in the privacy policy.
Is identification on by default?
No. Identification must be enabled per site in settings, and you have to pass a user ID. Contact details are stored encrypted and follow the compliance centre settings.