TapCub is live — analytics, insights and live chat, free on one platform

Data security & privacy Accurate data. And respect for every user's privacy.

Analytics sets no cookies. The compliance centre handles consent, export and deletion. The product is designed for compliance — this page lists only measures that exist and claims no certification it has not earned.

  • No analytics cookies
  • GDPR / CCPA baseline, China mode on top
  • Encrypted in transit, sensitive fields encrypted at rest
Cookieless analytics

No analytics cookie in the browser

Visits are told apart by a hash salted daily on the server: the site, the day's salt, a truncated IP and the browser signature produce one value, and tomorrow it changes. The browser stores no analytics identifier at all.

  • No analytics cookies, no local storage
  • The hash rotates daily and belongs to one site only
  • IP addresses are truncated before storage; the original never lands
  • Search crawlers stay on the bot row
app.tapcub.com

How the visitor identifier is computed

  • Sitesite=acme-web
  • Daily saltsalt=2026-10-02 · rotates daily
  • Truncated IP203.0.113.0/24
  • Browser signatureUA · language · time zone

Today's visitor hash

a91f…3c7e

The salt changes tomorrow, so does the hash — no cross-day tracking

Nothing in the browser: no cookie, no local storage

The raw IP is never stored and cannot be recovered from the hash

Only when identification is enabled for logged-in users is the hash linked to the user ID you pass in. You switch that on in site settings.

Sample data
Compliance centre

International rules as the baseline, China mode on top

GDPR, ePrivacy, CCPA and the GPC signal form the baseline; switch on China mode (PIPL) when you need it, with revocable consent. Consent, opt-outs and data subject requests live in one place.

  • Respects the Global Privacy Control signal
  • Consent records are timestamped and exportable
  • One person's data can be looked up, exported and deleted
  • GDPR and ePrivacyThe baseline for consent, purpose limitation and data subject rights.
  • CCPA and GPCHonours the Global Privacy Control signal and opt-out choices.
  • PIPL (China)Switch on China mode above the baseline, including revocable consent.
  • Export and deleteLook up, export or delete one person's data in the compliance tools.
app.tapcub.com/p/acme/compliance

Compliance centre · acme-web

Configured

Applicable mode

International (GDPR / CCPA)+ China modeChina only

Collection and consent

  • Cookieless analyticsNo analytics cookies, always on
  • Respect GPC signalNo identification when the browser opts out
  • Identification (logged-in users)Requires you to pass a user ID
  • Encrypt contact detailsPhone and email encrypted at rest
  • Chat session recordingOff
Data subject requests · 2 this monthExport / delete
Sample data
Data regions

Each project states where its data lives

The privacy documents generated for your site reference this region. It is a project setting, not a certification; this page names no city and no audit number.

Your own servers

The machines an on-premise deployment runs on. See enterprise.

European Union

The project region referenced in privacy documents.

United States

The project region referenced in privacy documents.

Mainland China

The project region referenced in privacy documents.

Data security

Encryption, masking, retention, export and deletion

Designed for compliance. Only measures that exist are listed.

Encrypted in transit

Traffic between browsers, SDKs and the service is TLS-encrypted end to end.

Sensitive fields encrypted at rest

Phone numbers, emails and other contact details on a profile are encrypted before storage. You switch this mode on.

Masking by role

Sensitive values can be hidden or partially shown depending on who is looking.

Export and deletion

The compliance centre can look up, export or delete everything about one person, and records the action.

Data retention

Analytics data is kept according to plan. It is cleared automatically at the end and can be exported beforehand.

PlanRetentionNotes
Free6 monthsCleared automatically
Pro12 monthsExport to CSV or via API
VIP24 months+Enterprise by contract
  1. 1Enter a user ID or email in the compliance centre
  2. 2The person's events and properties are found
  3. 3Export as JSON, or delete with one click and a logged record
Sample data
Team security

Five roles, with an exportable audit log

Viewers read reports. Agents handle chat only and never open analytics. Owners and admins manage members and compliance actions.

Owner and admin

Manage the project, members, chat settings, and compliance exports or deletions.

Analyst

Builds reports and segments, and can enter the chat workspace.

Viewer

Reads reports. Viewers do not take conversations.

Agent

The chat workspace only, with no analytics reports.

Audit log

Member actions can be exported. This is an operating record, not a certification.

Chat data

Conversation content is retained separately and visitors can ask for deletion. See the chat privacy notice.

Need self-hosting?

Keep your data on your own servers. TapCub Enterprise is quoted separately for your security and compliance needs.

Talk to sales
FAQ

About privacy and security

Still have a question?

Chat with the team behind TapCub — we usually reply within a few hours on business days.

Does analytics set cookies?

No. Visits are told apart by a hash that rotates daily and belongs to one site. The browser stores no analytics identifier. See the cookie policy.

Do you publish certification numbers?

No. This page does not claim a completed audit. Controls are designed for compliance; contact sales for current documentation.

Where is the data stored?

Each project has one data region: your own servers, the EU, the US or mainland China. Privacy documents reference it. On-premise deployment is discussed under enterprise.

How long is analytics data kept?

Free 6 months, Pro 12 months, VIP 24 months or more. Chat retention is separate. See pricing.

Can I delete one person?

Yes. The compliance centre can look up, export or delete one person's data. The legal wording is in the privacy policy.

Is identification on by default?

No. Identification must be enabled per site in settings, and you have to pass a user ID. Contact details are stored encrypted and follow the compliance centre settings.

See your data clearly. Find your growth.

Every click, backed by data. Install one line of code and see your first numbers in a minute.

No credit card · Free plans for analytics and chat · Cookieless analytics