Who we are
This privacy policy applies to all services of Taply B.V., based in Roermond, the Netherlands. Taply provides NFC-based digital receipts to retailers in the Netherlands and Belgium.
- Company name: Taply B.V.
- Address: Roermond, the Netherlands
- Chamber of Commerce (KVK) number: [KVK NUMBER TO BE ADDED]
- VAT number: [VAT NUMBER TO BE ADDED]
- Privacy email: info@taplyreceipts.com
- Website: taplyreceipts.nl
What personal data we collect
We only collect the data needed to deliver our service. Concretely, these are the following categories:
Account data
First name, business name, business email address, hashed password. Optional: KVK and VAT number, address details, phone number.
Receipt data
Per transaction: amount, line items, date, timestamp, payment method. This data comes directly from your POS system and is linked to your account, not to the end customer — unless they voluntarily leave their email.
End-customer data (only with explicit opt-in)
When a customer enters their email address on the receipt page, we store that address, the time and the associated receipt. Consent is requested explicitly.
Payment data
Payments run through Stripe. We only receive transaction confirmations and the last four digits of your payment method — no full card details.
Technical data
IP address, browser type, operating system, session cookies, date/time of visit. For analytics we use anonymised variants wherever possible.
For which purposes we use this data
- Service delivery: creating your account, delivering receipts, showing the dashboard.
- Billing: subscription payments via Stripe, VAT-compliant invoices.
- Support: answering your questions via email or chat.
- Marketing: only with opt-in — product updates, tips, offers.
- Fraud prevention and security: detecting unusual patterns, protecting accounts.
- Legal obligations: fiscal retention duty, responding to legal requests.
Legal basis for processing
We process your data on the basis of one or more of the following legal grounds:
- Performance of the contract — for everything needed to deliver Taply as a service.
- Legitimate interest — for security, fraud prevention, product improvement and business administration.
- Consent — for marketing emails and non-functional cookies (voluntary, revocable).
- Legal obligation — for the fiscal retention duty and legally required information requests.
Who we share data with
We never sell your data. We only share it with third parties needed for the service, and exclusively under a data processing agreement (DPA):
- Stripe (payments) — card details are processed at Stripe, not stored with us.
- Supabase (database, authentication) — our data infrastructure, hosted within the EU/EEA.
- Vercel (hosting) — our web hosting, with EU edge locations where possible.
- Competent authorities — only when legally required, and only after careful review.
International transfers
Personal data is in principle processed exclusively within the EU/EEA. Our database and authentication run on servers within the EU/EEA. Should a transfer outside the EU/EEA incidentally be needed — for instance for a third-party tool — it only happens under appropriate safeguards such as the European Commission's Standard Contractual Clauses.
Retention periods
- Account and billing data: 7 years after the end of your subscription, based on the fiscal retention duty.
- Receipt data: 7 years, likewise based on the fiscal retention duty.
- Marketing opt-ins: until you unsubscribe. After that only a minimal suppression list (email address, date) so we do not contact you again.
- Support correspondence: 3 years for quality assurance and legal protection.
- Logs and technical data: 90 days, then anonymised or deleted.
Security
We take appropriate technical and organisational measures to protect your data. Among others:
- TLS/SSL encryption for all network traffic.
- Encryption at rest at database level (AES-256).
- Access strictly limited to employees who need it for their work.
- Passwords are stored hashed (bcrypt/argon2 via Supabase Auth).
- Regular backups and monitoring for suspicious activity.
Your rights
Under the GDPR you have the following rights regarding your personal data:
- Right of access
- Right to rectification
- Right to erasure (right to be forgotten)
- Right to restriction of processing
- Right to data portability
- Right to object
- Right to withdraw given consent at any time
You can send requests to info@taplyreceipts.com. We respond within one month, often sooner. A request to withdraw marketing consent is processed immediately.
Cookies
For a detailed overview of the cookies we use — strictly necessary, functional, analytical and marketing — please see our Cookie policy.
Changes to this policy
We may amend this privacy policy from time to time. For significant changes we will inform you by email. The most recent version can always be found on this page, with the date of the last update at the top.
Contact and right to complain
Questions about this policy or the way we handle your data? Send us an email at info@taplyreceipts.com.
You also always have the right to lodge a complaint with the Autoriteit Persoonsgegevens — the Dutch data protection authority.
Questions about this document? Email info@taplyreceipts.com.