Privacy policy
Last updated 24 August 2026
Tag and Tap puts your contact details on a tag so a stranger can return your dog or your suitcase. That only works if you trust us with the details, so this page is written plainly and says exactly what happens to them.
The short version. You choose which fields on your profile are public; everything else stays private. We do not sell data, we run no advertising, and there are no third-party trackers or analytics in the app or on the tag pages. We never store the IP address of someone who scans your tag.
1. Who we are
Tag and Tap ("we", "us") provides the Tag and Tap mobile app, the NFC tags, and the public profile pages at tagandtaps.com. We are the data controller for the personal data described here. Contact us at support@tagandtaps.com.
2. What we collect, and why
| Data | Why we hold it | Legal basis (UK/EU GDPR) |
|---|---|---|
| Name and email | To create your account, sign you in, and send password resets and lost-pet alerts. | Performance of a contract |
| Password | Stored only as a bcrypt hash. We cannot read it and cannot tell you what it is. | Performance of a contract |
| Profile details | Pet name, breed, photo, vet, medical notes, luggage details, and the contact numbers you enter. These exist so a finder can reach you. | Performance of a contract |
| Tag records | Which tags belong to you, their status, and when they were activated. | Performance of a contract |
| Scan records | The date and time a tag was scanned, and an approximate location. This is the feature that tells you your pet has been found. | Legitimate interests (reuniting you with your property) |
| Push token | An anonymous device identifier so we can send you a scan alert. | Performance of a contract |
| Support messages | To answer you. | Legitimate interests |
Photographs
Photos you upload are stripped of all embedded metadata, including any GPS coordinates your camera recorded, before they are stored. We re-encode every image, so nothing from the original file survives except the picture itself.
3. What is public, and what is not
Every field on a profile has its own public/private switch. A field is only ever shown on the public page if you have switched it on. Sensitive fields — microchip number, medical information, allergies and medication — are private by default, and the app warns you before you make one public.
Your account email, your password, your other profiles, and your scan history are never public under any circumstances.
Public profile pages carry a noindex instruction, and the web address on your
tag is a random string rather than a sequential number. Together these stop search engines
listing your pet's page and stop anyone browsing through other people's profiles.
4. If you scanned someone's tag
You do not need an account, and you are not asked to identify yourself. When a tag is scanned we record:
- The date and time.
- An irreversible hash of your IP address. We use it only to avoid alerting the owner repeatedly if you reload the page. The raw IP address is never written to disk and cannot be recovered from the hash.
- An approximate location (usually the town your mobile network routes through, which is often tens of kilometres away) and whether you were using iOS or Android.
If a pet is marked lost you may be offered a Share my location button. That is entirely your choice. If you tap it, your device's location is sent to the owner for that one pet, and nothing else about you is recorded. If you do not tap it, no precise location is collected.
The owner never sees your identity, your phone number, or your IP address.
5. Who else sees your data
We do not sell personal data and we do not share it for advertising. We use a small number of service providers who process data on our behalf:
- Hostinger — hosting and database storage (EU/UK data centres).
- Expo, Apple and Google — delivery of push notifications. They receive the device token and the alert text, which contains your pet's name.
- Apple and Google — only if you choose to sign in with them, to confirm your identity.
We may disclose data where we are legally required to, or to protect someone's safety.
6. What we deliberately do not do
- No advertising identifiers, and no advertising.
- No third-party analytics or tracking SDKs in the app.
- No cookies on public tag pages.
- No sending a scanner's IP address to a third-party geolocation service.
- No selling or renting of data, ever.
7. How long we keep things
- Account and profiles — until you delete them.
- Scan history — 24 months, then automatically removed.
- Support messages — 24 months.
- Deleted accounts — removed immediately, including photos. Tags are returned to unregistered stock and their web address is changed, so the old link stops working.
8. Your rights
You can access, correct, export, restrict or erase your data, object to processing, and complain to a regulator. Two of these are built into the app so you do not have to ask us:
- Export — Account → Privacy → Download my data.
- Delete — Account → Delete account. This removes everything immediately.
For anything else, email support@tagandtaps.com and we will respond within 30 days. If you are in the UK you may complain to the Information Commissioner's Office.
9. Children
Tag and Tap is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.
10. Security
All traffic is encrypted with HTTPS. Passwords are bcrypt hashed. Sign-in sessions use short-lived tokens that refresh automatically and are revoked when you change your password. Scanner IP addresses are one-way hashed with a secret salt. Access to a profile is checked against its owner on every single request.
No system is perfectly secure. If you find a vulnerability, please tell us at support@tagandtaps.com and we will respond quickly.
11. International transfers
Your data is stored in the UK/EU. Push notification delivery may involve transfers to the United States under Standard Contractual Clauses or an equivalent safeguard.
12. Changes
If we change this policy materially we will tell you in the app before the change takes effect. The date at the top always reflects the current version.