Privacy Policy
Last updated: 17 July 2026
OneTapCardReview ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website, services, and NFC review card products.
Quick summary: We collect only the data needed to provide our service. We do not sell your data. You have full rights under UK GDPR to access, correct, or delete your data.
1. Who We Are
OneTapCardReview is a UK-based service provider offering NFC-enabled review cards and a review aggregation platform for businesses. Our registered office is in the United Kingdom.
Data Controller: OneTapCardReview
Contact: privacy@onetapcardreview.co.uk
2. What Data We Collect
2.1 Business Account Data
- Business name, address, and contact details
- Administrator name and email address
- Account login credentials (passwords are hashed)
- Payment and billing information
2.2 Review & Analytics Data
- Customer tap/interaction counts (anonymised where possible)
- Review platform links and configuration
- Aggregated review statistics
2.3 Website Usage Data
- IP address, browser type, and device information
- Pages visited and time spent on site
- Referral sources
2.4 Cookies
We use essential cookies for authentication and security. We also use analytics cookies to understand how visitors use our site. See our Cookie Policy for details.
3. How We Use Your Data
We process your data for the following purposes:
- Service provision: To create and manage your account, generate NFC cards, and provide the review aggregation platform
- Analytics: To provide insights on card usage and review collection performance
- Communication: To send account-related notifications, updates, and support responses
- Security: To protect against fraud, abuse, and unauthorised access
- Legal compliance: To comply with applicable laws and regulations
4. Legal Basis for Processing (GDPR)
Under UK GDPR, we process personal data on the following legal bases:
- Contract: Processing necessary to fulfil our service agreement with you
- Legitimate interests: Improving our service, preventing fraud, and ensuring security
- Consent: Where explicitly requested (e.g., marketing communications)
- Legal obligation: Where required by law (e.g., tax records)
5. How Long We Keep Your Data
- Active accounts: Data retained while your account is active
- Closed accounts: Data deleted within 90 days of account closure, except where legal retention is required
- Analytics data: Anonymised after 24 months
- Server logs: Retained for 12 months for security purposes
6. Data Sharing & Third Parties
We do not sell your personal data. We only share data with:
- Hosting providers: For secure server infrastructure
- Payment processors: To process transactions (e.g., Stripe, PayPal)
- Email services: To send account notifications
- Legal authorities: When required by law or court order
All third-party processors are GDPR-compliant and bound by data processing agreements.
7. International Data Transfers
Our primary servers are located in the UK and EU. In cases where data is processed outside the UK/EEA, we ensure appropriate safeguards are in place (e.g., Standard Contractual Clauses).
8. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Access: Request a copy of the data we hold about you
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Limit how we process your data
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests
- Withdraw consent: Withdraw consent at any time (where applicable)
To exercise any of these rights, contact us at privacy@onetapcardreview.co.uk. We will respond within 30 days.
9. Data Security
We implement appropriate technical and organisational measures to protect your data:
- SSL/TLS encryption for all data in transit
- Passwords hashed using bcrypt
- Regular security audits and vulnerability assessments
- Access controls and role-based permissions
- Automated backups with encryption at rest
10. Children's Privacy
Our services are not intended for individuals under 16. We do not knowingly collect data from children. If you believe we have collected data from a child, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Significant changes will be communicated via email.
12. Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact us:
Email: privacy@onetapcardreview.co.uk
Website: onetapcardreview.co.uk