Who we are
Tapme is an AI customer operating system for local businesses. We provide wallet loyalty passes, a merchant CRM, and messaging tools. This policy explains what we collect, why, and the choices you have.
In this policy, "merchant" means a business that uses Tapme to run its loyalty program, and "customer" means a person who joins a merchant's program and receives a wallet pass.
Information we collect
Merchant account data — the email, password (stored only as a salted hash, never in plain text), business name, and subscription tier you provide when you sign up.
Customer program data — the name, contact details, visit history, purchase totals, points, tier, and preferences a merchant records or that flow in from a connected point-of-sale.
Wallet & device data — the pass serial numbers and Apple/Google device registration tokens needed to deliver a pass and push updates to it.
Integration data — access tokens and records we receive when a merchant connects a POS or CRM (for example Square, Toast, Shopify). Tokens are used only to sync that merchant's own data.
Usage & analytics — pages viewed and features used, collected via Google Analytics to help us improve the product.
How we use information
To operate the loyalty program: issue passes, award points, track visits, and deliver rewards.
To send messages a merchant configures — SMS, email, and wallet notifications — subject to the recipient's consent and the guardrails (quiet hours and daily caps) each merchant sets.
To provide AI features such as the concierge and campaign planning. When these features run, the relevant prompt is sent to our AI provider to generate a response; it is not used to train third-party models.
To bill subscriptions, prevent abuse, secure the service, and comply with law.
How we share information
We do not sell personal information. We share it only with service providers who process it on our behalf — our hosting, database, email (Resend), SMS (Twilio), payments (Stripe), and AI providers — and only as needed to run the service.
Each merchant sees only the data belonging to its own program. Customer data is isolated per business and never shared across merchants.
We may disclose information if required by law or to protect the rights, property, or safety of Tapme, our users, or the public.
Data retention
We keep account and program data for as long as the account is active. When a merchant closes an account we delete or de-identify its data within 90 days, except where we must retain records for legal or accounting reasons.
Your choices & rights
Customers can leave a program at any time and stop messages by replying STOP to a text or using the unsubscribe link in an email; their consent state is recorded and honored.
Depending on where you live, you may have rights to access, correct, export, or delete your personal information. Merchants can act on these for their own customers from the portal, or you can contact us and we will help.
Security
Passwords are hashed with scrypt. Sessions use signed, HttpOnly cookies. Access to data is scoped to the owning business at every layer. No system is perfectly secure, but we work to protect your information with appropriate safeguards.
Contact
Questions about this policy or your data? Email privacy@tmitechai.com and we'll respond promptly.