Security & Privacy for TapCard for Business
Last updated: 6 October 2026 · AIERT Ltd
In short
- Your staff list stays with you. You choose it on your own computer and it is read there. AIERT never uploads or keeps it.
- You send the invites, from your own email. AIERT never emails your staff.
- Each invite link is signed, works once and expires after 30 days.
- Only the employee or your admin can remove a card. Removing it stops its link everywhere, including copies that were forwarded on.
- No advertising, no tracking, and we never sell or share your data for marketing.
What AIERT stores
About your company:
- company name, email domain, website, brand colour and company social links
- your company logo, if you add one
- which card fields employees can and can't edit
- the email address of each admin, so they can sign in
- your plan, billing status and the Stripe customer and subscription references (no card details)
About each employee, only once they activate their card:
- their card: name, job title and email from the invite, the company details above, and anything they add themselves in the app, such as a phone number or photo
- a one-way hash of the card's secret edit key (see below)
For each invite that has been used, we keep only a one-way hash of the invite's random ID and the date, so it can't be used twice. That says nothing about who it was for. Invites that are never used leave nothing behind at all.
What AIERT never stores
- your staff list, or anyone you invited who hasn't activated their card
- staff photos from you. Employees add their own photo in the app if they want one
- payment card details, which are handled entirely by Stripe
How invites work
On the Employees page you choose your staff list: a CSV, or a contacts export from Outlook / Microsoft 365, Google or iCloud. Your browser reads the file on your computer. Only each person's name, email and job title are sent to us, once, to be signed into an invite link. Nothing is saved, and the links come straight back for you to send from your own email.
- Signed:each link carries the person's details and a cryptographic signature (HMAC-SHA256) made with a key only our server holds. Changing any detail, or making up a link, makes it invalid.
- Single use:the first time a link is used to set up a card it is marked as spent, and two taps at once can't both succeed.
- 30-day expiry, after which the link no longer works.
- Kept out of server logs:the details sit after the "#" in the link, a part browsers never send to a server. Only the TapCard app sends them, once, inside the request that sets up the card.
- Seat limits: a card can only be set up while your plan has a free seat and billing is active.
Treat an invite like a password-reset email: until it's used, anyone who has the link could set up that card. If one goes to the wrong person, remove the card on the Employees page and send a new invite.
How cards are protected
- Only the card's owner can change it. When an employee activates their card, their phone receives a secret edit key that never leaves it, except to authorise their own changes. We store only a one-way hash of that key, so changing, deleting or sending a card as that person needs their phone.
- Locked fields are enforced by our server, not just the app,so the company details you lock can't be changed by an old app version or a hand-made request. When you update your template, employees' cards pick up the change.
- Card links are long and random(128 bits) and can't be guessed, and card pages ask search engines not to index them.
Who can see a card, and forwarding
A card is made to be shared: anyone with its link, QR code or Wallet pass can see it and save the contact. Like a paper business card, it can't be stopped from being passed on once someone has it. They could forward the link or save the details. What TapCard does guarantee:
- nobody but the employee can change the card or send it as them
- when the card is removed, its link and QR code stop working everywhere, including forwarded copies. A Wallet pass already saved on someone's phone stays there, as passes do, but no longer updates.
Removing cards and leaving
- Someone leaves: remove their card from the Employees page. It is permanently deleted from our database, along with its photo.
- An employee can remove their own card at any time from the app.
- Only the employee or your admin can do this.AIERT has no admin tool for deleting company cards, and the only ways to delete one need the card's edit key or an admin sign-in for that company.
- If billing lapses,existing cards keep working (we won't break cards your staff are already using), but no new invites can be created or used.
- To close your account and delete your company's data, email enquiries@aiert.co.uk from an admin address.
Admin sign-in
- No passwords to leak: admins sign in with a link emailed to them. It works once and expires after 15 minutes.
- Opening the link doesn't sign you in until you press the button, so email security scanners that open links (such as Microsoft 365 Safe Links) can't use it up.
- Your session is a signed, secure, HTTP-only cookie that lasts 30 days, and scripts on the page can't read it.
- Each admin only ever sees and manages their own company.
Your company logo
You can upload a logo, or use Use logo from website. That button reads the public home page of the website in your template to find your logo, the same way link previews do. It only fetches public pages over HTTPS, never accepts SVG files (which can contain code), and checks the result is a real image before saving it.
Service providers
- Vercel: hosts the TapCard website and API, and stores logos and card photos.
- Neon: hosts the database.
- Stripe: handles subscriptions and payments.
- Resend or Microsoft 365: sends admin sign-in emails.
- Apple and Google: Wallet passes, once an employee adds their card to their wallet.
All connections to TapCard use HTTPS.
Roles and data protection
AIERT Ltd (registered in England & Wales, No. 16587000) runs TapCard. Your company decides who to invite and what goes on your template. Each employee controls their own card once it's activated, as with any TapCard. Under UK data protection law, anyone can ask what we hold about them, or ask us to correct or delete it, by emailing enquiries@aiert.co.uk, and can complain to the Information Commissioner's Office (ico.org.uk). If your organisation needs a data processing agreement or answers to a security questionnaire, email us.
The general TapCard privacy policy covers the app and personal cards.
Reporting a security issue
If you think you've found a security problem, email enquiries@aiert.co.ukwith "Security" in the subject. We'll look at it straight away.