TapCard

Privacy Policy

Last updated: 1 October 2026 · AIERT Ltd

Summary

TapCard has no accounts, no advertising and no tracking, and its only analytics is an anonymous count of taps on our own app promotions (see below). Your card stays on your iPhone until you tap Share my card. Sharing publishes a copy at a private link so other people can view and save it, and Stop sharing deletes that copy from our servers.

Who we are

TapCard is provided by AIERT Ltd, registered in England & Wales (No. 16587000), which is the data controller for the information described here. Contact: enquiries@aiert.co.uk.

On your iPhone only

Your cards are stored locally in the app. Until you share a card, nothing in it leaves your device. If you use Fill in from Contacts, iOS lets you pick one contact and gives TapCard only that contact; TapCard does not get access to the rest of your address book. Photos you choose are handled the same way, through the system photo picker.

If you tap Add missing details to my contact, TapCard asks for Contacts access (on iOS 18 and later you can allow just your own contact), shows you which details from your card are missing from that contact, and adds only the ones you tick. It never removes or changes anything already in the contact, and this all happens on your iPhone. Nothing from your contacts is sent to us.

When you share a card

Tapping Share sends a copy of that card to our server so it can be shown at its link, QR code and Apple Wallet pass:

  • name, job title, company, phone, email and website
  • social links (LinkedIn, X, Instagram, Facebook, TikTok) you added
  • your card photo, if it has one, resized before upload
  • the card's label (for example "Business")
  • a random identifier created by the app, used only so Wallet can group your passes together. It is not your device's advertising identifier or any Apple identifier.
  • a secret edit key for that card, stored only as a one-way hash, so that only your app can change or delete it

Edits you save to a shared card are sent the same way so the link stays up to date. To limit abuse, when a card is first shared we keep a one-way hash of the sending IP address to cap how many cards can be created in an hour. We never store the IP address itself.

Who can see a shared card

Anyone who has the link, scans the QR code or has the Wallet pass can see the card and save it as a contact. The link is long and random, and the page asks search engines not to index it, but it is not password protected, so only share it with people you are happy to give those details to.

The card page counts how many times it has been opened and saved, and those two numbers are shown to you in the app. We do not record who viewed or saved it.

Counting interest in our other apps

When you tap the MailBroom or PowerSearch promotion inside TapCard, the app tells our server which one was tapped and whether it was on iPhone or Android. It sends nothing else: not your card, your name or any device identifier. Our server stores that with the approximate country, a shortened IP address (the last part removed, so it can't identify you) and the app and system version, so we can count how many people are interested. Taps on the TapCard, MailBroom and PowerSearch links on a shared card page are counted the same way. None of this is linked to you or used to track you.

Founder places and the lifetime unlock

The first 1,000 people get TapCard free for life. To count them, the app sends our server Apple's signed record of when your Apple ID first downloaded TapCard. We keep only a one-way hash of its identifier, that download date, your place in the count and the price offered to you. It contains no name, email or card details, and isn't used to track you. Lifetime unlock purchases are handled by Apple; we never see your payment details.

Service providers

  • Vercel: hosts the TapCard website and API, and stores card photos.
  • Neon: hosts the database that holds shared cards.
  • Google: the app and the card page show your company's logo using Google's public favicon service, which receives your website's domain and the viewer's IP address, as with any image loaded from Google.
  • Apple: the in-app links to our other apps open Apple's own App Store banner, and Wallet passes are handled by Apple Wallet.

We do not sell or rent your information, or share it with anyone for advertising.

How long we keep it, and deleting it

A shared card stays online until you tap Stop sharingin the app. That permanently deletes it from our database and deletes its photo, and the link, QR code and Wallet pass stop working. When you replace a card's photo, the old one is deleted. Deleting the app does not delete a card that is still shared, so stop sharing first, or email us with the card's link and we will delete it.

Your rights

Under UK data protection law you can ask for a copy of the information we hold about you, or ask us to correct or delete it, by emailing enquiries@aiert.co.uk. You can also complain to the Information Commissioner's Office (ico.org.uk).

Reporting a card

If a TapCard link shows something abusive or impersonates you, use the Report this card link on the card page or email us, and we will review and remove it.

TapCard for Business

Company cards set up through TapCard for Business are covered by this policy too. How company accounts, staff invites and company cards are handled is explained on the TapCard for Business security & privacy page.

Children

TapCard is a business-card tool and is not directed at children under 13.

Changes

If this policy changes materially, we will update the date at the top of this page.