Effective July 26, 2026
This policy explains what Tapd Technologies, Inc. (“Tapd”, “we”, “us”) does with information when you visit tapdtechnologies.com or use the Tapd application. We have written it in plain language on purpose. If anything here is unclear, ask us and we will explain it.
Tapd is operated by Tapd Technologies, Inc., a corporation organized under the laws of the State of Delaware, United States. We are the controller of the personal information described in this policy. Notices can be sent to [Registered notice address to be added] or to assistant@tapdtechnologies.com.
We collect four kinds of information, and no more than we need to run the service.
Account information. Your email address and authentication credentials, plus the name of your restaurant. We use Supabase Auth, so your password is stored as a hash by Supabase and is never visible to us.
Restaurant operating data. The menu items, recipes, preps, ingredients, suppliers, and prices you enter, plus the invoices you upload as photos, PDFs, or CSV files and the line items extracted from them. This is business data rather than personal information, but supplier contacts and similar details can appear inside it.
Technical information. Standard server request data such as IP address, browser user agent, and timestamps, generated automatically when you load a page.
Messages you send us. If you use the contact form or join the waitlist, we keep your name, email address, and anything you write to us.
We use your information to operate Tapd for you: computing per-dish cost and margin, matching invoice lines to your catalog, maintaining price history, sending you the alerts you have asked for, answering your messages, keeping the service secure, and diagnosing faults.
We do not sell your information. We do not share it for cross-context behavioral advertising. We do not use your restaurant's data to train machine learning models, and our AI vendor is contractually barred from doing so with content sent through their API.
When you upload an invoice, we send the image or document to Anthropic's API to read the line items. That extraction is a draft, not a decision. Extracted values land in a pending state and a person on your team confirms them before any price enters your price history. Nothing that affects your numbers happens without a human confirming it.
We use a small number of vendors to run the service. Each one only receives what it needs to do its job, and each is bound by its own contractual obligations to us.
| Vendor | Purpose | Data involved |
|---|---|---|
| Supabase | Hosted Postgres database and authentication | All account and restaurant data |
| Anthropic | Extracting line items from uploaded invoices | Invoice images, PDFs, and the text extracted from them |
| Vercel | Application hosting and delivery | Request metadata such as IP address and user agent |
| Resend (Amazon SES) | Sending transactional and contact-form email | Email address and message contents |
| Clover | Optional point-of-sale integration, only if you connect it | Sales and menu item data from your POS |
We may also disclose information if the law requires it, or to protect our rights or someone's safety. If we are ever part of a merger or acquisition, your data may transfer with the business, and this policy travels with it.
Your data is stored and processed in the United States. If you are outside the United States, using Tapd means your information is transferred there, where privacy laws may differ from those in your country.
All traffic runs over HTTPS. Database access is server-side only: the browser never holds a key that can read tables directly. Every table carries a restaurant identifier and row-level security is enabled and deny-by-default, so one restaurant cannot read another's data. Application routes are behind an authentication gate.
No system is perfectly secure, and we will not claim otherwise. If a breach affects your data, we will tell you promptly and tell you what we know.
We keep your data for as long as your account is open. Confirmed price history is retained while your restaurant is active even if you delete individual records, because the historical series is the thing the product is built around. When you close your account we delete your data within 30 days, except where we are legally required to keep something longer.
Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, or export it in a portable format. Email assistant@tapdtechnologies.com or use the contact page. We will respond within 30 days and we will not charge you or degrade your service for asking.
If you are a California resident, you have the rights to know, delete, correct, and opt out of sale or sharing under the CCPA as amended by the CPRA. We do not sell or share personal information, so there is nothing to opt out of, but the right to know and delete applies and you can exercise it at the address above.
If you are in the European Economic Area or the United Kingdom, you additionally have the right to object to or restrict processing and to lodge a complaint with your supervisory authority. We process your data to perform our contract with you and on the basis of our legitimate interest in operating and securing the service.
We set a session cookie so you stay signed in. That is a strictly necessary cookie and the application does not work without it. We do not use advertising cookies, and we do not run third-party trackers on the marketing site.
Tapd is a tool for businesses and is not directed at anyone under 18. We do not knowingly collect information from children. If you believe a child has given us information, tell us and we will delete it.
If our practices change we will update this page and move the effective date at the top. For a change that materially reduces your rights, we will give you notice by email before it takes effect.
Questions about privacy go to assistant@tapdtechnologies.com or the contact page. A real person reads it.