Skip to main content

Privacy Policy

TapTally is operated by Lexom Inc. ("Lexom", "TapTally", "we", "us", or "our"). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when businesses and customers use TapTally.

Last updated:

Collect less

We collect the business, staff, customer, visit, reward, and technical data needed to run TapTally.

Use clearly

We use data to provide loyalty cards, prevent misuse, support accounts, improve the service, and communicate with users.

Canadian focus

We design this policy around PIPEDA principles and applicable Canadian provincial privacy laws.

01

Scope

This policy applies to TapTally websites, the owner portal at portal.taptally.ca, generated customer links that may use go.taptally.ca, and related services we provide for digital loyalty cards, stamp tracking, reward redemption, and business dashboards.

Businesses that create loyalty programs through TapTally are responsible for the offers they publish and for giving their customers any additional notices required for their specific loyalty program.

02

Information We Collect

  • Business and account information: business name, owner or staff name, email address, phone number, login credentials, plan details, business profile, and support messages.
  • Loyalty program information: reward rules, stamp counts, locations, QR/NFC links, staff permissions, redemption notes, and program settings.
  • Customer loyalty information: customer identifiers needed to open or recover a loyalty card, stamp and reward progress, visit history, and redemption status.
  • Payment and billing information: subscription status, invoices, billing contact details, and payment processor records. We do not intend to store full payment card numbers on TapTally servers.
  • Technical and usage information: IP address, device/browser type, pages viewed, approximate location derived from IP, error logs, analytics events, and security signals.

03

How We Use Information

  • Create and manage business accounts, staff access, loyalty cards, stamps, rewards, and customer links.
  • Provide the owner portal, customer card pages, QR/NFC flows, support, troubleshooting, and account notifications.
  • Prevent fraud, misuse, duplicate accounts, unauthorized access, and abuse of loyalty rewards.
  • Measure product performance, improve onboarding, understand repeat-visit behavior, and decide which MVP features to build next.
  • Process subscriptions, billing, taxes, receipts, plan changes, renewals, cancellations, and failed payment notices.
  • Comply with legal obligations, enforce our terms, and respond to lawful requests from courts, regulators, or government authorities.

04

Consent and Canadian Privacy Principles

TapTally is designed around Canadian private-sector privacy principles, including accountability, identifying purposes, meaningful consent, limiting collection, limiting use and retention, safeguards, openness, individual access, and challenging compliance.

We seek to explain what we collect, why we collect it, who we share it with, and what choices are available. Where express consent is required by applicable law, we will seek express consent. Consent may be withdrawn where legally and contractually possible, though withdrawal may limit access to parts of TapTally.

05

SMS Consent and Phone Numbers

If you provide your phone number for TapTally owner portal onboarding or account verification, we use it to send one-time verification codes and account security messages. Message frequency varies based on onboarding and account verification activity. Carrier message and data rates may apply.

SMS opt-in data and consent are used only to provide TapTally verification and account security messaging. We do not sell, rent, share, or transfer SMS opt-in data or consent with third parties for marketing or promotional purposes.

You can reply STOP to stop receiving verification texts or HELP for help. If you opt out of verification texts, some account access or recovery features may not work until another verification method is available or you opt back in.

06

Service Providers and Sharing

We do not sell personal information. We may share information with service providers and partners only as needed to operate TapTally.

  • Cloud hosting, database, authentication, storage, security, and infrastructure providers.
  • Payment processors, subscription management tools, accounting providers, and tax tools.
  • Analytics, product monitoring, email, support, and customer communication tools.
  • Professional advisors, insurers, auditors, law enforcement, regulators, or courts where required or appropriate.
  • A business account and its authorized staff, where a customer joins that business's TapTally loyalty program.

07

Business-Customer Data

When a customer joins a loyalty program through a business using TapTally, the business may see the customer's loyalty-card status, stamps, reward progress, redemption activity, and identifiers needed to operate that program.

Businesses must use customer information only for lawful loyalty, rewards, support, and customer-service purposes. Businesses should not upload information to TapTally unless they have the right to do so.

08

Cookies and Analytics

TapTally may use cookies, local storage, and similar technologies for essential site functionality, authentication, security, analytics, and product improvement. Analytics helps us understand page views, button clicks, device type, referral source, approximate geography, and feature usage.

You can control cookies through your browser settings. Disabling some cookies may affect portal sign-in, saved sessions, or product functionality.

09

Retention

  • Active business accounts: retained while the account remains active and as needed to provide TapTally.
  • Customer loyalty data: retained while needed for the loyalty program, business reporting, fraud prevention, legal compliance, or a reasonable backup period.
  • Deleted or closed accounts: removed from active systems within a reasonable period, subject to legal, tax, fraud-prevention, dispute, and backup retention requirements.
  • Aggregated or anonymized data: may be retained to improve TapTally, measure product performance, and understand business trends without identifying an individual.

10

Security

We use administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, collection, use, disclosure, copying, modification, disposal, or destruction.

No internet service can be guaranteed perfectly secure. Businesses and staff are responsible for keeping credentials confidential and limiting staff access to people who need it.

11

International Transfers

TapTally may process and store information in Canada, the United States, or other countries where our service providers operate. When information crosses borders, it may be subject to the laws of that jurisdiction.

We use contractual, technical, and organizational measures designed to keep service providers accountable for the personal information they process for TapTally.

12

Your Privacy Rights

Subject to applicable law, you may request access to your personal information, correction of inaccurate information, withdrawal of consent, deletion where available, and information about how we handle your data.

To exercise privacy rights, contact privacy@taptally.ca. We may need to verify your identity before responding.

13

Quebec and Provincial Privacy Rights

Where Quebec's private-sector privacy law or another substantially similar provincial privacy law applies, additional rights and obligations may apply, including rights related to access, rectification, portability, withdrawal of consent, de-indexation or cessation of dissemination in certain cases, and privacy impact assessments for certain projects.

TapTally's designated privacy contact is reachable at privacy@taptally.ca.

14

Children and Minors

TapTally is intended for local businesses and their customers. We do not knowingly create TapTally business owner accounts for children under 13. If a loyalty program is used by a minor, the business operating that program is responsible for any notices or consents required for its customer relationship.

15

Breach Notification

If we become aware of a breach of security safeguards involving personal information under our control, we will assess the incident and notify affected individuals, businesses, privacy regulators, or other parties where required by applicable law.

16

Changes and Contact

We may update this Privacy Policy as TapTally evolves. The updated version will be posted on this page with a new last-updated date.

For privacy questions, contact privacy@taptally.ca. For general business questions, contact hello@taptally.ca.