TAPIN PRIVACY POLICY
Effective Date: September 8, 2026
1. INTRODUCTION
TapIN ("TapIN," "we," "us," or "our") operates a proximity-based social connection platform designed to facilitate in-person meetups among verified users ("Platform"). This Privacy Policy describes how we collect, use, disclose, and retain information about you when you use the TapIN mobile application and related services (collectively, the "Services").
By downloading, installing, or using the Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this Privacy Policy, you must discontinue use of the Services immediately.
This Privacy Policy is incorporated into and made part of TapIN's Terms of Service. Capitalized terms not defined herein have the meanings ascribed to them in the Terms of Service.
2. INFORMATION WE COLLECT
A. Information You Provide Directly
Account Information: When you register for the Services, we collect your full name and mobile phone number. You may optionally provide a profile photograph, a short biographical description ("bio"), your city or general location, and interests.
Verification Information: If you elect to verify your university student status, we collect your university email address and a one-time verification passcode. Your email address, verification status, and verification timestamp are retained to validate and annually re-confirm your student badge.
User-Generated Content: We collect posts, photographs, comments, ratings, and any other content you create or submit through the Platform, including TapIN history posts and pod content.
In-App Communications: We collect the content of messages you send and receive through the Platform's in-app messaging feature. Messages are stored to enable delivery and to support safety investigations in accordance with our Trust & Safety program.
Safety Reports: If you submit a report about another user or about content appearing on the Platform, we collect the details of that report, including any written description you provide and the identity of the reported user or content.
Linked Contacts (Optional): If you choose to use the "Linked Contacts" feature, you may grant the Platform access to your device's local contact list. We collect phone numbers from your contact list solely to identify existing TapIN users you may know and to suggest connections. Phone numbers belonging to individuals who are not TapIN users are not stored on our servers beyond the duration of the initial matching process and are deleted immediately thereafter.
B. Information Collected Automatically
Device and Technical Data: We automatically collect certain technical information about the device you use to access the Services, including device model, operating system version, application version, unique device identifiers (such as the IDFA or Android Advertising ID where applicable), crash logs, and diagnostic data.
Push Notification Tokens: We collect push notification tokens issued by Apple Push Notification service (APNs) or Google Firebase Cloud Messaging (FCM) to deliver push notifications to your device. These tokens are associated with your account and refreshed automatically.
Usage and Interaction Data: We collect information about how you interact with the Services, including screens viewed, features used, tap events, session duration, and other in-app behavioral signals. This data is used to operate, maintain, and improve the Services.
Location Data: The Platform uses proximity-based matching to surface users near you. To enable this functionality, we collect approximate location data derived from your device's GPS, Wi-Fi, or cell-tower signals. We collect this data only while you are actively using the Services and only if you have granted location permissions. We do not share your precise GPS coordinates with other users; proximity is communicated in approximate terms only. You may revoke location permissions at any time through your device's system settings; however, doing so will disable proximity-based features.
C. Information We Do Not Collect
We do not collect payment card numbers or financial account information. We do not collect biometric identifiers such as fingerprints or facial recognition data. We do not knowingly collect personal information from individuals under the age of 18.
3. HOW WE USE YOUR INFORMATION
Service Delivery and Core Features
We use your information to create and maintain your account, authenticate your identity, enable TapIN connections and proximity matching, facilitate in-app messaging, surface the TapIN History feed, manage pod memberships, and otherwise provide the core functionality of the Platform.
Trust, Safety, and Enforcement
We use account activity data, safety reports, and behavioral signals to operate our Trust Score system, process user-submitted reports, apply our Community Guidelines, and take enforcement actions — including temporary restrictions, account suspension, or permanent removal — when those Guidelines are violated. Our trust and safety team reviews flagged accounts and may take both automated and manual enforcement actions. Enforcement decisions may be made without prior notice where we determine that user safety requires immediate action. Users who believe an enforcement action was taken in error may submit a written appeal to privacy@tapin.fun. Appeals are reviewed by a human member of our trust and safety team within 14 business days.
Identity and Student Verification
We use your phone number and verification code at registration to confirm your identity. We use your university email address and the associated verification timestamp to validate your student status and to remind you of annual re-verification requirements.
Communications and Notifications
We use your device push notification token to deliver push notifications related to your account activity, new messages, TapIN connections, and safety alerts. You may manage your notification preferences within the app at any time.
Analytics, Research, and Product Improvement
We use usage data, crash logs, and diagnostic information to understand how the Platform is used, identify and fix bugs, measure feature performance, and develop improvements. Where possible, this analysis is conducted on aggregated or pseudonymized data.
Legal Compliance and Rights Protection
We may use your information to comply with applicable laws and regulations, respond to subpoenas, court orders, or other legal process, enforce our Terms of Service, investigate potential violations, and protect the rights, property, and safety of TapIN, our users, and the general public.
We do not use your personal information to serve interest-based or behavioral advertisements. We do not sell your personal information to advertising networks or data brokers.
4. SMS & TWO-FACTOR AUTHENTICATION
We use text messages (SMS) for two purposes: confirming that you control the phone number you register with, and, if you choose, adding a text-message security code as a second step when you sign in with a username and password. This section describes both uses, how consent works, and how to opt out.
Phone Verification (Account Sign-Up)
When you register for the Services, we send a one-time passcode by text message to the phone number you provide, to confirm that you own and control that number. Completing this step is required to create an account and cannot be disabled, as it is our primary method of confirming account ownership.
Two-Factor Authentication (Sign-In)
If you sign in using a username and password, we may send a one-time text-message code as a second verification step before completing sign-in. This feature is enabled by default when you create your account. You may turn it off, or back on, at any time from Profile → Login & Security within the app. When turned off, sign-in proceeds with your password alone.
Consent, Message Frequency, and Charges
By providing your phone number and completing registration, you consent to receive the phone-verification text described above. If two-factor authentication is enabled on your account, you separately consent to receive a text message each time you sign in with your username and password; you may withdraw this consent at any time using the in-app toggle described above, which takes effect immediately for all future sign-ins.
Message frequency varies and is tied to your own activity — you will only receive a text when you register or when you sign in with two-factor authentication enabled. Message and data rates may apply, depending on your mobile carrier and plan.
No Third-Party Sharing of Mobile Opt-In Data
Text messaging originator opt-in data and consent — meaning the fact that you agreed to receive the messages described in this section — are not shared with any third parties for marketing or promotional purposes. This information is used solely to deliver the account-verification and sign-in security messages described above.
Safety Alerts to Your Trusted Contacts
If you use the Platform's Live Location Sharing or SOS safety features, we send an email containing a live-tracking link to the email addresses you have added as your own trusted contacts. These alerts are sent only at your direction (or, for missed check-ins, by an automated trigger you configured) and only to addresses you have personally added — never to other TapIN users generally. The link opens a web page that shows your approximate position for up to four hours or until you stop sharing; your position is updated while the TapIN app is open on your device. Your trusted contacts do not need a TapIN account. The names, email addresses, and any phone numbers you enter for trusted contacts are stored solely to deliver these alerts and are deleted with your account.
5. HOW WE SHARE YOUR INFORMATION
With Other Users of the Platform
Your display name, profile photograph, bio, city, interests, Trust Score, and student verification badge are displayed on your public profile and may be viewed by other users on the Platform. Your phone number is never displayed to other users.
Messages you send are visible only to the designated recipient(s). TapIN History posts may be visible to your approved connections, subject to your privacy settings at the time of posting.
With Service Providers
We engage carefully selected third-party service providers to assist us in operating the Platform. These providers are permitted to process your personal data only as directed by TapIN and in accordance with this Privacy Policy and applicable data protection agreements. Categories of third-party service providers include:
- Cloud computing and hosting infrastructure providers
- Push notification delivery infrastructure (Apple APNs, Google FCM)
- Application analytics and crash reporting providers
- Customer support tooling providers
- Email delivery service providers
For Safety and Legal Purposes
We may disclose your personal information to law enforcement agencies, regulators, courts, or other governmental authorities if we have a good-faith belief that disclosure is required or permitted by applicable law, legal process, or governmental request; is necessary to enforce our Terms of Service or defend legal claims; or is necessary to protect the immediate safety of any person.
In Connection with a Business Transfer
If TapIN undergoes or negotiates a merger, acquisition, financing, reorganization, bankruptcy, dissolution, or sale of all or substantially all of our assets, your personal information may be transferred to or evaluated by the counterparty as part of that transaction. We will notify you of any material change in ownership or data-handling practices via an in-app notice or other reasonable means prior to such a transfer becoming effective.
With Your Explicit Consent
We may share your personal information with third parties in ways not described above when you have given us your specific, informed, and unambiguous consent to do so.
We do not sell your personal information to third parties. We do not share your personal information with third parties for their own independent marketing purposes.
6. DATA RETENTION
We retain personal information for as long as your account remains active or as otherwise necessary to fulfill the purposes described in this Privacy Policy, comply with our legal obligations, resolve disputes, and enforce our agreements.
Specific Retention Periods
Account and Profile Data: Retained for the lifetime of your account. When you delete your account from within the app (Profile → Delete Account), your profile, photos, active TapINs, TapIN History, comments, likes, connections, pod memberships, Trusted Circle contacts, location shares, phone number, email address, and login credentials are deleted immediately at the time of your request. Deletion requests submitted by email are processed within 30 calendar days.
In-App Messages: Message content is retained for a rolling 12-month period from the date of transmission. Messages older than 12 months may be archived or permanently deleted at our discretion.
Safety Reports: Reports submitted to our trust and safety team, and records of enforcement actions taken, are retained for a minimum of 24 months from the date of submission. This retention is necessary to support ongoing safety reviews, detect patterns of abuse, and respond to appeals.
Linked Contact Data: Phone numbers of non-TapIN users collected during the contact-matching process are processed ephemerally and are not persisted to our servers.
Device and Technical Data: Crash logs and diagnostic data are retained for up to 90 days. Aggregated analytics data that does not identify individual users may be retained indefinitely.
Deleted Accounts: When you delete your account, the information listed under "Account and Profile Data" above is removed immediately and your account cannot be recovered. Two categories of information are retained in anonymized form because they belong to other users' records: (1) direct messages you sent remain in your recipients' conversations, attributed to a "Deleted Account" placeholder with no name, username, or photo — copies of those messages already exist on your recipients' devices, and no new messages can be sent to a deleted account; and (2) where another user logged a TapIN meetup with you, their record retains a "Deleted Account" placeholder in place of your name and photo. Safety reports are retained as described above. We may also retain information where required by law, by legitimate safety obligations, or to resolve pending disputes or enforce outstanding legal claims. Anonymized or aggregated data derived from your activity may be retained after deletion.
7. YOUR RIGHTS AND CHOICES
Access and Correction
You may review, update, and correct most of your account information at any time via the Profile and Edit Profile screens within the app. For information that cannot be updated in-app, contact us at privacy@tapin.fun.
Notification Preferences
You may opt out of push notifications at any time through the Notification Settings screen in the app or through your device's system-level notification settings.
Location Data
You may revoke the app's access to your device's location at any time through your device's privacy settings. Revoking location access will disable proximity-based features but will not otherwise affect your ability to use the Platform.
Account Deletion
You may permanently delete your account and associated personal data at any time from within the app: open your Profile, scroll to the bottom, and tap Delete Account. You will be asked to confirm; deletion then takes effect immediately and cannot be undone. See "Data Retention" above for exactly what is removed and the limited placeholder information that remains in other users' records.
If you are unable to sign in, you may instead request deletion by contacting us at privacy@tapin.fun from the phone number or email address associated with your account. We will process verified email requests within 30 calendar days, subject to any legally required retention periods.
Data Portability
You may request a structured, machine-readable copy of the personal data we hold about you by contacting us at privacy@tapin.fun. We will fulfill verified portability requests within 45 calendar days.
California Residents (CCPA / CPRA)
If you are a resident of California, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the purposes for collection, and the categories of third parties with whom we share it.
- Right to Delete: You may request deletion of personal information we have collected from you, subject to certain exceptions.
- Right to Correct: You may request correction of inaccurate personal information we maintain about you.
- Right to Opt Out of Sale or Sharing: We do not sell or share personal information for cross-context behavioral advertising. If our practices change, we will provide a "Do Not Sell or Share" mechanism.
- Right Against Discrimination: We will not discriminate against you for exercising your privacy rights.
To exercise these rights, contact us at privacy@tapin.fun. We will respond to verified requests within 45 calendar days.
Other U.S. State Residents
Residents of Virginia, Colorado, Connecticut, Texas, Montana, Indiana, Tennessee, Iowa, and other states with comprehensive consumer privacy laws may have rights to access, correct, delete, or obtain a copy of their personal data, and to opt out of certain processing activities. To exercise these rights, contact us at privacy@tapin.fun.
8. CHILDREN'S PRIVACY
The Platform is intended exclusively for users who are 18 years of age or older. We do not knowingly collect, solicit, or retain personal information from any individual under the age of 18. If we learn or have reason to believe that we have inadvertently collected personal information from a minor, we will take prompt steps to delete such information from our systems.
If you have reason to believe that a minor is using the Platform or that we have collected personal information from a minor, please contact us immediately at privacy@tapin.fun.
9. SECURITY
We implement commercially reasonable administrative, technical, and physical security measures designed to protect your personal information from unauthorized access, disclosure, alteration, or destruction. These measures include encryption of data in transit using Transport Layer Security (TLS), access controls limiting data access to authorized personnel, and security monitoring.
Notwithstanding the foregoing, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee the absolute security of your information and expressly disclaim liability for unauthorized access by third parties that is beyond our reasonable control.
In the event we become aware of a security incident that has compromised or is reasonably likely to have compromised your personal information, we will notify you and, where required, the appropriate regulatory authorities in accordance with applicable breach notification laws.
10. THIRD-PARTY LINKS AND SERVICES
The Services may contain links to, or integrate with, third-party websites, maps services, or applications — for example, links that open Apple Maps or Google Maps to provide directions to a Verified Meetup Zone. This Privacy Policy does not apply to those third-party services, and we are not responsible for the privacy practices of any third party.
We encourage you to review the privacy policies of any third-party services you access through or in connection with the Platform before providing them with any personal information.
11. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or the Services we offer. When we make changes, we will revise the "Effective Date" at the top of this document.
For material changes — meaning changes that substantially affect your rights or how we use your personal information — we will provide you with advance notice by displaying a prominent notice within the app, by sending a push notification, or by other reasonably effective means, no less than 14 days before the changes take effect.
Your continued use of the Services following the effective date of any revised Privacy Policy constitutes your acceptance of the changes. If you do not agree with a revised Policy, you must cease using the Services and may request deletion of your account as described in the "Your Rights and Choices" section above.
CONTACT OUR PRIVACY TEAM
Questions about this Policy, data deletion requests, or to exercise your privacy rights — reach us at any time at privacy@tapin.fun.
----------------------------------------------------------------
TapIN Ventures, LLC · West Lafayette, IN This Privacy Policy was last updated on August 21, 2026. For prior versions of this Policy, contact privacy@tapin.fun.