This policy explains how Tapino processes personal data on the website, in the Tapino mobile app, in venue tools, and when you use bookings, orders, event tickets, quizzes, notifications, or support.
The controller for Tapino's own processing is Miletra, a Swedish sole trader, organisation number 650306-9053, Roliasgatan 4, 553 39 Jönköping, Sweden ("Tapino", "we", or "us"). Contact us at support@tapino.app.
2. Our role and the role of venues
Tapino is the controller when we determine why and how data is processed for Tapino accounts, authentication, platform security, support, product operations, our own communications, and payment administration.
A venue is normally the controller for its guests' operational data, such as bookings, orders, event registrations, and guest communications. Tapino then processes that data as a processor on the venue's documented instructions. Read Tapino's Data Processing Agreement. Questions about a particular venue's use of your data should normally be directed to that venue first. You may also contact us and we will help route the request.
3. Personal data we process
Account and profile: name, email, phone number, authentication details, selected sign-in provider, home city, language, age confirmation, and recorded legal acknowledgements.
Demographic profile data: the selected gender option, including a prefer-not-to-say or non-specific option. It is used for broad demographic insight and product development. Individual gender-based advertising or sharing with venues or advertising platforms is not active.
Venue and staff data: business name, organisation or VAT number where provided, address, contact person, role, permissions, invitations, and business settings.
Bookings and events: name, contact details, date, time, party size, table, status, notes, ticket, and event details.
Orders and payments: items, amount, currency, status, receipt, and transaction references. The payment provider processes full card details; Tapino does not store full card numbers.
Quizzes: team or display name, selected symbol, answers, scores, ranking, and participation in a quiz session.
Device and operations: IP address, device and browser type, app version, language, time zone, installation identifier, push token, logs, security events, and limited error and performance data.
Location: the device's precise position when you grant location permission, and city and country that may be derived from it. See section 6.
Support and communications: message content, contact details, and information needed to handle the matter.
4. Sources of data
We receive data directly from you, from the venue or venue staff you interact with, from your device and use of Tapino, and from services you choose to connect, such as Google or Apple sign-in. Business details may be verified with the Swedish Companies Registration Office or the EU VAT validation service.
5. Purposes and legal bases
Where Tapino is a processor, the venue determines the legal basis for processing its guests' operational data.
Purpose
Examples of data
Legal basis
Create and manage accounts and deliver Tapino features
Account, profile, venue, booking, order, event, and quiz data
Contract or steps requested before a contract
Complete and document payments
Amounts, status, transaction, and receipt data
Contract and legal obligations, including accounting
Security, fraud prevention, and abuse prevention
Sign-in, IP address, device, logs, and security events
Legitimate interest in a secure and reliable service and, where applicable, legal obligation
Support, troubleshooting, and reliability
Contact data, support content, app version, and limited diagnostics
Contract and legitimate interest in maintaining and improving the service
Broad demographic insight and product development
Selected gender option and aggregated use
Legitimate interest in product insight, with a non-specific option and the right to object
Local content, nearby venues, and relevant notifications
On-device position and derived city and country
Your choice to grant location permission and our legitimate interest in local relevance; permission can be withdrawn
Optional website and app analytics, advertising, and direct marketing
Pseudonymous app-instance and cookie identifiers, sanitized screen views, generic events, and contact or audience data only where such a feature is expressly activated
Consent where required. Consent can be withdrawn without affecting earlier lawful processing
6. Location and notifications
If you grant location permission, the precise position is used on the device to calculate distance to nearby venues. Tapino does not send precise latitude and longitude as the server query used to find nearby venues.
The app may convert the position into a broader city and country signal and send it to Tapino's server for local content and audience-based notifications. The device location permission currently controls this processing. You can disable it in device settings, but some location-based features will stop working. Push token, installation ID, platform, app version, language, and time zone may be processed to deliver notifications.
7. Cookies, app analytics, and similar technologies
The website uses cookies and similar storage technologies. Necessary technologies support sign-in, security, and essential functionality. Preference technologies remember language and theme. Analytics or marketing technologies are activated only after the required consent.
In Tapino's Android and iOS app, Google Firebase Analytics may be used after a separate in-app choice. Collection is disabled by default. If you allow app analytics, only sanitized screen templates, a coarse area category, and generic events such as registration, completed customer booking, and quiz participation are processed. Automatic screen names, advertising identifiers, ad personalization, and Analytics user IDs are disabled. The choice is stored locally for no more than one year and can be changed under Privacy & Analytics in the app.
With the same optional analytics choice, Tapino may store aggregate counts by venue and day in its own database to measure which venue is entered. This aggregate does not retain an individual visit history, and the venue name or ID is not sent as an Analytics event parameter to Firebase Analytics.
When Google Analytics 4, Google Ads, Meta Pixel, or Firebase Analytics is configured, it is used only according to the relevant cookie or app-analytics choice. Tapino does not send exact URLs, names, contact details, free text, quiz answers, booking, order, account, or venue IDs, exact order values, revenue, venue payouts, or operational data to these providers.
Technologies currently used on the website.
Technology
Provider
Category
Purpose and information
Duration
Cookie choices
Tapino
Necessary
Stores your choices for necessary technologies, analytics, and marketing.
1 year
Language and theme preferences
Tapino
Preference
Remembers the selected language and visual theme between page views.
Up to 1 year or until you change the choice or clear browser data
Sign-in session
Google Firebase
Necessary
Maintains a secure sign-in session and processes authentication and session information.
Until sign-out, account deletion, or browser data is cleared
Local workspace data and drafts
Tapino
Necessary
Keeps workspace preferences, local quiz drafts, and temporarily cached booking information on the device.
For the session or until the item is replaced, deleted, or browser data is cleared
Website analytics
Google Analytics 4
Analytics
Measures general user journeys using sanitized page paths, coarse link and button categories, and 50- and 90-percent scroll thresholds. Exact URLs, order, revenue, payout, customer, and operational data is not sent.
We do not sell personal data. We disclose it only where needed for the service, on a venue's instructions, as required by law, or based on a valid choice from you.
Recipient
Use
Venues and authorised venue staff
Bookings, orders, events, tickets, quizzes, and guest communications for that venue
Google Cloud and Firebase
Authentication, databases, file storage, server functions, security checks, technical operations, and consent-based app analytics when activated
Vercel
Web hosting and server operations for the Tapino website and web APIs
Google Maps Platform
Address and city search, geocoding, and map features
Cloudflare
Turnstile controls against automated signup abuse
Expo
App distribution, updates, and push notification delivery
Sentry
Error and performance monitoring. Tapino disables default PII transmission and filters request data
Stripe
Payment processing when paid checkout is used. Stripe processes card details; Tapino does not store full card numbers
Apple and Google
Optional sign-in, app distribution, and platform services
Google Analytics 4
Consent-based website analytics for sanitized user journeys and coarse interaction categories without exact URLs, transaction, or operational data
Swedish Companies Registration Office and EU VAT validation
Business and VAT registration verification
Authorities, courts, or advisers
Where required by law or needed to establish, exercise, or defend legal claims
9. Processing outside the EU/EEA
Tapino's main production database is configured in the EU eur3 region and server functions in europe-west1. Some providers or their support, security, and delivery functions may nevertheless process data outside the EU/EEA.
For transfers to a country without an adequacy decision, we use applicable safeguards such as the European Commission's Standard Contractual Clauses, the EU–US Data Privacy Framework for certified recipients, and supplementary technical or organisational measures. Contact us for information about a particular transfer.
10. How long data is kept
We keep data for as long as necessary for its purpose and determine retention using these criteria:
Account data is kept while the account is active and for a limited closure and security period afterwards.
Venue-controlled guest data is kept under the venue's documented instructions and Tapino's Data Processing Agreement.
Booking, order, payment, and transaction records may be retained longer where accounting rules, disputes, refunds, or other legal requirements apply. Data may then be restricted or anonymised.
Support, security, and diagnostic data is retained as needed for the matter, abuse prevention, and incident investigation.
Notification messages, delivery diagnostics, and location-derived city signals have limited operational retention and are removed or replaced when no longer needed.
Acceptance, policy-version, and contract logs may be retained as needed to demonstrate what applied and handle legal claims.
When Google Analytics 4 or Firebase Analytics is configured, website analytics cookies and the app's local consent choice are limited to one year. Event-data retention in the linked GA4 property is limited to 14 months. Advertising measurement technologies are listed with a maximum of 90 days in the technology table.
Backups are deleted when overwritten in each provider's normal backup cycle.
11. Security
Tapino uses technical and organisational safeguards including authentication, role- and venue-based access, server-side checks, database and storage rules, encrypted transport, provider encryption at rest, security logging, abuse controls, and limits on operational data sent to monitoring services. No service can guarantee absolute security.
12. Your rights
Depending on the circumstances, you have the right to:
receive information and access your personal data
correct inaccurate or incomplete data
request deletion or restriction
object to processing based on legitimate interests and always object to direct marketing
receive portable data where the right to data portability applies
withdraw consent where processing is based on consent
not be subject to certain solely automated decisions with legal or similarly significant effects
Tapino customer accounts are intended for people aged 18 or older, and signup includes an age confirmation. Contact us if you believe a child has submitted data contrary to this requirement.
Tapino does not currently use solely automated decision-making that produces legal or similarly significant effects. Rankings, recommendations, local content, and audience selection are not such decisions.
14. Changes and contact
We update this policy when Tapino's processing or legal obligations change. The date and version appear at the top. For material changes, we provide notice appropriate to the significance of the change.
Miletra, Swedish sole trader · Organisation no. 650306-9053 · Roliasgatan 4, 553 39 Jönköping, Sweden · support@tapino.app