Privacy Policy
Last updated: September 8, 2026
Who We Are
Tap.Giving sells NFC tap-to-give plates to churches. We are based in Texas, USA. We are hardware, not a payment processor: donations made through a plate go directly to your church's own giving platform, and we never see or store donor payment details. This policy covers what we collect on tap.giving and how we use it.
Information We Collect
We collect information you provide directly to us:
- Quote and order forms: your name, church name, email, phone number, and plate quantity.
- Contact form and email: whatever you choose to include in your message.
- Logo uploads: artwork files you send us so we can design your plates.
- Order details: shipping address and the giving-page URL you want programmed onto your plates.
We also collect standard analytics data (pages visited, device type, approximate region) as described under Cookies and Analytics below.
How We Use Your Information
- Respond to your inquiry, prepare your quote and plate mockup, and follow up about your order
- Produce, ship, and support your plates
- Send a short series of follow-up emails after you request a quote (you can opt out by replying, and we stop when you do)
- Understand how the site is used so we can improve it
We do not sell your information, and we do not use it for third-party advertising.
Service Providers We Share Data With
We use a small set of service providers to run the business. Each receives only what it needs:
- Cloudflare hosts the site, protects our forms from bots (Turnstile), stores form submissions, and runs the go.tap.giving redirect service, its database, and its tap analytics for churches on the Redirect Dashboard.
- Google Analytics gives us anonymized site-usage statistics (IP anonymization is enabled). Google Sheets is where we keep our customer list.
- Microsoft Clarity records how pages are used (heatmaps and session replays) so we can improve them. Your email, phone and name are masked before anything is sent to it.
- Zoho Mail handles our email, including replies to your inquiry.
- Stripe processes payments when you buy plates. Your card details go to Stripe directly and never touch our servers.
- Tally receives logo files you upload through our upload form.
- Formspree delivers messages sent through our contact page.
- Wistia serves the demo videos on the site.
Cookies and Analytics
We use Google Analytics cookies to understand site traffic (with IP anonymization). We also use Microsoft Clarity to see how pages are actually used: it records mouse movement, clicks, scrolling, and which parts of a page people reach, and turns that into heatmaps and session replays so we can find where the site is confusing. Because the point is to see where the plate designer confuses people, Clarity does record the text you type into it, such as the name you put on a plate or the giving link you point it at. Your email address, phone number, name, and anything you write in our contact form are masked and never recorded. Card details are entered on Stripe's own pages, which our analytics cannot see at all. Cloudflare may set functional cookies for security (bot protection). We do not advertise to you or retarget you, and we run no ad-network tags of our own. Clarity is a Microsoft product, though, and it shares an identifier with Microsoft Advertising: that request can set Microsoft's own cookies (_uetvid, _uetmsclkid and MUID) in your browser. We neither use nor can see that data, and blocking those cookies costs you nothing here. You can block cookies in your browser without losing access to anything on the site.
The Redirect Dashboard (go.tap.giving)
Churches that add our Smart Redirect Dashboard get plates programmed with a Tap.Giving short link (for example go.tap.giving/yourchurch) instead of a fixed giving URL, plus a login to change where that link points without reprinting. This section covers that service specifically. Two different kinds of information are involved, and we treat them differently.
When someone taps a plate
So we can show your church how often its plates are used, each tap records:
- the date and time, and which of your plates was tapped
- the destination it forwarded to
- country and city, as our network provider estimates them from the connection
- device type, browser, and operating system, as the phone's browser reports them
- a one-way cryptographic hash of the IP address, salted and re-salted every day
- any campaign parameters present on the link
We do not record who tapped, whether they gave, or how much. No name, no email address, no phone number, no amount, and no payment detail of any kind, because none of that reaches us: the tap forwards to your own giving platform and the gift happens there. A tap sets no cookie. Sensitive query parameters are stripped before anything is stored, and traffic we identify as automated is not recorded at all.
We cannot identify a person from this, and the daily salt is the reason. The IP address itself is never stored. What is stored is a hash that cannot be reversed, and because the salt changes every day, the same phone produces a different value tomorrow than it did today. So we cannot follow an individual across days, across your plates, or across churches. "Unique visitors" in your dashboard means distinct hashed values within a single day. It is not a count of people, and the dashboard says so: one phone on the church wifi and an entire congregation behind a single address are indistinguishable to us.
Individual tap records expire; only counts remain
Per-tap records live in Cloudflare Analytics Engine and expire on that service's own retention, roughly 90 days. What we keep after that is totals: taps per day, taps per country and city, and taps per device type, for each plate. No hashed IP address, no browser string, and no individual tap record survives that rollup.
Your church's login
For the dashboard account itself we hold a username, a contact email address, a one-way hash of the password (we cannot see or recover your password), the time of your last sign-in, and a security log of sign-ins recording the IP address and browser used. That log exists so an unexpected sign-in can be spotted. Each church sees only its own plates and its own numbers; access is scoped to the account that owns them.
Who else is involved, and where it lives
The redirect service, its database, and its tap analytics run on Cloudflare, and the data is processed in the United States. If your church is outside the United States, using the dashboard means asking us to process this information there.
Where the tap goes next is not ours
Once a tap is forwarded, your own giving platform takes over and its privacy policy governs what happens from there. We do not control that page, we set nothing on it, and we cannot see what is entered there. Your congregation's giving records are between your church and your platform.
Deleting it
Email hello@tap.giving and we will delete your dashboard account, its sign-in log, and your stored tap totals. Two honest limits: per-tap records in Analytics Engine cannot be deleted early and will expire on their own retention instead, and totals that no longer identify anything may be kept as counts. We will confirm when it is done.
Data Retention and Your Rights
We keep inquiry and order records for as long as we serve your church, plus what tax and accounting rules require for completed orders. Redirect Dashboard data runs on its own, shorter clock, described in that section above: individual tap records expire after roughly 90 days and only totals remain. If you want the information we hold about you or your church corrected or deleted, email hello@tap.giving and we will take care of it, usually within a few days. We will confirm when it is done. If your church is in the United Kingdom, the European Union, or Canada, the access, correction, deletion, and objection rights your local law gives you apply to us as well, and that same address is how you exercise them.
Data Security
The site is served over HTTPS, form submissions are encrypted in transit, and payment processing is handled entirely by Stripe, a PCI-DSS-compliant processor. We limit access to customer records to the people who need them to serve you.
Children's Privacy
Our site and products are for churches and their staff. We do not knowingly collect information from children under 13.
Changes to This Policy
If we change this policy, we will update the date at the top of this page. Material changes will be noted here plainly.
Contact Us
If you have any questions about this Privacy Policy, please contact us:
Email: hello@tap.giving
Phone: (832) 510-8788