Legal

Privacy Policy

This policy describes how Tap App Link ("we", "us") handles information when you use https://app.tapapplink.com, go.tapapplink.com, sandbox.go.tapapplink.com, and this website. It is written to match the product as it works today. It is not legal advice.

Who this covers

Information we collect

Account and workspace

Firebase Authentication stores your email, hashed password or Google Sign-In identifier, and whether the email is verified. We store your display name, plan, Stripe customer and subscription ids, workspace membership, and settings you enter in the dashboard (apps, creators, links, integrations, invoices).

Website analytics and acquisition

On this website and the app dashboard we use Google Analytics 4 (Firebase Analytics) to measure page views and product events such as signup. Ads personalisation and Google signals stay off. We store a first-touch acquisition record in your browser localStorage (campaign parameters, optional referral code, referring site host, and the first landing path) so we can attribute signups across tapapplink.com and the app origin. When you create an account we may copy that first-touch data onto your account so we can see which channels lead to signups and paid plans. We do not use this for advertising audiences.

Attribution

When someone opens a tracking link we record the slug, timestamp, IP address, user-agent, locale, and related click metadata so we can match a later app install. The SDK may send an install event, device signals needed for matching, and an app user id you choose (typically the same id your billing provider uses). We do not collect IDFA or other iOS advertising identifiers, and we do not require an App Tracking Transparency prompt.

Payments for Tap App Link itself

Stripe processes Pro and Scale subscriptions. We store Stripe customer and subscription ids and plan status. Card numbers never touch our servers.

Creator payouts

Tap App Link does not send money to creators. After a payout window closes you issue invoices, pay creators yourself, and may upload proof of payment. Those files are stored in Cloud Storage.

Email

Firebase Authentication sends verification and password-reset mail. Team and creator invitations are sent by Resend from invites@tapapplink.com when a Resend API key is configured.

Where data lives

Application data is stored in Google Cloud (Firebase Authentication, Cloud Functions in us-central1, Cloud SQL via Firebase Data Connect, and Cloud Storage). Email is sent by Google (Auth) and Resend (invites). Subscription billing is processed by Stripe. Website analytics events go to Google Analytics. We do not sell this information.

Why we use it

Retention

Account and attribution records are kept while the workspace exists and for a limited period afterward so we can operate the product, handle disputes, and meet legal obligations. You can ask us to delete a workspace by emailing support@tapapplink.com. Browser first-touch data stays in localStorage until you clear site data.

Sharing

We share information with the processors above only to run the product. We share data with your own billing provider when you point their webhooks at Tap App Link. We may disclose information if required by law.

Your choices

You can access and update account profile data in the dashboard, revoke SDK keys, and close your account by contacting support@tapapplink.com. Creators can access the portal they were invited to. End users of customer apps should contact the app developer that used the tracking link. You can clear first-touch localStorage in your browser settings.

Contact

Questions: support@tapapplink.com.