Privacy Policy
This policy explains how the TapPass app ("the app", "we", "us"), published by EXAMCERT PTY LTD, handles your information. TapPass stores your membership, loyalty and gift cards on your device. We do not require an account, and we do not run servers that receive your card data.
The app is free and supported by advertising provided by Google AdMob. Section 4 explains what Google may collect to show ads and how you can control it.
1. Card data stays on your device
- Card names, numbers, barcodes, notes, tags, balances, expiry dates, colours and front/back photos are stored locally on your device only.
- We never transmit your card data to us — we have no servers that could receive it.
- Backups: when you choose Export Backup, the app creates a file containing your cards, logos and photos and hands it to your device's share sheet. Where it goes (Files, email, cloud storage) is entirely your choice. The backup file is not encrypted, so store it somewhere you trust.
- Import: when you import a TapPass backup or a Catima export, the file is read on your device only.
2. Camera and photos
- The camera is used to scan barcodes and, if you choose, to photograph your cards. Scanning happens on your device; images are not uploaded.
- Photo library access is used only when you pick a photo to scan or attach to a card.
3. Location
- Country detection: the first time you add a card, the app may ask for your approximate location once, to show store cards for your country. Only the country name is kept on your device. If you decline, your device's region setting is used instead.
- Apple Wallet store locations (iOS, optional): if you tap Add Current Location on a card, that position is saved with the card on your device and included in its Apple Wallet pass, so Wallet can suggest the pass when you are near the store. Nothing is sent to us.
- The app never tracks your location in the background, and we never share it.
4. Advertising (Google AdMob)
- The app shows banner ads provided by Google AdMob. Google may collect device identifiers (such as the advertising ID on Android or the IDFA on iOS), approximate location derived from your IP address, and ad-interaction data to serve, measure and personalise ads.
- In the European Economic Area, the UK and Switzerland, you are asked for consent through Google's consent form (User Messaging Platform). You can change your choice at any time in the app under Settings → Privacy Settings → Manage Ads Consent.
- On iOS, personalised ads are used only if you allow tracking in the App Tracking Transparency prompt. You can change this in iOS Settings → Privacy & Security → Tracking.
- On Android, you can reset or delete your advertising ID and manage ad personalisation in your device's Google or Privacy settings (Settings → Google → Ads or Settings → Privacy → Ads, depending on the device).
- Google processes this data under its own privacy policy. See How Google uses information from sites or apps that use its services.
5. Store logos
When you browse store templates, the app may download a store's logo from a logo service (logo.dev or Clearbit) or a public image host. These requests contain only the store's web domain (for example "woolworths.com.au") — never your card number or any other card data. As with any internet request, the service receives your device's IP address. Downloaded logos are cached on your device.
6. Notifications
Expiry reminders are scheduled locally on your device from the expiry dates you enter. We do not use push notification servers, and no notification data leaves your device. You can turn reminders off in the app under Settings → Reminders & Security → Expiry Reminders, or in your device settings.
7. App Lock (Face ID / fingerprint)
App Lock uses your device's built-in authentication (Face ID, Touch ID, fingerprint or device passcode). The app never receives or stores biometric data — it only learns whether authentication succeeded.
8. Apple Wallet, widgets and shortcuts
- Add to Apple Wallet creates a pass on your device and hands it to Apple Wallet, which is governed by Apple's privacy policy.
- Home-screen and Lock Screen widgets, quick actions and Siri Shortcuts read a copy of the card(s) you choose from storage shared between the app and its extensions on your device. This data is not sent to us.
9. What we do not do
- We do not require or offer an account or sign-in.
- We do not collect, store or sell your card data, photos or backups.
- We do not share your location with anyone.
10. Children
The app is not directed at children under 13 (or the equivalent minimum age in your country), and we do not knowingly collect personal information from children. Ads shown in the app are limited to content rated PG or lower.
11. Your choices
- Delete any card (and its photos) in the app. Uninstalling the app removes all of its data from your device.
- Withdraw ad consent or tracking permission as described in section 4.
- Revoke camera, photo, location and notification permissions in your device settings at any time.
12. Data security and retention
Data on your device is protected by your device's own security, and optionally by App Lock. Because your card data never reaches us, we hold nothing about you to retain or delete. Data collected by Google for advertising is retained under Google's policies.
13. Your rights
Depending on where you live (for example under the GDPR, the UK GDPR, the Australian Privacy Act or US state laws such as the CCPA), you may have rights to access, correct or delete personal data held about you, or to object to its use for advertising. We do not hold personal data about you; for advertising data, use the controls in section 4 or contact Google. You are always welcome to contact us with any question.
14. Changes to this policy
If this policy changes, we will update this page and the effective date above. Significant changes will also be noted in the app's release notes.