Privacy Policy
Last updated: January 1, 2025
TagFlow ("we," "us," or "our") operates the TagFlow platform. This Privacy Policy explains how we collect, use, and protect your information when you use our service.
1. Information We Collect
1.1 Account Information
When you register, we collect your username, email address, and a hashed version of your password. We never store plain-text passwords.
1.2 Profile Information
If you create a digital profile on a tag, you may optionally provide your name, job title, company, bio, phone number, email, website, and address. This information is publicly visible on your profile page.
1.3 Scan Data
When someone scans your NFC tag, we automatically log:
- Timestamp of the scan
- IP address of the scanner
- User agent string (browser and device information)
- Referring URL (if any)
- Device type, operating system, and browser name (parsed from user agent)
This information is associated with your tag and visible to you in your analytics dashboard.
1.4 Cookies and Sessions
We use a single session cookie to maintain your logged-in state. This cookie is HttpOnly, SameSite=Lax, and expires when the session ends or after the configured lifetime. We do not use third-party tracking cookies or advertising cookies.
2. How We Use Your Information
- To operate and maintain your account and tags
- To provide analytics on tag scans
- To send password reset emails (if requested)
- To detect and prevent fraud or abuse
- To improve our service
3. Information Sharing
We do not sell, trade, or rent your personal information to third parties. We may share information only in the following circumstances:
- Public profile pages: Information you add to a digital profile is publicly accessible to anyone who scans or visits your tag URL.
- Legal requirements: We may disclose information if required by law or to protect the safety and rights of TagFlow and its users.
- Business transfer: If TagFlow is acquired or merged, user information may be transferred as part of that transaction.
4. Data Retention
We retain your account information and tag data for as long as your account is active. You may delete your account at any time by contacting us. Scan logs may be retained for up to 12 months after account deletion for fraud prevention purposes.
5. Security
We use industry-standard security measures including bcrypt password hashing, CSRF protection, and HTTPS encryption. However, no method of transmission over the internet is 100% secure.
6. Children's Privacy
TagFlow is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us.
7. Your Rights
Depending on your location, you may have rights to:
- Access the personal information we hold about you
- Correct inaccurate information
- Request deletion of your data
- Object to processing of your data
To exercise these rights, contact us at the email below.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We'll notify registered users of significant changes by email or by posting a notice in the dashboard. Continued use of TagFlow after changes constitutes acceptance of the updated policy.
9. Contact Us
If you have questions about this Privacy Policy, please contact us.