What we collect, why we collect it, how long we keep it, and — importantly — what we never see at all when someone scans one of your cards.
Last updated 1 Aug 2026
This is a template, not legal advice
These terms ship with the TapCard codebase as a realistic starting point. They have not been reviewed by a lawyer and they are not tailored to your business, your jurisdiction or your actual practices. Have them reviewed before you launch publicly — particularly the sections on liability, refunds and personal data. This draft is written against Pakistani law. If you sell into the EU or the UK you will need GDPR-specific wording as well.
TapCard.pk (“we”, “us”) designs and prints custom Google review cards and payment QR cards for businesses in Pakistan. We are the responsible party for the personal information described here, under the Personal Data Protection Bill and the Prevention of Electronic Crimes Act, 2016 (PECA).
Our information officer can be reached at shoptapcard@gmail.com, or by post at Johar Town, Lahore, Punjab, Lahore 54782.
We collect only what a transaction and an account actually require.
| Data | Why | Lawful basis |
|---|---|---|
| Name, email address, phone number | To take, confirm and deliver an order, and to contact you about it | Performance of a contract |
| Delivery address | To deliver your cards, and for the courier to collect on COD | Performance of a contract |
| Password (stored only as a bcrypt hash) | To let you sign in, send us your design brief and track orders | Performance of a contract |
| Your design brief — logo, links, account titles for payment cards | To design and print your card, and to reprint it later | Performance of a contract |
| Order history and payment references | Accounting, warranty and tax records | Legal obligation |
| IP address and browser string, on sign-in attempts only | To detect and slow down credential-stuffing attacks | Legitimate interest in account security |
| Anonymous first-party analytics events | To see which pages lead to orders | Legitimate interest in running a shop |
We never see your card details. When you pay by card you are handed over to the payment provider’s own hosted page, you enter your card there, and we receive a reference and — at most — the card brand and last four digits for your receipt.
No card number, expiry date or CVC is ever transmitted to, processed by, or stored on our servers. This keeps our deployment inside PCI-DSS SAQ-A, the smallest possible scope.
This is the part that matters most to businesses using our cards, so it is worth being blunt about it.
On a normal card, we see nothing at all. The QR code we print encodes your own Google review link or your own bank QR directly. A customer scanning it goes straight there and never touches our servers. We could not track them if we wanted to.
The exception is a Smart QR card, if you order one. Those route through our short link so you can change the destination later, and for those we record that a scan happened, roughly when, and a coarse device class (iOS, Android, or other). That is the complete list.
We deliberately do not record:
The redirect also sends a Referrer-Policy: no-referrer header, so the site they land on is not told which card sent them.
The consequence is that your scan counts are counts, not people. If you need to know who your customers are, that has to come from what they do at the destination, under that destination’s own privacy terms.
You may ask us to:
Email shoptapcard@gmail.com from the address on your account and we will respond within 30 days. There is no charge for a reasonable request.
One caveat worth stating plainly: your printed cards keep working after you close your account, because their codes point directly at your own listing or account. What you lose is the stored artwork, which means a future reprint starts from scratch.
If you are unhappy with how we have handled a request, tell us first and we will try to put it right. You can also raise it with the Pakistan Telecommunication Authority, which handles complaints under PECA.
If we ever suffer a breach affecting your personal information, we will notify you as soon as reasonably possible and tell you exactly what was exposed.
We will post any change here and update the date at the top. If a change materially affects how we use your personal information, we will email account holders before it takes effect.
TapCard.pk
Johar Town, Lahore, Punjab, Lahore 54782, Pakistan
shoptapcard@gmail.com · +92 300 1234567