Privacy notice

Tap Cards & Privacy

Last updated September 10, 2026

Tap Cards helps you share the contact information you choose through a physical card, public profile, downloadable contact file, and optional share links. This notice explains how FollowDon AI Consulting LLC uses information when you order, manage, tap, scan, share, or save a Tap Card.

Privacy at a glance

  • You choose what becomes public. Only the contact details, links, image, and promotion selected for a card or share link are shown there.
  • Stripe handles your full payment-card details. Tap Cards does not receive or store your full card number.
  • Public card and share pages have no product analytics.
  • Buyer data is not sold or shared with partners for their marketing.
  • You have practical controls. Card owners can edit their profile and revoke share links. Anyone can email help@followdon.com to request access, correction, or deletion.

Ordering your Tap Card

Information you provide

When you order a Tap Card, we collect the buyer’s name and email address; the name, role, company, credentials, tagline, contact details, websites, social links, and custom links selected for the card; card design and display choices; quantity, accessories, delivery choice, and price; any production request; and confirmation that you have permission to use uploaded images.

We use this information to price, design, produce, deliver, track, and support the order. The public profile receives the contact information, links, portrait, and promotion selected for it. Order, payment, delivery, consent, and production records are not displayed there.

Drafts and private return information

Your browser can save an unfinished order, including contact information, images, card choices, prices, and private information used to resume an order or return to its status page. Draft content is sent to Tap Cards only when you submit the order.

Unfinished order details and draft images normally expire after 24 hours, and a saved pickup option expires at the time shown with it. Limited submitted-order, artwork, pricing, and recovery information can remain until you start over, the app clears invalid information, or you clear this site’s browser data. Private return information kept only in the current tab disappears when that tab session ends.

Order operations

When an order is submitted, we record limited browser information for troubleshooting and abuse investigation. We also maintain private operational records for order status, pickup or shipping decisions, carrier tracking information, payment follow-up, production actions, customer notifications, and recovery from processing failures.

Paying for and delivering your order

Checkout

Tap Cards sends Stripe the order email, order number, items, prices, delivery choice, and secure return information needed to create and safely resume Checkout. Stripe’s hosted checkout collects your full payment-card details, phone number, and shipping address and may send your receipt. Tap Cards does not receive or store your full payment-card number.

Stripe returns the payment result and fulfillment details we need to complete the order. Tap Cards stores payment and checkout identifiers, status, amount, phone number, shipping address, and limited recovery information. If shipping is added after a pickup decision, Stripe also handles that separate shipping payment.

Payment confirmation

Stripe sends Tap Cards payment updates. We keep a limited record connecting a processed Stripe event with its order so a repeated notification is not treated as a second payment.

Your public card, share links, and wallet passes

What visitors can see

An active Tap Card can publicly show the name, suffix, role, company, tagline, email address, phone number, website, social or custom links, promotion, and portrait selected for that card. Anyone who taps the card, scans its QR code, or has its public link can see that information. The downloadable contact file can include the selected contact information and portrait.

Front and back production artwork, production files, and stored contact files remain available only through operator tools. A recently served portrait can remain in a temporary public cache for up to one hour after deletion.

Editing and limited share links

Tap Cards keeps the published and draft versions of a card, review and audit history, access records, and the information needed to operate owner-created share links. A share link shows only the fields selected for that link, but anyone holding an active link can view them until the owner revokes it. Revoking a link or suspending a card stops access; it does not by itself delete the underlying record.

A signed-in session and a pending email sign-in link are each removed automatically about seven days after they stop being valid.

Compass card contacts

On a Compass-branded card, the person you meet can share their name and either an email address or phone number back to you, along with a few optional details — for example, another agent's markets and brokerage, or a client's interest and what they're looking for. You can also add someone by hand. You can add your own notes and tags, and download the list for your own CRM.

Only the card owner's signed-in session can see this list; the person who shared their details cannot. It is deleted when the owner's own card is deleted, and the owner can remove one entry at a time.

Apple Wallet

When a card owner chooses an Apple Wallet pass, it can contain the display name, role, company, website, public email or phone number, portrait, and a QR code for the card. Tap Cards prepares the pass and downloads it to the owner’s device without contacting an Apple service during that build step.

The pass remains on the device until the owner removes or replaces it.

Google Wallet

When a card owner chooses Google Wallet, Tap Cards sends Google a save link containing the display name, optional role and company, the Tap Cards logo, and a QR code that opens the live card page. Google controls the saved pass under Google’s policies.

Signing in and protecting the service

Card-owner access

Approved card owners can sign in with a one-time email link or Google. Authentication services receive the email address, account identity, and sign-in information needed to verify the owner. The sign-in email provider receives the recipient address, message, and one-time link. Tap Cards does not add its own open or click tracking to that email.

After sign-in, a necessary cookie keeps the owner’s approved management session active. It expires after 30 minutes and is cleared when the owner signs out.

Abuse protection

To protect Tap Cards and its customers, we use IP addresses and limited activity information to prevent automated abuse, enforce usage limits, and keep the service working reliably. Sign-in request and card-owner abuse-limit records are removed automatically about seven days after they stop being valid; other protection data remains until an eligible deletion request is completed.

Emails from Tap Cards

Order and service messages

We use an email and workflow provider to send order, production, editing, review, pickup, and shipping updates and to alert the Tap Cards operator when action is needed. Depending on the update, the provider can receive a name, email address, order number, card and delivery choices, private order-status or card-management links, shipping-payment information, changed-field labels, review results, and coordination details. A message can also include an operator-written rejection note or pickup instructions.

If we begin sending marketing messages, they will be occasional messages about related services provided by FollowDon itself to US buyers. Purchase history may help determine which message is relevant. Every marketing message will include an unsubscribe link that we honor. Buyer data is not sold or shared with partners for their marketing.

Analytics and information in your browser

Product analytics

When production analytics is enabled, Tap Cards measures activity on its landing, ordering, checkout, order-status, sign-in, and card-management pages. The analytics can include page views; browser, device, operating-system, screen, language, viewport, and time-zone information; device and session identifiers; approximate location derived from the IP address received by the analytics provider; and events such as starting or submitting an order, checkout results, card type and add-ons, profile changes, and paid amount. Some events use an internal order-related identifier.

The order form page may be recorded, with what you type and upload hidden. No other page uses session replay. It does not run on public card pages, share-link pages, or operator pages. Analytics uses a cookie and browser storage on the pages where it runs. You can remove the browser copy by clearing this site’s data or prevent it by blocking site storage.

Session recordings: Kept for up to 30 days, then deleted by PostHog. Don deletes a recording sooner once he has reviewed it.

Saved preferences

If you dismiss the optional add-to-home-screen hint, your browser remembers that choice until you clear this site’s data. That preference is not sent to the Tap Cards server.

For Production Desk operators, the browser also remembers the chosen light, dark, or system appearance until the operator changes it or clears this site’s data. This preference is not sent to the Tap Cards server.

Service providers and recovery copies

Who helps us run Tap Cards

Tap Cards uses Stripe for payments; Google and Firebase for sign-in and cloud services; Resend and GrowthHub for email; PostHog for the limited product analytics described above; and Vercel for hosting and technical logs. These providers receive the information described in the relevant sections and retain their copies under their own policies.

Hosting logs can contain technical request information and service identifiers used to operate, protect, and troubleshoot Tap Cards.

Backups and recovery

Managed recovery copies help restore records or uploaded files after accidental deletion or corruption. Database recovery versions are kept for 7 days, daily database backups for 14 days, and recoverable deleted file versions for 30 days before those recovery copies expire.

How long we keep information

Different information has different lifetimes. Sign-in and security windows expire quickly, while some browser records stay until you clear or replace them. Temporary request counters can exist only in server memory. Service providers retain their copies under their own policies.

We delete information covered by an eligible written request within 30 days. The limited portions of order and payment records required for tax or accounting are kept for 7 years and then deleted. Recovery copies expire on the schedules described above. A recently served portrait can remain cached for up to one hour. An Apple Wallet pass already saved to a device remains there until the owner removes or replaces it; Google controls a saved Google Wallet pass under Google’s policies.

Your choices

Email help@followdon.com to access, correct, or delete your information. Card owners can open card management to edit their card and revoke share links. You can clear Tap Cards browser data in your browser settings. Blocking the necessary sign-in cookie prevents card-owner sign-in.

If you receive a marketing message, you can opt out using the unsubscribe link in that message.

Children

Tap Cards is not directed to anyone under 18.

Changes to this policy

We post updates to this policy here and change the date at the top. If a change materially affects how we handle your data and we have your email address, we will email you.

Contact

FollowDon AI Consulting LLC, 1717 N Street NW, Suite 1, Washington, DC 20036. Email don@followdon.com for legal notices or help@followdon.com for everything else.

Refunds are covered in the refund section of our terms.