Privacy Policy

Last updated: 19 August 2026

This policy explains how MIRO ONLINE LIMITED, trading as TapSpot, handles personal information through the TapSpot website, business services and TapSpot Loyalty app.

TapSpot Loyalty uses account and loyalty activity information to operate digital loyalty programmes. It does not use advertising tracking, collect payment-card details from loyalty members, or save camera images used to scan QR codes.

1. Who we are

TapSpot is operated by MIRO ONLINE LIMITED, a company registered in England and Wales under company number 10188486. MIRO ONLINE LIMITED is the controller of personal information used to create and secure TapSpot accounts, operate the TapSpot platform and app, provide support, and manage our relationship with users.

Participating businesses decide how their loyalty programmes work and their authorised staff can use TapSpot to administer those programmes. A participating business may be a separate controller for its customer relationship, promotions and its own use of loyalty information. Its own privacy notice may also apply.

2. Who this policy covers

This policy applies to personal information relating to:

  • TapSpot Loyalty members who join a participating business's loyalty programme;
  • staff who sign in to identify members and administer loyalty transactions;
  • TapSpot business customers, account users and authorised administrators;
  • people who visit our website, contact us, or submit information through a TapSpot service.

When a participating business collects information for its own purposes through TapSpot, that business is responsible for explaining its use of the information and establishing an appropriate lawful basis.

3. Information we collect and use

Account and contact information

  • name, email address and, where provided, telephone number;
  • account, staff, business and membership identifiers;
  • sign-in information, authentication tokens, login status and security records;
  • communication and marketing preferences for each participating business.

Loyalty programme information

  • businesses and programmes joined, membership status and QR or six-digit lookup identifiers;
  • stamp and points balances, lifetime totals, rewards, offers, redemptions and related timestamps;
  • loyalty transaction activity, including an amount spent where a points programme calculates rewards from spend;
  • notes, adjustment reasons, void reasons and redemption notes entered by authorised staff;
  • the staff, administrator or system actor responsible for a loyalty transaction.

Device, notification and security data

  • push-notification token, device platform, app version, generic device name and token activity status;
  • notification content, delivery status, message identifier, error details and delivery timestamps;
  • IP address, browser or app user-agent information, login attempts and security-event details;
  • technical logs needed to diagnose errors, protect accounts and maintain the service.

Website and business-service data

  • information supplied through contact forms, support requests and other forms created using TapSpot;
  • business account, menu, QR-code, campaign and service-usage information;
  • billing records for business customers. Payment-card details are handled by our payment provider and are not stored in the TapSpot Loyalty member account.

Information from other sources

A participating business may provide staff-account details or create information about a member's visit, purchase, loyalty transaction or reward. We may also receive payment status from our payment provider for business services and technical delivery information from notification and email providers.

4. Camera, browser storage and app permissions

TapSpot Loyalty can request camera access when a customer or staff member chooses to scan a loyalty QR code. Camera frames are processed on the device to read the code. TapSpot does not save or upload the camera image; only the decoded QR value is sent to the service to identify the relevant business or membership.

The app may ask for notification permission. Notifications are optional and can be disabled through the device's system settings. A participating business may send service messages and, where permission or another lawful basis allows it, promotional messages for its loyalty programme.

TapSpot uses browser or app WebView storage for authentication tokens, login state, selected business context and essential preferences. Authentication tokens are transmitted to TapSpot when needed to verify an authorised request. Signing out clears the local TapSpot Loyalty authentication state.

For information about website cookies, please read our Cookie Policy.

5. Why we use personal information

Purpose Lawful basis
Create accounts; authenticate users; provide loyalty memberships, balances, rewards, transaction history, business services and support. Performance of a contract, or steps requested before entering a contract. Where the contract is with a participating business, our legitimate interests and those of that business in delivering the requested service may also apply.
Protect accounts, investigate misuse, prevent duplicate welcome rewards, maintain audit records and defend legal claims. Our legitimate interests, and those of participating businesses, in preventing fraud, securing the service and keeping appropriate business records; and legal obligations where applicable.
Deliver operational emails, push notifications and service announcements. Contract and legitimate interests in operating the requested service.
Send optional promotional messages and remember marketing choices. Consent where required. Consent can be withdrawn at any time. In limited circumstances, another lawful basis permitted by electronic-marketing law may apply.
Diagnose faults, measure service reliability and improve security and usability. Our legitimate interests in maintaining and improving a reliable service, balanced against users' rights.
Meet tax, accounting, regulatory and other legal duties. Legal obligation and legitimate interests.

We do not use TapSpot Loyalty information for advertising tracking or sell personal information. We do not make decisions based solely on automated processing that have legal or similarly significant effects on loyalty members. Automated calculations may award stamps, points or reward eligibility according to the participating business's published programme rules.

6. Who receives personal information

We may disclose relevant information to:

  • the participating business and its authorised staff, so they can operate the loyalty programme, identify members, award or correct loyalty credit, fulfil rewards and provide support;
  • hosting, database, backup, monitoring and technical service providers that support the TapSpot service;
  • email-delivery providers for sign-in links and service or permitted marketing messages;
  • Google Firebase Cloud Messaging for push-notification delivery;
  • Stripe and related payment services for TapSpot business billing, not for customer loyalty transactions;
  • professional advisers, insurers, auditors, regulators, courts or law-enforcement bodies where reasonably necessary or required by law;
  • a buyer, investor or successor if our business or assets are reorganised, sold or transferred, subject to appropriate confidentiality and data-protection safeguards.

Service providers are permitted to use personal information only for the services they provide to us and must protect it appropriately.

7. International transfers

Some of the providers we use may process personal information outside the United Kingdom. Where UK data-protection law requires it, we rely on an appropriate safeguard – such as an adequacy decision, the UK International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses, or the EU–US Data Privacy Framework – to protect the information.

In particular, push-notification information is handled by Google (Firebase Cloud Messaging), which processes it on Google’s global infrastructure, including outside the United Kingdom, under the Firebase Data Processing and Security Terms and the safeguards described above. Our hosting provider stores account and loyalty information on our behalf; where any of this is held outside the United Kingdom or European Economic Area, the same safeguards apply.

You can contact us for more information about the safeguards relevant to your data.

8. How long we keep information

We keep personal information only while it is needed for the purposes described in this policy. The exact period depends on the type of record and why it is used. We apply the following criteria:

  • account, profile, membership and balance information is kept while the account or membership is active. If a membership has no activity for 24 months we make it inactive, and after 36 months of inactivity we anonymise the personal details in that membership so that only non-identifying totals (such as points and dates) remain;
  • loyalty transactions, redemption records and staff-entered notes are kept while the membership is active and are anonymised 36 months after a membership becomes inactive. Where an account has no active memberships anywhere and has been dormant for 36 months, we also anonymise the account’s name, email address and telephone number;
  • sign-in links are deleted 24 hours after they expire; QR codes and related security values (which expire within minutes) and expired session tokens are removed by routine security cleanup;
  • device tokens used for notifications are removed 90 days after they become inactive, and notification delivery records are kept for 90 days;
  • loyalty security and audit records are kept for up to 12 months. The record we keep of an account deletion is kept for up to 24 months, with the network (IP) address removed after that point;
  • records of loyalty emails we send are kept for 90 days. Sign-in emails never store the login link itself in our logs;
  • support, contract, billing and other legal records for TapSpot business services are kept for the period needed to meet legal, tax, accounting, dispute and insurance requirements;
  • where an account receives a one-time welcome reward, TapSpot may retain a keyed, one-way hash derived from the account email after account deletion. The address itself is not stored in that record. The hash is used only to prevent the same person repeatedly claiming that reward and is kept for up to 24 months after deletion, then removed.

We periodically review whether information is still needed. We delete or anonymise it when the relevant purposes, legal duties and dispute periods no longer apply.

9. How we protect information

We use technical and organisational measures intended to protect personal information, including access controls, authentication, encryption in transit, database permissions, security monitoring and limits on staff access. No online service can guarantee absolute security, so users should also protect access to their email account, device and sign-in details.

10. Loyalty membership and account deletion

A loyalty member can remove an individual business membership or delete the TapSpot Loyalty account from the profile section of the app. Deleting the account removes the member's TapSpot Loyalty account and linked business memberships, subject to the limited records we are entitled or required to retain for security, fraud prevention, legal obligations or legal claims.

If you cannot sign in, follow the instructions on our TapSpot Loyalty account-deletion page or email developer@tapspot.link from the address connected to the account. We may need to verify your identity before acting.

A participating business may hold separate records outside TapSpot or retain information under its own lawful basis. Contact that business about those records.

11. Your rights

Depending on the circumstances and lawful basis, UK data-protection law may give you the right to:

  • ask for access to your personal information;
  • ask us to correct inaccurate or incomplete information;
  • ask for erasure or restriction of processing;
  • receive certain information in a portable format;
  • object to processing based on legitimate interests;
  • object at any time to the use of your information for direct marketing;
  • withdraw consent at any time, without affecting processing carried out before withdrawal;
  • complain to the Information Commissioner's Office.

These rights are not absolute and exemptions may apply. Email privacy@tapspot.link to make a request. We may ask for information needed to confirm your identity and locate the relevant records.

You can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint. We would appreciate the opportunity to address your concern first.

12. Changes to this policy

We may update this policy when our services, providers or legal obligations change. We will publish the updated date on this page and, where a change materially affects users, provide an appropriate additional notice.

13. Contact us

For privacy questions or requests, contact privacy@tapspot.link.

MIRO ONLINE LIMITED (TapSpot)
Company number: 10188486

Registered office
21 Gower Road, Sketty
Swansea, Wales
SA2 9BX
United Kingdom
Office
142 Woodfield Street
Morriston, Swansea, Wales
SA6 8AL
United Kingdom Visitors are welcome Monday to Friday, 9am to 5pm; look for the Lowcost Printing shopfront.