Privacy Policy

Last Updated: September 5, 2026

1. Introduction

Welcome to GrowTap ("we," "our," or "us"). We respect your privacy and are committed to protecting personal data. This Privacy Policy outlines how we collect, handle, protect, and process data across our website (growtap.net), customer portals, cloud routing engine, and physical NFC smart hardware stands and cards.

2. Information We Collect

Depending on your interaction with GrowTap, we collect the following categories of information:

  • Client & Business Information: Business legal name, storefront address, phone number, Google Business Profile details, contact person name, and physical delivery address for hardware dispatch.
  • Payment & Billing Information: Payments and subscriptions are processed through Square (Block, Inc.). We do not process, store, or transmit raw credit card numbers on our infrastructure. Transaction tokens, payment confirmation statuses, and Square Order IDs are retained for subscription fulfillment.
  • Physical NFC Stand Tap Telemetry: When customers or patrons tap a physical GrowTap NFC stand or scan a dynamic QR code, our edge infrastructure logs transient telemetry strictly necessary to redirect the user and provide aggregate analytics to the venue operator. This includes: timestamp, destination route, anonymous device category (Mobile/Desktop), generalized regional geography (via Cloudflare edge headers), and an ephemeral, short-lived 24-hour identifier for same-visit tap deduplication. We do not store personal patron identities, names, or persistent hardware device fingerprints.
  • Private Feedback Submissions: If a patron submits private internal feedback via Review Guard™, feedback comments and optional customer callback phone numbers are delivered securely to the respective venue manager.

3. How We Use Information

We process collected data for the following legitimate business purposes:

  • Fulfilling, encoding, and provisioning physical NFC hardware stands and routing chips.
  • Operating the dynamic cloud routing and Review Guard™ reputation protection system.
  • Generating aggregated foot traffic and engagement telemetry for subscribing business tenants.
  • Billing and accounting via our payment partner, Square.

4. Data Sharing & Third Parties

We never sell, rent, or trade your personal data. Data is shared strictly with essential service providers bound by confidentiality and data processing agreements:

  • Square (Block, Inc.): Hosted checkout, credit card processing, and PCI-DSS compliant subscription billing.
  • Cloudflare: Edge security, SSL/TLS encryption, and distributed DDoS mitigation.
  • Google Cloud Platform (GCP): Encrypted virtual private server (growtap-prod) and PostgreSQL database hosting.

5. Data Subject Rights (GDPR & CCPA/CPRA Compliance)

Depending on your jurisdiction (including the European Economic Area, UK, and California), you possess specific legal rights regarding your personal information:

  • Right to Access: You may request copies of personal data we maintain about you.
  • Right to Rectification: You may request corrections to inaccurate or incomplete business profile data.
  • Right to Erasure (Right to be Forgotten): You may request deletion of your account and associated lead records upon subscription cancellation.
  • Right to Opt-Out: GrowTap does not sell personal data or share data for cross-context behavioral advertising.
  • Non-Discrimination: We will never discriminate against you for exercising your privacy rights.

To exercise any of these statutory rights, submit a written request to [email protected] or call us at (979) 476-9827 with the subject line "Privacy Rights Request". Requests are verified and fulfilled within 30 days.

6. Security Measures

All communications with GrowTap are protected using modern TLS 1.3 encryption, strict HTTP transport security (HSTS), frame clickjacking protections, and encrypted server-side databases. Administrative access requires multi-factor cryptographic authentication (TOTP).

7. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our hardware telemetry practices, please contact our data privacy coordinator at [email protected] or by phone at (979) 476-9827.