Srpski · English
Privacy Policy
Last updated: 2026-09-28
This Privacy Policy explains how [Company Legal Name] (“Prvi na mapi”, “we”, “us”), based in [Address], collects and uses personal information through the Prvi na mapi platform. It covers two kinds of people:
- Business users — owners, managers, and employees of a business that has a Prvi na mapiaccount (“Business”).
- End customers — people who tap an NFC card, scan a QR code, or otherwise land on a public Prvi na mapi review page run by a Business, whether or not they leave a review.
For personal data about end customers, the Business is the controller and Prvi na mapi is its data processor / service provider, as described in our Terms of Service. Requests from end customers about their own data should generally go to the Business first; we’ll assist the Business as needed.
1. Information We Collect
- Account data: name, email, hashed password, company name/branding, role, and locale preference, for Business users.
- Tap logs: when a card is tapped or a QR code is scanned, we log the card/company, a hashed IP address (not the raw IP), user-agent string, source (NFC/QR/link/job), and timestamp.
- Review content: the star rating, any text the customer types as AI input, the AI-drafted or final review text, which platform (Google/Yelp/etc.) it was posted to, locale, and — for a review imported from a connected platform — the reviewer’s public name.
- Private feedback: the feedback message and any contact name, email, or phone number the customer chooses to provide.
- Referral information: a referred friend’s name, phone, and/or email, plus the referrer’s name and any note, when a customer submits a referral.
- Job/customer contact information: name, phone, email, and service details a Business imports (manually, via CSV, or via webhook/Zapier) so we can send review-request messages on its behalf.
- Uploads: logo and cover images a Business uploads for branding.
- Cookies: see Section 6.
2. How We Use Information
- Operate the Service: authenticate accounts, log taps, attribute reviews/feedback to employees, and run the dashboard, leaderboard, and analytics.
- Generate AI-assisted review drafts and translations when a Business has AI assist enabled.
- Generate an AI-drafted suggested reply to a review — using the reviewer’s name, rating, and review text, plus the credited employee’s first name — automatically for new reviews when a Business’s reply mode is set to draft (the default for new companies), or on demand. These drafts are only ever suggestions: a Business reviews and can edit a draft before it’s published, and nothing is posted automatically today.
- Send review-request and transactional messages (SMS/email) on behalf of a Business, and notify a Business of new private feedback.
- Process referrals and reward/payout calculations for employees.
- Detect and prevent abuse, fraud, and security incidents (e.g., rate limiting, hashed IP logging).
- Comply with legal obligations and enforce our Terms of Service.
3. Service Providers We Use
We share personal data with the following service providers, only as needed to provide the Service:
- Supabase — our production Postgres database host (all app data at rest).
- Vercel — application hosting and edge/serverless request handling.
- Anthropic — processes customer-provided input text to generate AI review drafts and translations, when AI assist is enabled, and processes review content (reviewer name, rating, review text) and the credited employee’s first name to generate AI-drafted suggested replies for a Business to review, when reply drafting is enabled.
- Resend — sends transactional and review-request emails on our behalf.
- Twilio — sends review-request SMS messages on our behalf; see our SMS Program Terms.
- Stripe — processes Business subscription billing/payment information; we don’t store full card numbers ourselves.
- Google — Business review-page links (Google Place ID) and, planned for a future release, a Google Business Profile API integration for importing and replying to reviews (not yet available).
- Sentry (Functional Software, Inc. — data stored in the EU (Germany)) (optional, enabled when we set an error-monitoring DSN) — error monitoring. We configure Sentry to collect only technical failure data (error type/message, the failing URL’s path without its query string, browser/device type) and to filter out request contents, contact details, and message text before an event is sent to Sentry. Despite that filtering, an error report may incidentally include a fragment of the data being processed at the moment an error occurs. Access to our Sentry project is limited to our engineering team, and event data is retained for a limited period under our Sentry plan.
- PostHog (optional) — product analytics, if enabled.
All of our infrastructure and service providers listed above store and process data in the United States, except Sentry, whose data for our project is stored in the EU (Germany).
4. Data Retention
We retain personal data for as long as the associated Business account is active, plus a reasonable period afterward for legal, billing, and dispute-resolution purposes, or until the Business or end customer requests deletion under Section 5 and we’re not otherwise required or permitted to keep it (e.g., for fraud prevention or tax records). Placeholder — specific retention windows per data type are still being finalized.
5. Security
We use industry-standard safeguards, including encrypted connections (HTTPS/TLS), hashed passwords, hashed IP addresses in tap logs, and httpOnly session cookies. No method of storage or transmission is 100% secure, and we can’t guarantee absolute security.
6. Cookies
- Session cookie (
tapstar_session) — an httpOnly, signed cookie that keeps a Business user logged in for up to 7 days. Strictly necessary; can’t be disabled and still use the authenticated dashboard. - Locale cookie (
tapstar_locale) — remembers a visitor’s English/Spanish/ Serbian language choice. - Review-session dedupe cookie — a short-lived cookie set after tapping a card, so a refresh or second page load in the same browser session doesn’t log a duplicate tap. It expires automatically (after about 30 minutes) and isn’t used for tracking across sites.
We don’t use third-party advertising cookies.
7. Your Rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal data, and to opt out of certain uses. This includes rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”) and the Texas Data Privacy and Security Act (“TDPSA”), among other applicable state privacy laws. To exercise a request, contact us at [Contact Email]; if you’re an end customer of a Business, we may need to verify your request with that Business first, since they control the underlying data. We will not discriminate against you for exercising these rights.
8. Customers in Serbia
If you’re located in the Republic of Serbia, a dedicated Serbian-language privacy notice — structured around the Serbian Zakon o zaštiti podataka o ličnosti („ZZPL“), including your right to complain to the Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti (www.poverenik.rs) — is available at /privacy?lang=sr, or via the “Srpski” link at the top of this page.
9. Children
The Service isn’t directed to children under 13 (or the relevant age of digital consent in your jurisdiction), and we don’t knowingly collect personal data from them. If you believe a child has provided us personal data, contact us at [Contact Email] and we’ll delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where required by law, by additional notice.
11. Contact
Questions about this Privacy Policy or a data request? Contact us at [Contact Email] or [Address].