Privacy
Privacy
Version 2, in force since 26 September 2026.
Tap2Wafa runs digital loyalty stamp cards that live in Apple Wallet and Google Wallet. This one page covers everyone we hold data about: visitors to this site, merchants (the cafés and businesses that subscribe), and cardholders (their customers who join a loyalty card). We wrote it to be read. The longer sections open with a plain summary, and the full text governs. This policy is incorporated into our Terms & Conditions.
The short version: we collect very little, we tell you exactly how long we keep it, we never sell or share it, and there is no tracking anywhere.
1. Website visitors
In plain words: the site has no trackers.
- Server logs: like every web server, ours writes standard access logs: IP address, page requested, time, browser identifier. We keep them for 14 days. We use them only to keep the site running and to defend it against abuse. Your IP address is deliberately not stored next to your email address.
- No tracking, a promise rather than a habit: no analytics, no advertising trackers, no third-party cookies, no pixels, here or anywhere on the platform. The only things we ever store on your device are strictly-necessary ones, and there are a few kinds. The two cookies that log merchants into their dashboard, and a third that remembers the device they signed in from, so a sign-in from a new device asks for the password again. A note of whether you chose the light or the dark version, which we keep on this site, on a café's join page, in your dashboard and on a till: in your browser's own storage here, and in a cookie that works across tap2wafa.com and the pages under it, so your choice follows you from one page to the next. That note holds nothing but the word light or dark. A till also remembers that it is that till, so your staff do not set it up again every morning. If the dashboard fails to load, it notes for one minute, in that browser tab only, that it has just reloaded itself, so it never reloads over and over. None of this identifies you, and nobody but us ever reads any of it. There is no automated decision-making or profiling anywhere: stamps are counted, people are never scored. If any of this ever changes, this policy changes first, with notice. Never silently.
What we store on your device, item by item. Each row says who it touches. If you only hold a loyalty card, the most we ever keep on your phone is the light or dark note, and only if you chose one. The merchant and till items never touch you.
__Secure-t2w_refresh(cookie): Merchants only. Keeps you signed in to your dashboard. At most 30 days from sign-in, and it ends sooner after 7 days without a visit. Strictly necessary.__Host-t2w_csrf(cookie): Merchants only. Stops another website from sending requests to your dashboard in your name. At most 30 days. Strictly necessary.__Secure-t2w_device(cookie): Merchants only. Remembers the device you signed in from, so a sign-in from a new device asks for the password again. About 13 months (400 days). Strictly necessary.__Secure-t2w_bound(cookie): Merchants only, and only where the browser supports it. Shows that the browser holding your sign-in still holds its own key, so a copied sign-in cookie is useless anywhere else. 10 minutes, renewed while you stay signed in. Strictly necessary.__Secure-t2w_oauth(cookie): Merchants only, while you sign in with Google or Apple. Matches the answer that comes back to the sign-in you started. 10 minutes. Strictly necessary.t2w_theme(cookie): Anyone who picks light or dark. It holds only that word, so your choice follows you across tap2wafa.com and the pages under it. Because it is shared across those pages, its name carries no security prefix, and the page can read it on purpose. One year. Your preference.t2w-theme(browser storage): Anyone who picks light or dark. The same word, kept in this browser, for a browser that refuses cookies. Until you clear it. Your preference.t2w.cashier.credential(browser storage): Tills only. How a till proves it is that till, so your staff do not set it up again every morning. Until the café removes the till, or the browser's storage is cleared. Strictly necessary.t2w.cashier.theme(browser storage): Tills only. Light or dark on the till. Until the browser's storage is cleared. Your preference.t2w-chunk-reload-at(browser storage, this tab only): Merchants only. The time the dashboard last reloaded itself, so it never reloads over and over. One minute, and gone when you close the tab. Strictly necessary.t2w-cashier-shell(the till's offline copy): Tills only. A copy of the till's own screens and pictures, so it opens quickly. It holds no personal data. Until the till loads a newer version. Strictly necessary.
Global Privacy Control and Do Not Track change nothing here, because nothing is sold, shared or tracked for them to turn off. You can delete all of it in your browser's settings by clearing the cookies and site data for tap2wafa.com. A merchant who does that is signed out, and a till has to be set up again.
2. Merchants — what we hold about your business
In plain words: your account details, your card designs, and billing records. Your customer list is yours, not ours.
- Account & business data: your name, your login email and your password, which is stored only as an irreversible hash, or a sign-in provider you connect (Google or Apple), of which we keep only the provider's stable identifier and the email it verified for us. Your business name and branding. A contact number, if you choose to give us one, so we can reach you about your account. Your card designs and your dashboard settings. That is what running your account needs, and nothing more.
- Billing records: we record invoices and the payments you make: the amount, the date, and a reference for the method. Payments are push-based on Iraqi rails, so we never hold card numbers or wallet credentials. You pay us; nothing is ever pulled from you.
- Our record of what was done: the platform keeps an audit trail of what you do in it, each action with its time and the connection address it came from, for 3 years. It is the record of what was done, so entries are never edited, and they are removed once they are three years old.
- When you leave: 90 days after a café closes and its data is deleted, your login is closed too if that was your last café, and it can no longer sign in. We keep the closed record, which is your name and your login email, so that the same details cannot start another free trial. Ask us and we erase those as well.
- Error and speed reports (only while switched on): if we switch them on, your dashboard sends us a short report when a page breaks or to say how fast it loaded: the page, what went wrong or the timing, the browser family, and the operating system family with its major version. Never the full version, the device model, the full browser string or anything that identifies you. We use them only to fix problems.
- Your customers' data is YOURS: we are the custodian, not the owner (Terms §8). Ask for an export any time at support@tap2wafa.com, and it normally reaches you within 7 days.
3. Cardholders — what joining a loyalty card means
In plain words: a card needs your name. Your phone number only if you choose to share it. That is all we ask, and you agree by joining.
- What we collect: your name, your phone number if you choose to provide it, and the stamp history of your card. That is the entire list of what we ask of you.
- How you agree: the join page says it right above the button: "By joining, you agree your name — and your phone number if you share it — are used to run this loyalty card." A link to this policy follows it. Joining is the agreement. We record when you joined and which version of this policy applied. That consent record holds the time you joined, the policy version and, where we keep it, the connection address you joined from. We keep it as evidence of your consent and against abuse, and we remove it together with your details when you ask for deletion.
- What it's used for: running the loyalty program of the café you joined: your stamps, your rewards, and the card's own updates and offers in your wallet. The café you joined can see it. Other cafés never can.
- Checking the number is real: to stop fake sign-ups we can switch on a check that decides whether a phone number is a real mobile or landline. It never stores your number for this. It keeps a one-way code of the number and the answer for 30 days, so a returning customer is not checked twice.
- Card messages: the offers and updates a café sends arrive as messages of the card you deliberately joined. The platform enforces sending limits, so they stay rare and relevant. Don't want them? Remove the card from your wallet, or ask for deletion (section 5).
- Children: Tap2Wafa is a business service and is not directed at children. We do not knowingly collect personal data from anyone under 16, and a deletion request for a minor's data is honored without question. Section 5 says how and when it completes.
4. Where your data lives, and who ever sees it
In plain words: our own servers in the United States. Apple and Google render the wallet passes. A few more companies may help us, only if we switch them on, and we name them here.
- Hosting: all platform data is stored on our own servers in the United States. If we ever move hosting, this policy is updated with notice.
- Wallet platforms: to put a card in your wallet, pass data is delivered through Apple Wallet and Google Wallet. That is how wallet passes work on every platform, and Apple's and Google's own privacy terms cover it on your device. To deliver pass updates we also hold the technical identifiers Apple and Google assign your device's wallet. They identify the card's device, nothing else.
- Location lookups: to tell a sign-in from a new city, we look up the country and city of your connection address on our own server, using data from MaxMind. This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com. The lookup never leaves our server and is never used for marketing.
- Who else can see your data: our own servers (United States) and, for the wallet card, Apple and Google. A few more companies may help us, and only if we switch them on. Cloudflare (United States) runs a check on the join page that you are a person and not a robot; it sees the same connection details any website sees, and nothing about your card. Stripe (United States) takes card payments from cafés; it sees a café's billing details, never a customer's. Resend (United States) and Mailjet (France) carry the email with a merchant's verification code, sent only if we switch email verification on; each sees the café owner's login email and the code, never a customer's details, and if the first cannot deliver, the second tries. If we ever use another company to help us run the service, for hosting, security checks or payments, we will name it here, with what it does, before any of your data reaches it. If a public authority asks us for data, we hand over only what a valid legal order requires, and nothing more. We check that the order is real and no wider than the law allows, and we push back when it is not. We tell the café concerned before we hand anything over, unless the law forbids it or someone is in immediate danger; if we were forbidden, we tell them as soon as we may.
- Nobody else: apart from the wallet platforms and the companies named above, nobody else sees your data. We never sell it. We never share it with advertisers, brokers, or "partners." We keep only anonymized, aggregated statistics, such as "cafés average X stamps a week." Nothing in them identifies a person or a café.
5. Your rights — see it, fix it, delete it
In plain words: ask and you will see your data. Your café can fix it. Either of us will delete it.
- See your data: cardholders can ask at support@tap2wafa.com or through their café. Before we read your details out, we make sure it is you. Either in person at the café, or through the phone number on your card plus one detail about the card: the month you last collected a stamp, or how many stamps you have. That way we never read your details out to somebody who now has your old number. Merchants: your dashboard IS your data, and the full export is a support email away.
- Fix it: for cardholders, your café can correct your name or phone in seconds.
- Delete it: cardholders can ask their café, or contact us directly, and we verify you hold the phone number on the card. Your personal details are erased within 30 days of the request, and your card is revoked. Deleted details also leave our backups on a fixed schedule: our encrypted nightly copies are kept for 14 days and our point-in-time copies for about 4 weeks, and then they are overwritten. Until then those copies are used for one thing only — restoring the service after a failure — and if we ever had to restore from one, your deletion would be applied again. Merchants: cancellation lets your paid month run out, and then the retention clock below starts.
6. How long we keep things — the real numbers
- Emails given to our earlier waitlist form — 6 months after the launch invitation is sent, or deleted at once on request
- Server logs (incl. IP) — 14 days
- Audit trail (who did what in the platform, including the operator's connection address) — 3 years. It is the record of what was done, so entries are never edited, and they are removed once they are three years old
- Your consent record (when you joined, which policy version, and, where we keep it, the connection address you joined from) — Removed together with your details when you ask for deletion
- The real-number check (only while it is switched on) — A one-way code of the number and the answer, for 30 days. Never the number itself
- Your email verification code (only while email verification is switched on) — A one-way code of your email address, a one-way code of the verification code itself, and how many tries it took, for 48 hours after the code is sent, then deleted. It proves you can read the address you signed up with, and it holds the daily code limit. The code itself exists only in the email we sent you
- Your password reset code (only while password reset is switched on) — A one-way code of your login email or phone number, a one-way code of the reset code itself, and how many tries it took, for 48 hours after the code is sent, then deleted. It proves the reset request is yours and holds the daily code limit. The code itself exists only in the message we sent you
- Your sign-in session (merchants) — For as long as the session lives: at most 30 days from sign-in, and it ends sooner after 7 days without a visit. It holds a one-way code of the device cookie, a one-way code of the network block your connection came from, the country and city we work out from your connection address, the address itself, and the kind of browser. We use them for one thing: to end a session that suddenly comes from another device or another city, which is how a stolen session is stopped. The country and city come from a MaxMind GeoLite2 lookup on our own server; we use them only to protect your sign-in, never for marketing and never to find where you live. Expired records are removed by the nightly clean-up
- Cardholder personal details after a deletion request — Erased within 30 days (stamp records stay, with no personal details in them)
- Deleted personal details still inside our encrypted backups — Up to 14 days in nightly copies and about 4 weeks in point-in-time copies, then overwritten — never restored into use
- A lapsed or cancelled merchant's data (card designs, customer list, stamp history) — 90 days after the subscription pauses or ends. Export freely in that window; after it the data is deleted (the stamp records stay, with no personal details in them, exactly as above)
- A café that signs up but never activates a plan — Closed 90 days after sign-up, like a lapsed café. The card designs and settings go. We keep the name, login email and contact number so a free trial cannot be started again with them; ask us and we erase those too.
- Your merchant login (your name, login email, password hash, two-factor secret) and your café's contact number — Until 90 days after your last café closes, and then the account is closed and cannot sign in. One login can run more than one café, so it is closed only when the last one is gone. We keep your name, login email and contact number after that, so a free trial cannot be started again with them; ask us and we erase those too.
- Merchant billing records (invoices, payment entries) — Kept as long as bookkeeping honestly requires. They contain business records, not cardholder personal data
Where a window also appears in our Terms & Conditions, the numbers match exactly; current values are stated here and updated with notice if they ever change.
7. How we protect your data
We keep the personal-data inventory deliberately tiny, because what we never collect can never leak. What we do hold is protected by encryption in transit, by hardened servers we operate ourselves, by a cryptographic key for each café, and by an append-only stamp ledger. Every scan is verified against your café's own cryptographic key. Every stamp entry is permanently recorded and attributed, and no one can alter or erase what was recorded, café staff included. Phone numbers are masked in our own logs.
8. If something ever goes wrong
If we confirm a data breach affecting personal data, we will tell the merchants it affects without undue delay, and our target is within 72 hours of confirming it. We will say what happened, what data was involved, and what we are doing about it. Merchants relay it to their affected customers. Where we can reasonably notify cardholders directly, we will.
9. Changes, language, and contact
- Changes: material changes are announced to merchants 30 days ahead, by email and in the dashboard, matching the Terms. Every version is dated and archived.
- Language: this policy is written in English and published in Arabic and Kurdish translation for convenience. If the versions ever differ, the English version controls.
- Contact: support@tap2wafa.com, for questions, access requests, corrections, deletions, exports and complaints. One address, and a human answers.
Version 2 · effective 26 September 2026 · last updated 26 September 2026