Legal
Privacy policy
Last updated 18 August 2026
Who we are
Tapbound is operated by SkyWay Mark Trading Ventures (TapBound.com), located at Sixth Floor, 602, Shivam Raj Residency, Ranjan Path, near Panch Mandir, Danapur, Patna - 801503, Bihar, India. We are the data controller for personal data you provide when using this platform. Our contact emails for data protection matters are [email protected] and [email protected].
When you build an app on this platform and that app collects data from its own end users, Tapbound acts as a data processor on your behalf. You are the controller of that data. A Data Processing Agreement (DPA) is available to download from your account settings.
What personal data we collect and why
Account data: email address, hashed password, account status, and marketing preference. Collected under contract necessityto create and operate your account.
App configuration and assets: your website address, app name, colour choices, icon and splash-screen uploads, build outputs. Collected under contract necessity to deliver the conversion service.
Credentials you provide: store API keys, signing certificates, and integration tokens (e.g. Firebase, OneSignal, AdMob). Encrypted at rest; used solely for the submission or integration they were provided for. Collected under contract necessity.
Billing status: plan tier, payment status, and Paddle transaction references. We do not store card numbers. Collected undercontract necessity.
Support communications: messages you send us via support tickets or email. Collected under legitimate interest (resolving your request).
Analytics events: anonymised funnel events (e.g. page visited, wizard step completed) with no personal identifiers, collected only after you give cookie consent. Collected under consent.
Security and fraud logs: IP address (in rate-limit counters, not persistently stored), failed login timestamps, and audit-log entries of privileged actions. Collected under legitimate interest(security and abuse prevention).
Lawful bases (GDPR Article 6)
- Contract (Art. 6(1)(b)): account, configuration, build, credential, and billing data necessary to provide the service you requested.
- Consent (Art. 6(1)(a)): marketing email and non-essential analytics, each with a clear opt-in and a one-click opt-out at any time.
- Legitimate interest (Art. 6(1)(f)): security logging, fraud prevention, abuse enforcement, and support communications. We have assessed that these interests are not overridden by your rights.
- Legal obligation (Art. 6(1)(c)): retaining billing records to the extent required by applicable tax or accounting law.
Subprocessors and international transfers
We rely on the following primary subprocessors:
- Cloud build infrastructure: automated compilation and packaging services (including Expo Application Services) used strictly to produce application binaries under Standard Contractual Clauses.
- Cloudflare R2: build artifact storage. Operated by Cloudflare Inc. (US). Standard Contractual Clauses apply.
- Transactional email relay: delivery of account and build notification emails.
- Paddle.com Market Limited: payment processing. Paddle acts as Merchant of Record and processes billing data under its own privacy policy and GDPR obligations.
Where personal data is transferred outside the UK or EEA, we ensure appropriate safeguards are in place, including adequacy decisions, Standard Contractual Clauses (SCCs), or equivalent lawful transfer mechanisms.
How long we keep your data
- Account and configuration data: for the life of your account, then deleted within 30 days of account closure, except where retention is required by law.
- Build artifacts (free plan): 7 days from build completion, then automatically deleted.
- Build artifacts (paid app): retained until you delete the app or the account.
- Billing records: 7 years, or as required by applicable tax law.
- Support communications: 2 years from the last message, unless a legal obligation requires longer retention.
- Security logs: 90 days.
Your rights
Under GDPR (and equivalent UK law), you have the right to:
- Access: download all personal data we hold about you (available from your account settings as a JSON export).
- Rectification: correct inaccurate data (email and password are editable from account settings; contact support for other corrections).
- Erasure (“right to be forgotten”): request deletion of your account and associated data via account deletion in settings or by emailing [email protected]. Billing records are retained only to the extent required by law.
- Restriction: request that we restrict processing of your data while a dispute is resolved.
- Data portability: receive your data in a machine-readable format (the JSON export).
- Objection: object to processing based on legitimate interest. We will cease unless we can demonstrate compelling legitimate grounds.
- Withdraw consent: withdraw consent for marketing email or analytics cookies at any time, without affecting the lawfulness of prior processing.
To exercise any right, email [email protected]. We will respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with your national data protection authority (e.g. the ICO in the UK at ico.org.uk).
California residents (CCPA / CPRA)
Tapbound does not sell or share your personal information for monetary consideration or for cross-context behavioural advertising. California residents have the right to know what personal information we collect, to delete it, to correct it, and to opt out of any future sale (which does not apply here). To exercise these rights, email [email protected].
Children’s privacy
This platform is intended for users aged 18 and over. We do not knowingly collect personal data from children under 13 (or under 16 where applicable under local law). If you believe we have inadvertently collected such data, contact [email protected] and we will delete it promptly. The pre-build flow disables data-collecting features for any app declared as directed at children.
Cookies and tracking
We set only essential cookies by default (session authentication). Analytics and marketing cookies are set only after you give explicit consent via the cookie banner. You can withdraw consent or change your preference at any time using the floating cookie control on every page. For full details, see our cookie notice embedded in the consent panel.
Security
All credentials you provide are encrypted at rest with AES-256-GCM. Sessions use signed, short-lived JWT tokens. We apply rate limiting, bot protection, and SSRF filtering across all public endpoints. For vulnerability reports, see the security page.
Changes to this policy
Material changes will be notified by email at least 30 days before taking effect. The updated policy will be posted here with a new effective date.
Contact
Data protection enquiries: [email protected]