Privacy Policy

Last updated: October 4, 2026

⚠ This policy has not yet been reviewed by a lawyer. It is accurate to the system as of the date above, and material changes will be reflected here with an updated date.

Summary in one paragraph

We collect the personal data listed below to run and improve the product. For your account, that is your email address and password. For the features, it is your name, watchlist, alerts and plan. We keep an IP address in our database in one case only, described under What we store. Our server logs and error reports never record an IP address or your email address: they write a short one-way code in its place (see Server logs under What we store). We never see your card details: Stripe handles them. We use Google Analytics 4 and Google Ads to see how the site is used and to measure our ads. They set cookies and get limited data about your visits and signups. Our servers also send Meta a hashed version of your email address when you sign up, start a trial or are charged. With it, we send the IP address and browser user agent of your most recent signup, Google sign-in or checkout, when we have them. Hashing is not anonymisation: Meta matches those hashes against its own records. If you may be in the European Economic Area, the United Kingdom or Switzerland, we ask you first. Google and Meta get none of this unless you press Accept. The Cookies and Sub-processors sections below give the details. We do not sell your personal data. We do share limited advertising-measurement data, as described there.

What we collect at signup

  • Email address — required. We use it to sign you in, for account emails (welcome, trial reminders, alerts you turn on) and to recover your account. We also send other product emails, such as tips, upgrade offers and a note if you have been away. You can turn those off in your email settings. A one-way SHA-256 hash of it is also sent to Meta as a conversion signal — never the address itself. See Sub-processors.
  • Password — required, minimum 8 characters. We never store the raw password; only a one-way bcrypt hash that cannot be reversed back to your password.
  • Name — optional. Used to greet you in our emails and in the app. If someone signs up with your referral link, their welcome email shows your name. The Tapeline team also sees it in some internal alerts and reports.
  • Referral code — optional. If you signed up via someone else's referral link, we record which user referred you so we can credit them the referral bonus. They can see a partly hidden version of your email address, your plan, whether you have paid, and when you joined. They also get an email with the partly hidden address once you confirm your email address.
  • Cloudflare Turnstile token — your answer to the bot check. We check it with Cloudflare, then throw it away.
  • IP address — kept in server memory until the server restarts, to limit how many requests and signups come from one address. When you sign up with an email and password, we also send it to Cloudflare with the bot check. If you hit the signup limit, our server logs note it, with a short one-way code in place of your IP address and email address. If the bot check refuses a signup, the Tapeline team may get an email with the email address that was typed and a short one-way code for the IP address it came from. For the one IP address we may keep in the database, see What we store.
  • How you found us — your answer to the optional “How did you hear about us?” box. We keep the first 40 characters. If your browser kept them, we also store the campaign tags, the website that sent you and the first page of ours you landed on (see Browser storage under Cookies). We add Google or Meta ad click codes only if ad measurement is allowed for you (see Cookies). We store all of these with your account, to see where signups come from.
  • Email choices — whether you ticked the boxes for the weekly market email and the daily Top 10 email. Both start unticked.

What we store while you use the product

  • Your tier (Free / Pro / Premium / Lifetime) and trial-end date.
  • Your watchlist tickers and any notes you add to them, your alert rules and the alerts we send you, your saved scans, and any settings you configure.
  • Your Stripe customer ID — linked on first checkout. We never receive or store card numbers; Stripe handles all payment data directly.
  • Your referral code (your own code to share) and how many unused referral credits you have. If you are one of the top 10 referrers, other signed-in users see a short form of your name and how many people you referred. The short form is your first name, plus your last initial if you gave one. If you have not set a name, it is the first two letters of your email address.
  • A list of which lifecycle emails we have already sent you (for example "3,7,end"), so we never send one twice.
  • Your scan history: the filters and search text of each scan you run, and the top results it returned, so we can see how the scanner is used.
  • When your account was made and last changed, and when you were last active (updated at most once an hour).
  • Your cookie choice as our servers last recorded it (or that you were not asked). We also keep when and where it was recorded, such as the cookie banner, signup or sign-in, so our servers can follow it (see Cookies).
  • For the Meta events described under Sub-processors, and for nothing else, we keep: the most recent IP address and browser user agent from your signup, Google sign-in or checkout; the latest _fbp value your browser sent with those requests; and the most recent Meta click identifier (_fbc) it has sent us, with when your browser first saw that click. Each is replaced only by something newer. We store these only when ad measurement is allowed for you, and use them only while it still is (see Cookies).
  • If you turn on browser push alerts: the push address and keys your browser gives us, and that browser’s user agent (a line of text naming the browser, its version and the operating system). Your browser maker’s push service (for example Google, Mozilla, Apple or Microsoft) delivers the alerts, encrypted. We delete these when you turn push alerts off on our site, when the push service tells us the subscription no longer exists, or when you delete your account.
  • A log of which features you use: running a scan, opening a stock page, saving a scan, adding to your watchlist, opening the billing page and starting a checkout. It has one entry per feature per day. We also log the date and time each time you reach a Free-plan limit. Both logs are deleted with your account.
  • If you cancel a paid plan: when you cancelled, the reason you pick and any comment you type.
  • If you subscribe to the daily email: your email address, where on the site you subscribed, any campaign tags (see Browser storage under Cookies), and whether you are subscribed.
  • If you answer our survey: your answers and, if you ask for a reply, your email address. Survey answers are not linked to your account.
  • Server logs. Our servers log each request with the time, the web address requested (which can include a search you typed) and the result. These lines do not include your IP address. Where any other log line would include an IP address or an email address (for example a contact-form message, a daily-email signup or a refused signup), our servers write a short one-way code in its place. The same address always gives the same code, so we can see repeat attempts, but the code cannot be turned back into the address. When the site shows you an error, we log the page address and your browser’s user agent. Some lines record your email address but not your IP address. For example: when you sign up or sign in with Google, join or leave the daily email, or when an email to you fails or is not sent. Fly.io’s log search keeps these logs for 7 days.

Website visits

We keep our own log of visits to tapeline.io, whether or not you have an account. It shows us how many people come, where from, and how the site is used. For each visit we store:

  • the page you arrived on, with any tracking codes except our own removed;
  • the website that sent you (its name only, not the page);
  • any campaign tags on the link, and which kind of ad click code it carried, if any (not the code itself);
  • whether you used a phone, tablet or computer, and which browser and operating system;
  • your device’s time zone and language;
  • how many pages you viewed, the last page you viewed, and how long you stayed.

If you are signed in, the visit is linked to your account. The Tapeline team gets a private notification when a visit starts and a short summary when it ends (see Telegram under Sub-processors).

Your browser keeps a random code for the current visit in local storage. It can also keep a second random code, so a return visit can be counted as a return. We do not store your IP address or your full browser details with a visit. We do not keep the return-visit code if your browser sends Global Privacy Control or Do Not Track. If we ask you about cookies (see Cookies), we keep the return-visit code only after you press Accept, and we remove it if you press Reject. Clearing your browser storage removes both codes.

This log is our own. It is not one of the optional tools under Cookies. Apart from the return-visit code, the cookie banner does not switch it off, and it works the same whether you press Accept or Reject.

What we explicitly do not collect or store

  • Payment card numbers — Stripe handles these directly. We only see a stripe_customer_id.
  • Bank account details, SSN, passport, or other government IDs.
  • Your brokerage credentials or actual portfolio holdings. Tapeline scans the public market — it does not connect to your broker.
  • IP addresses in the database or in our logs, with the one exception under What we store. Server logs and error reports carry a short one-way code instead; see Server logs under What we store.
  • Device fingerprints. Our code does not work out a code from your browser’s settings to recognise your device. (Cloudflare’s bot check on the signup page does look at your browser, to tell people from bots; see Cloudflare under Sub-processors.)
  • Location or geolocation data.
  • We have never sold your personal data and have no plan to. But we do share limited advertising-measurement data with Google and Meta. Some privacy laws, California’s among them, count that kind of sharing separately from a “sale”, so we name it here. What each company gets is listed under Sub-processors, and the cookies involved are under Cookies.

Sub-processors

These are the outside companies whose systems may touch your data when you use Tapeline. Each one is listed with what it sees, and whether it is switched on today. Most act only on our instructions. The advertising platforms are different. Google Ads and Meta decide their own purposes for what they receive, and may combine it with data they already hold. So treat them as independent recipients, not as vendors working for us.

  • Stripe — payment processing (PCI DSS Level 1). Sees your email, our internal account ID, and any billing data you provide directly to Stripe.
  • Resend — email delivery. It sees your email address, your name (if set) and the content of the emails we send you. It also carries messages sent through our contact form (your name, email address and message), and the team’s internal emails about accounts. These include the daily activity report, which lists account email addresses and app activity. They also include alerts such as a refused signup, with the email address tried and a short one-way code for the IP address it came from. It also delivers a private activity report to the Tapeline team every 6 hours: for each signed-up account that used Tapeline in that time, it lists the email address, plan, how they found us, time on the site, visits and pages, which tools they used and how often (the scanner, saved screens, stock pages, watchlist, alerts, free-plan limits and the billing page) and their device’s time zone, plus totals for all visits.
  • Cloudflare — DNS, Turnstile bot checks, and Email Routing for mail sent to @tapeline.io. When you open our signup page, your browser loads Cloudflare’s Turnstile script, so Cloudflare sees your IP address and browser details. When you sign up with an email and password, we also send Cloudflare your bot-check answer and your IP address to check it. Email Routing sees the mail sent to us, such as messages from our contact form, and passes it on to the team’s inbox.
  • Google (Analytics 4 & Google Ads) — usage analytics and advertising measurement (US). It gets page views, in-app events, and a signal when you sign up or subscribe. Its tags set analytics and advertising cookies (e.g. _ga, _ga_*, _gcl_*). They also get your IP address from your browser, and Google uses it to estimate your city and country. If we ask you about cookies (see Cookies), none of this happens until you press Accept.
  • Google Sign-In — only if you choose “Continue with Google”. Google sends us your email address and name, and Google knows that you signed in to Tapeline.
  • Google (Gmail) — the Tapeline team’s email inbox. Our internal emails about accounts can arrive there. The daily activity report and the activity report sent every 6 hours list account email addresses and app activity. An alert about a refused signup includes the email address tried and a short one-way code for the IP address it came from. An alert about a Free-plan limit you reached includes your email address, your name and the names of your saved scans. Mail sent to an @tapeline.io address, such as messages from our contact form, can be forwarded there too.
  • Meta (Facebook & Instagram) — advertising measurement. Currently enabled. Meta is not a vendor acting only on our instructions. It decides its own advertising purposes, and may combine what it receives with data it already holds about you. There are two separate flows. From our servers: we send Meta one event at each of these moments: you create an account, a trial starts, you pay at checkout, or a trial’s first payment is charged. We send these only if ad measurement is allowed for you (see Cookies). Each event holds a SHA-256 hash of your email address, a hash of our internal account ID, the event name, a timestamp and a de-duplication ID. Some events also hold the amount charged and its currency, the plan, or how you signed up. Some hold the address of the page the event belongs to: the page you signed up on, or our billing page. When your browser had them, the event also carries the _fbp and _fbc values described under Cookies. These are Meta’s own browser and click identifiers, from your signup, Google sign-in or checkout. The event also carries the IP address and browser user agent of your most recent signup, Google sign-in or checkout, when we have them. Those are sent unhashed, as Meta requires, and we keep only the most recent of each on your account. We do not send your raw email address or your name. Hashing is not anonymisation: Meta matches the hash against its own records, so treat this as sharing personal data. From your browser: Meta’s script runs on our public marketing pages only. It never runs on the signed-in app, so it cannot see which tickers you look at. It sets the cookies described under Cookies and reports each page view. Loading that script tells Meta your IP address, browser and language. The request goes to facebook.com, so your browser may attach Facebook cookies it already holds. That can let Meta link the visit to your logged-in Facebook or Instagram account. This happens between your browser and Meta; we neither see nor store it, and a tracker-blocking extension prevents it.
  • PostHog — product analytics. Not currently enabled. It receives your account ID, account tier, and product-usage events to build a per-user product profile, and sets analytics cookies. It is never sent your email address.
  • Microsoft Clarity — session replay and heatmaps. Not currently enabled. It records how you move through pages.
  • Plausible — privacy-focused traffic analytics. Not currently enabled. It is cookie-less and records no per-person identifier.
  • Fly.io — runs our website and our backend servers in Sydney, Australia. Every page you load and every request the app sends passes through Fly.io. That includes what you type into forms, your IP address and your sign-in cookie. Fly.io first receives each request at one of its servers near you, which may be in your own country, and passes it on to Sydney. Our servers there read and write our database, so the data we hold about you is processed on Fly.io, but it is stored with Neon. Fly.io’s log search keeps our server logs for 7 days (see Server logs under What we store).
  • Neon — stores our database, on Amazon Web Services in Sydney, Australia. It holds everything we store about you, as listed above.
  • TradingView — draws the price chart on each stock page inside the app. The chart loads straight from TradingView, so TradingView sees your IP address, your browser details and which stock you are looking at, and it may set its own cookies. We send it nothing about your account. If we ask you about cookies (see Cookies), the chart waits until you press Accept. Until then, and after Reject, it loads only if you click Load chart on that page.
  • Sentry — error tracking. Sometimes something breaks while our server is handling one of your requests. Then Sentry gets the error, the address requested and your browser’s user agent. It also gets what you sent in that request, such as the name and message you typed into a form, with any email address replaced by a short one-way code. Passwords and sign-in codes are removed first. This includes errors in your browser that the site reports to us. We do not send Sentry your cookies. We do not send it your IP address either: any IP address or email address in an error text is replaced by a short one-way code first.
  • Telegram — used only for internal alerts to the Tapeline team. For example: a notification when someone signs up or subscribes, and for each website visit, one when it starts and a summary when it ends. A visit summary says where the visitor came from, which device and browser, their time zone, how long they stayed and how many pages they viewed. Messages about a signed-in visitor include their email address and plan. They stay in the team’s private Telegram chat. If Telegram is not set up, the signup, subscription and payment alerts go to the team’s email inbox instead. Every 6 hours the team also gets a short activity report there: for each signed-up account that used Tapeline in that time, its email address, plan, how they found us, time on the site, visits, pages and device time zone, plus totals for all visits and for each tool, with no names next to the totals. Once a day the team also gets a report, in this chat and by email. For each new account, it gives the email address, when the account was made, where the person came from and the first page they saw. For each account that used the app that day, it gives:
    • the email address and plan;
    • about how long they spent;
    • how many scans they ran, the searches they typed and the filters they used;
    • whether they looked at a stock, added one to their watchlist or saved a search.
    Telegram is no longer offered as a way to get your own alerts.
  • Third-party market-data feeds — power the scanner with prices, fundamentals, macro indicators, SEC filings, and news. No user data is sent to any of them. They power the scanner; they never see you.

Cookies

We set the cookies below ourselves, without asking.

  • tapeline_session keeps you signed in. It holds a signed token with your account ID. It lasts 30 days, or until you sign out.
  • tapeline_consent stores your cookie choice (Accept or Reject, and when you chose) for 6 months. It is also sent to our own servers so they follow the same choice. Page JavaScript can read it, because the page checks it before loading the optional tools below.
  • tapeline_device remembers that this browser has already passed an emailed sign-in check, so signing in with your password from it does not ask for an emailed code again. We set it when you create an account with email and password, when you enter a sign-in code we emailed you, and when you finish resetting your password. It holds a signed token with your account ID, when it was issued and when it expires, a counter that lets us cancel it, and a random number. It holds nothing about your device, and we keep no list of your devices. It lasts 30 days. Signing out does not remove it. When you reset your password, every other browser has to enter an emailed code again. When you turn off two-factor authentication, every browser has to, including the one you used. Signing in with Google does not use it. Accounts with an authenticator app are asked for that code instead.
  • oauth_state_* and oauth_next_* exist only while you sign in with Google. They last at most 10 minutes and are deleted when you come back. The first protects the sign-in against forgery. The second remembers which page to return you to.
  • tapeline_mfa_challenge is set only when an account with an authenticator app signs in with Google. It carries a 5-minute token to the code screen, which then deletes it. Page JavaScript can read it, because the code screen sends it back to us. On its own it does not sign anyone in.

The cookies above are for signing in, its security checks and your cookie choice. None of them is used for analytics or advertising.

oauth_attr_* is different. It is set at the same time as oauth_state_*. It lasts at most 10 minutes and is deleted when you come back. It carries your cookie choice through the sign-in, and any campaign codes your browser holds (see Browser storage below). If ad measurement is allowed for you, it also carries ad click codes and Meta’s _fbp value. If the sign-in creates a new account, we store the campaign and click codes with it. Any Google sign-in, new account or not, also updates what we keep for Meta: the _fbp value, IP address and browser user agent (see What we store). That happens only if ad measurement is allowed for you. It is used to measure our advertising and to follow your cookie choice.

Page scripts cannot read tapeline_session or tapeline_device, and your browser sends them only over secure connections. Another website cannot make your browser send them, except by linking you to our pages. Both work on tapeline.io and its subdomains. Page scripts cannot read the oauth_* cookies either. Your browser sends them only over secure connections, and only to api.tapeline.io.

Everything else is optional measurement. Google Analytics 4 and Google Ads are active. Their script sets cookies on tapeline.io, for example _ga and _ga_*, which last 2 years, and _gcl_*, which last 90 days. Google may also set cookies on its own domains, such as doubleclick.net. PostHog, Microsoft Clarity and the Meta pixel would each set their own; of those, the Meta pixel is currently enabled.

Meta's script sets _fbp on every visit — a browser identifier lasting roughly 90 days — and _fbc when you arrive on a link carrying Meta’s click identifier (fbclid). Both are set on tapeline.io rather than on facebook.com, are readable by page JavaScript rather than HTTP-only, and are sent to Meta with the page address on each page view. The Meta script runs on our public marketing pages only, never on the signed-in app.

If you are in the European Economic Area, the United Kingdom or Switzerland, none of these optional cookies is set, and none of these scripts loads, until you press Accept on our cookie banner. Reject keeps them off, and you can change your choice at any time with Cookie settings at the bottom of every page. The banner covers these optional tools. It also covers the TradingView chart on stock pages and our return-visit code, but not the rest of our own visit log (see Website visits). To decide whether to ask you, your browser checks its own time zone and the region of the server your request reached. We look up no location and store none. If either suggests you may be in those countries, we ask, so some visitors elsewhere are asked too. As a backstop, Google applies its own regional default: if we miss you, Google’s tags set no cookies and redact ad click identifiers. Everywhere else these tools run as described above, and you can still change your choice with Cookie settings.

When you arrive from an ad, and only if these tools are allowed for you, we keep the ad’s click code (Google’s gclid, gbraid or wbraid, or Meta’s fbclid) in your browser’s local storage for 30 days, so a signup that follows can be credited to that ad. If you then sign up, the click code is saved on your account.

Our servers follow the same choice. Unless your current choice is Accept, or you are outside those countries, we send no event about you to Meta or Google from our servers, we save no ad click code and no Meta browser key on your account, and we use none that is already there. Meta browser keys are the _fbp and _fbc values and the IP address and browser user agent we keep for Meta. Press Reject and we delete the click codes and Meta browser keys from your browser and from your account. If you are signed out when you press it, your account is cleared the next time you sign in on that browser. The ad campaign name (utm_* tags), the website that sent you and the page you first landed on are not ad click codes or browser keys, and we keep them whatever you choose.

Before this banner existed, we kept ad click codes and Meta browser keys on accounts without asking. We deleted them when the banner went live. Accounts created before this choice existed are treated as not having accepted.

Browser storage. Our own code also keeps some values in your browser’s local storage, which stays until you clear it, and session storage, which is cleared when you close the tab. Unless we say otherwise below, they stay on your device.

  • Visit codes (tapeline_visit_v1, tapeline_visitor_v1). They are sent to us with each visit report, described under Website visits. The return-visit code follows your cookie choice, as described there.
  • Campaign codes. If you arrive from a link with campaign tags (utm_*), we keep the first ones we see. We also keep the name of the website that sent you and the first page of ours you landed on. Each is kept for 30 days. They are sent to us when you sign up, and stored with your account. The campaign tags are also sent when you subscribe to the daily email, and stored with your subscription. We keep them whatever you choose on the cookie banner, and even if your browser sends Global Privacy Control or Do Not Track.
  • Ad click codes (gclid, gbraid, wbraid, fbclid), kept the same way, but only if ad measurement is allowed for you, as described above. The Meta click code is also sent to us when you start a checkout.
  • Your settings: light or dark theme, and the last 5 tickers you opened, for the search box.
  • Messages already shown or closed, so we do not show them again, such as the email-verification banner, the trial offer and the upgrade prompt. Some of these keys include your account ID. While you are signed out, we also keep the tickers you viewed in the last 30 days, so we can decide when to suggest an account.
  • Events already counted, so the same signup, trial, purchase or first use is not reported to Google or Meta twice. Each holds only “1”. Some keys include your account ID or a Stripe checkout ID.
  • A checkout you started, kept in session storage and used only within 2 hours, so the page you return to from Stripe knows whether it was a trial.
  • Browser alerts. If you turn on browser push alerts, your browser installs a small script from us (a service worker) that shows them. See What we store.

Data retention

While your account is open, we keep its data, including your scan history. We do not delete inactive accounts.

If you cancel a paid plan, your account stays open on the Free plan. We keep its data until the account is deleted.

When an account is deleted, it is removed from our live database. It is a hard delete: the data is removed, not marked as deleted. Any Stripe subscription is cancelled too. The deletion covers:

  • your profile, watchlists, alert rules and alert history;
  • your saved scans and scan history;
  • the logs of features you used and Free-plan limits you reached;
  • website visits made while signed in;
  • push-notification subscriptions and API keys;
  • subscription records and your daily-email subscription.

A few records stay after deletion:

  • Messages our team received about your account. These are alerts about your signup, your payments, Free-plan limits you reached and visits you made while signed in, plus our activity reports. They include your email address and can include your name, the names of your saved scans and the searches you typed. They stay in our team’s email inbox and private Telegram chat.
  • Messages you sent us, and any survey answers you gave.

Backups and logs: deleted data can stay in the backups kept by our database host, Neon, until those backups are removed. Server logs can include your account ID and searches you typed; an email address or IP address appears there only as a short one-way code. Fly.io keeps them for 7 days. Error reports sent to Sentry can include the same details, with the same codes, and are kept for up to 90 days. Resend, which sends our emails, keeps copies of them for 30 days.

Other services: Stripe keeps your customer record and payment history under its own privacy policy and the law that applies to it. Deleting your Tapeline account does not delete your Stripe customer record. Data already sent to the analytics and advertising services listed under Sub-processors is kept under their own policies.

Other records: we delete records of visits not linked to an account 13 months after the visit. If you unsubscribe from the daily email, we keep your address, marked as unsubscribed.

Your rights

You can request, at any time:

  • A copy of the personal data we hold on you, sent to you by email.
  • Correction of any inaccurate field.
  • Deletion of your account and the data linked to it, except the few records listed under Data retention.
  • A list of which sub-processors received what data.

Email privacy@tapeline.io with your account email in the subject line. We respond within 7 days and fulfil the request within 30 days.

GDPR (EU) and CCPA (California)

Residents of the EU, UK, and California have additional rights under local law — access, correction, deletion, data portability, and the right to opt out of the sale or sharing of personal information. California’s CPRA treats “sharing” as a category separate from “sale”: passing identifiers to an advertising network so it can target you elsewhere can count even when no money changes hands. We do not sell your personal data and do not intend to — but we are not going to lean on that distinction, because we do run advertising and analytics tags that pass identifiers to third parties. Sub-processors and Cookies above are the current record of which are actually running. Cookie settings, at the bottom of every page, turns the advertising and analytics tags off for your browser at any time (not our own visit log, see Website visits); for anything else, email the privacy address below and we will action it manually. Whether these obligations bind us as a matter of law has not been confirmed by counsel — see the note at the top of this page — and we would rather honour the request than argue the threshold.

Tapeline is run from Australia. Our servers (Fly.io) and our database (Neon) are in Sydney, Australia. We also send data to the other recipients listed under Sub-processors, and they may handle it in other countries:

  • the United States, where Stripe, Resend, Google, Meta, Cloudflare, Sentry, TradingView and Fly.io are based;
  • Ireland, where Meta handles data about people in the European Union;
  • the countries where Cloudflare, Google and Fly.io run their networks, because your request may first reach one of their servers in or near your own country;
  • wherever Telegram keeps the team’s chat, in its own data centres outside Australia.

For vendors that work on our instructions, we rely on the data-protection terms in their standard agreements where they offer them, including Standard Contractual Clauses where those apply. The advertising platforms are not in that category — they set their own terms and act for their own purposes, which is why they are called out separately above.

Children

Tapeline is not directed at users under 18 and we do not knowingly collect data from minors. If we learn we have, we delete it.

Changes to this policy

We log every change with a date stamp at the top of this page. Material changes (new sub-processors, new categories of data collected, changes to how long we keep things) get a heads-up email to all account holders 14 days before the change takes effect.

Contact

privacy@tapeline.io