privacy policy
last updated 2 september 2026
TapKhata replaces a café’s paper punch card. We keep the count of your visits so a café can honour its own offer, and we try to keep as little else as possible. This page says exactly what that means.
What we store
There are two ways in, and they store different amounts. Whichever you use, you end up with the same single account — sign in with Google today and with a code tomorrow and your stamps are all in one place.
- Your email address, either way. It is what tells us you are you.
- Your name — as Google gives it to us if you sign in that way, or as you type it if you asked for a code instead. If you came by code and never typed one, we do not have one.
- An account identifier from Google, only if you sign in with Google. A long meaningless string that lets us recognise you again. If you only ever use an emailed code, we never have one.
- The codes we email you, scrambled so we cannot read them back, each with the time it stops working and a count of wrong guesses. They expire in minutes and are thrown away once used.
As you collect stamps, we also store:
- Your loyalty cards — which café, how many stamps, whether a reward has been earned or collected, and when and at which branch it was collected.
- Counts of a few actions— tapping a café’s stand, choosing to leave a Google review, choosing to collect a stamp. We record what happened, at which branch, and when.
- That it was you who tapped “leave a review”, if you were signed in at the time. It lets a café see how many peopletapped it, not just how many taps there were. Tapping from a café’s stand without signing in records nothing about you, and never asks you to. Either way we cannot tell whether you went on to write a review — Google does not tell us, and no part of TapKhata ever knows.
What we never store
- Payment details.TapKhata never handles money. We are not connected to the café’s till, so we do not know what you bought or what you spent.
- Your location.We know which café branch scanned you, because a member of staff scanned you there. We never read your phone’s location.
- Your contacts, photos, or anything else from your Google account. Signing in with Google gives us your name, email and that identifier. Nothing more is requested and nothing more is received. Signing in with an emailed code tells us even less — it proves you can read that mailbox, and that is all.
- A password. There is nothing to store: Google vouches for you, or a code we email does. Neither leaves a password with us to lose.
Who can see it
The cashier who scans you sees a stamp count and nothing else — not your name, not your email. Their screen shows how many stamps that card now has and whether a reward is ready.
A café owner sees numbers, not people. Their dashboard reports totals — how many taps, how many stamps, how many customers came back — and does not list who those customers were.
We do not sell your data, and we do not share it for advertising. Beyond the café you are collecting stamps at, your information reaches only the services that make the product work: Google, if you choose to sign in that way; the service that delivers our sign-in emails, which is given your address and the code; and the company that hosts our servers.
Closing your account
Closing your account switches it off; it does not erase it. Your stamps, your card history and your name and email stay in our database in a deactivated state. We are telling you this plainly because the honest word is deactivation, not deletion, and we would rather say so than imply an erasure we do not perform.
We keep records this way so a café’s history of what it gave away stays intact and so a closed account can be restored if it was closed by mistake. If you want your data genuinely removed, email us and we will tell you exactly what we can and cannot do — and we will not pretend it is automatic.
Keeping it safe
You never set a password with us, so there is none for us to leak — your session rests on your Google account, or on a code we emailed to an address only you can read. Those sign-in codes are stored scrambled, expire in minutes, and lock out after a few wrong guesses. The code on your screen that a cashier scans expires after about three minutes, so a photograph of it is not useful later. Café staff reach the system through their own credentials, which an owner can revoke at any time.
Children
TapKhata is meant for adults buying coffee. We do not knowingly create accounts for children under 13, and we have no reason to identify a customer’s age.
Changes to this policy
If what we store changes, this page changes with it and the date at the top moves. We are a small team running a pilot; if we get something here wrong, tell us and we will fix it.
questions? [email protected]