← Back to TapWorks

Privacy Policy

1. Information We Collect

TapWorks collects information you provide directly when you create an account, link water systems, or use our compliance tools. This includes:

  • Email address and account credentials
  • Water system identifiers (PWSID) you choose to link
  • Compliance data you enter (checklist progress, CCR content, service line inventory)
  • Payment information (processed securely by Stripe)

We also automatically collect certain technical information when you use the Service, including browser type, device information, and usage patterns through analytics tools.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our compliance tracking services
  • Process your subscription payments and manage your account
  • Send you deadline reminders, welcome emails, and important service notifications
  • Respond to your support requests and inquiries
  • Analyze usage patterns to improve the Service and develop new features
  • Protect against fraudulent or unauthorized activity

We will not sell your personal information to third parties or use it for purposes unrelated to providing and improving the Service.

3. Data Processors

We use the following third-party services to operate TapWorks. Each processor is contractually obligated to protect your data and use it only for the purposes we specify:

  • Google Analytics 4 (GA4)

    Anonymous usage analytics including pages visited, features used, and general location (country/region). No personally identifiable information is shared with Google Analytics. You can opt-out using the Google Analytics Opt-out Browser Add-on.

  • Supabase

    Database hosting, user authentication, and data storage. Your account information and compliance data are stored securely in Supabase's infrastructure.

  • Stripe

    Payment processing and subscription management. Your payment card details are handled directly by Stripe and never touch our servers.

  • Resend

    Transactional email delivery including welcome emails, trial reminders, and compliance deadline notifications.

  • Vercel

    Application hosting and content delivery network (CDN) that serves the TapWorks web application.

4. Cookies and Tracking

TapWorks uses cookies and similar technologies for the following purposes:

  • Session Management: Essential cookies to keep you logged in and maintain your session
  • Analytics: Google Analytics cookies to understand how users interact with our Service
  • Fraud Prevention: Stripe uses cookies to detect and prevent fraudulent transactions

Most web browsers allow you to control cookies through their settings. However, disabling essential cookies may prevent you from using certain features of the Service.

5. Data Security

We implement industry-standard security measures to protect your data:

  • All data is encrypted in transit using TLS/SSL
  • Data at rest is encrypted using AES-256 encryption
  • Access to production systems is restricted and logged
  • Regular security reviews and updates

While we take reasonable precautions to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

6. Data Retention

We retain your data for as long as your account is active or as needed to provide you services. Specifically:

  • Account data is retained while your account is active
  • Compliance data and reports are retained for your reference
  • Payment records are retained as required by law and for dispute resolution
  • Analytics data is aggregated and anonymized after 14 months

You can request deletion of your account and associated data at any time by contacting us at privacy@tapworks.report.

7. Your Rights

Depending on your location, you may have certain rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete personal data
  • Deletion: Request deletion of your personal data, subject to legal retention requirements
  • Data Portability: Request export of your data in a machine-readable format
  • Opt-Out: Opt out of marketing communications and analytics tracking

To exercise any of these rights, please contact us at privacy@tapworks.report. We will respond to your request within 30 days.

8. Children's Privacy

TapWorks is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.

If we discover that we have collected personal information from a child under 13, we will promptly delete that information from our systems.

9. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons.

If we make material changes, we will notify you by email or by posting a notice on our website prior to the change becoming effective. We encourage you to review this Privacy Policy periodically.

Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of the updated policy.

10. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

privacy@tapworks.report

Version 1.0 · Last updated January 30, 2026