tptaplyy
HomeAbout
Featuresv
Pass creationCampaign managementAnalyticsCross-wallet supportTeam operations
Business Typev
All industriesRetail and store groupsRestaurants and hospitalityEvents and venuesGyms and membershipsClubs and associationsChains and franchises
Pricing
Englishv
EnglishFrancais
Get Started

Legal center

Passholder Privacy Notice

How data is handled when a person receives or uses a pass powered by taplyy.

Effective
July 18, 2026
Version
1.0
Language
English

Legal documents

Legal overviewTerms of ServiceAcceptable UsePrivacy NoticePassholder PrivacyData Processing AddendumCookie NoticeSubprocessors

Legal or privacy question?

support@taplyy.com
Pre-launch operator notice. taplyy is currently an unincorporated business operated from Lebanon. Its registered legal name, service address, and company number must be added before commercial launch.

Applies to: People who receive, save, use, scan, or remove a customer pass · Effective July 18, 2026 · Version 1.0

1. Who controls your program data

The business named on your pass is the issuer and operator of the loyalty, membership, offer, ticket, access, or other program. That business decides why your information is used and is generally the data controller or equivalent responsible party.

taplyy provides pass infrastructure to that business and generally processes passholder information only on its documented instructions. Apple and Google independently operate their wallet platforms under their own terms and privacy notices.

Contact the business identified on your pass first for questions about eligibility, rewards, balances, offers, access, refunds, messages, or its privacy practices. You may also contact support@taplyy.com if you cannot identify or reach the issuer.

2. Data that may be processed

  • Pass identifiers, pass type, program or membership identifier, status, tier, balance, points, entitlement, expiry, and other fields selected by the issuer.
  • Contact or profile information supplied to the issuer or during a lawful enrollment flow, such as name, email, or telephone number.
  • Pass lifecycle events, such as creation, delivery, save, activation, update, removal, scan, redemption, or use, where the wallet platform or issuer makes those signals available.
  • Campaign and notification records, including audience selection, message status, and interaction signals available to the issuer.
  • Technical, security, and audit data required to deliver and protect the pass service.

3. Location-related passes

An issuer may configure business locations so Apple Wallet or Google Wallet can make a pass relevant near a venue. The wallet platform and your device control device-level location permissions and relevance behavior under their own settings and privacy terms.

taplyy stores the venue coordinates and campaign rules selected by the issuer. taplyy does not receive your device's continuous GPS history from Apple Wallet or Google Wallet unless a separate feature expressly tells you otherwise and obtains any permission required by law.

4. Why data is used

  • Create, sign, deliver, display, update, validate, and deactivate the pass.
  • Administer the issuer's customer program, benefits, tickets, access, balances, scans, and redemptions.
  • Send program updates or marketing selected by the issuer where a lawful basis and any required consent exist.
  • Measure adoption, usage, engagement, and program performance for the issuer.
  • Prevent fraud, secure the service, troubleshoot, comply with law, and resolve support requests.

5. Apple Wallet and Google Wallet

To provide a pass, required pass content and identifiers are transmitted to the selected wallet platform. Google may host or cache Google Wallet objects and return lifecycle signals. Apple Wallet passes are signed under the responsible Apple issuer identity and may communicate with an update service. Each platform processes information under its own terms and privacy notice.

Removing a pass from a device does not automatically delete the issuer's program account or records. Contact the issuer to close the underlying program or exercise a privacy right.

Apple Privacy Policy ↗Google Privacy Policy ↗

6. Marketing and advertising limits

The issuer must provide required notice and obtain consent before sending marketing where applicable. You can remove a pass, adjust wallet or device notification settings, and contact the issuer to withdraw marketing consent.

Apple pass-derived user or device data may not be combined with other data for targeted advertising, advertising measurement, or sharing with data brokers. taplyy does not sell passholder personal data.

7. Retention and your rights

The issuer sets the main retention period for its program data, subject to its legal obligations and taplyy's contract. Wallet platforms may separately retain data under their policies. taplyy deletes or returns Customer Personal Data as described in its Data Processing Addendum.

Direct access, correction, deletion, objection, or consent-withdrawal requests to the business identified on your pass because it controls the program. If you contact taplyy, we may forward the request to that business and assist it without independently changing records we are required to process on its instructions.

tptaplyy

Start with taplyy

Launch passes, manage programs, and see what performs.

Built for businesses that need a cleaner way to create wallet passes, manage campaigns, and measure engagement over time.

support@taplyy.com

taplyy

HomePricing

Features

Create passesRun campaignsTrack analyticsSupport both walletsOperate programs

Business Type

All industriesRetail and store groupsRestaurants and hospitalityEvents and venuesGyms and membershipsClubs and associationsChains and franchises

Company

AboutContact us

Legal

Terms of ServiceAcceptable UsePrivacy NoticePassholder PrivacyData Processing AddendumCookie NoticeSubprocessors

© 2026 taplyy. Apple Wallet and Google Wallet pass operations for modern teams.