Tapcoat logo

Privacy policy

This is a convenience translation. Only the German version is legally binding.

Last updated: June 2026 | Version: 1.0
Controller: Tapcoat GmbH, Hanauer Landstraße 204, 60314 Frankfurt am Main

Scope: This privacy policy applies jointly to: (1) the website tapcoat.com, (2) the Tapcoat SaaS dashboard, and (3) the Tapcoat app (iOS and Android). It is addressed to website visitors, registered clients, and prospective customers — not to end customers and guests whose data Tapcoat processes on behalf of clients (see Section 11).

1. Controller

The controller within the meaning of the GDPR is:

Tapcoat GmbH
Hanauer Landstraße 204, 60314 Frankfurt am Main
Legal representatives: Tim Hoh, Lutz Bischoff (Managing Directors)
Register court: Amtsgericht (Local Court) Offenbach am Main, HRB 141281
Data protection email: datenschutz@tapcoat.com
General contact: hello@tapcoat.com

Tapcoat has not appointed a data protection officer; there is currently no legal obligation to appoint one under Art. 37 GDPR. For data protection inquiries, please contact datenschutz@tapcoat.com directly.

2. What data we process and why — overview

We process personal data only where there is a legal basis under Art. 6 GDPR:

  • Art. 6(1)(a) — Consent: e.g., tracking cookies, Hotjar, newsletter (unless it constitutes advertising to existing customers)
  • Art. 6(1)(b) — Performance of a contract / pre-contractual steps: e.g., registration, account management, invoicing
  • Art. 6(1)(c) — Legal obligation: e.g., retention obligations under the HGB/AO
  • Art. 6(1)(f) — Legitimate interest: e.g., server logs, fraud prevention, service communication, HubSpot CRM

3. Website visitors (tapcoat.com)

3.1 Server logs and Cloudflare connection data

When you access tapcoat.com, the following data is automatically collected and stored in server logs:

  • IP address (anonymized after no more than 7 days)
  • Date and time of access
  • URL accessed
  • Volume of data transferred
  • Browser type and operating system (user agent)
  • HTTP status code

Legal basis: Art. 6(1)(f) GDPR (operation and security of the website).
Service providers: Mittwald CM Service GmbH & Co. KG (hosting, Espelkamp) and Cloudflare, Inc. (CDN/DDoS protection, Frankfurt PoP). DPAs concluded with both.
Retention period: 30 days, followed by automatic deletion.

3.2 Contact via HubSpot form or email

If you contact us via the contact form on tapcoat.com (provided by HubSpot Ireland Limited) or by email to hello@tapcoat.com, we process:

  • Name
  • Email address
  • Company (if provided)
  • Content of your inquiry
  • Time of contact

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in handling inquiries).
Service provider: HubSpot Ireland Limited, 1 Sir John Rogerson’s Quay, Dublin 2, Ireland (DPA under Art. 28 GDPR, third-country transfer based on SCCs + EU-US Data Privacy Framework).
Retention period: Inquiry data is stored for as long as it takes to handle the inquiry and for 3 years thereafter (limitation periods under the BGB). Data that gives rise to a client relationship is covered in Section 6.

3.3 HubSpot Chat

We operate a live chat via HubSpot on tapcoat.com. If you open or use the chat, cookies and connection data (IP address, chat content, timestamps) are transmitted to HubSpot.

Legal basis: Art. 6(1)(a) GDPR (consent via the cookie banner for tracking functions); Art. 6(1)(f) GDPR for the pure communication function.
Service provider: HubSpot Ireland Limited (as above). Chat histories may be stored in the HubSpot CRM.
Objection: You can close the chat at any time without using it. Consent can be withdrawn at any time at tapcoat.com/datenschutz.

4. Cookies and similar technologies — TDDDG and GDPR

Under § 25 TDDDG (German Telecommunications Digital Services Data Protection Act), setting cookies or reading information from end devices is only permitted with express consent, unless the cookies are strictly necessary for technical reasons. We set cookies that are not technically necessary (e.g., analytics, marketing, chat) exclusively after your active consent via our cookie banner.

4.1 Technically necessary cookies

We set the following cookies without consent, as they are strictly necessary for the operation of the website:

  • Session cookie (login status in the dashboard, valid for the duration of the session)
  • CSRF protection token (security against cross-site request forgery)
  • Cookie consent decision (stores your consent or refusal)

Legal basis: § 25(2) No. 2 TDDDG, Art. 6(1)(f) GDPR.

4.2 Analytics and marketing cookies (only with consent)

The following cookies and tracking technologies are only activated if you have consented in the cookie banner. You can withdraw your consent at any time with effect for the future (Section 15.1).

5. Analytics and marketing tools

5.1 Google Analytics 4 (GA4)

We use Google Analytics 4 (GA4) to analyze user behavior on tapcoat.com. GA4 uses cookies and similar technologies to collect pseudonymized user data.

Data processed: pseudonymized device ID, session data, page views, events (e.g., button clicks, form submissions), IP address (truncated on the server side).

Legal basis: Art. 6(1)(a) GDPR (consent), § 25(1) TDDDG.
Joint controllership: Tapcoat and Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) are joint controllers under Art. 26 GDPR. The essential content of the joint controller agreement is available at https://business.safety.google/adscontrollerterms.
Third-country transfer: Google LLC, USA. Safeguards: SCCs under Art. 46 GDPR + EU-US Data Privacy Framework (adequacy decision of July 10, 2023).
Retention period: Raw data 14 months (standard GA4 setting). You can permanently disable collection using Google’s browser add-on: https://tools.google.com/dlpage/gaoptout
Objection: Consent can be withdrawn at any time in the cookie banner.

5.2 Google Ads and conversion tracking

We use Google Ads to place advertisements on Google services, and Google Conversion Tracking to measure the success of our advertising campaigns.

Data processed: cookie ID, click ID (gclid), conversion event (e.g., registration), pseudonymized device information.

Legal basis: Art. 6(1)(a) GDPR (consent), § 25(1) TDDDG.
Joint controllership: Tapcoat and Google Ireland Limited, joint controllers under Art. 26 GDPR. Google’s privacy policy: https://policies.google.com/privacy
Third-country transfer: Google LLC, USA — as above (SCCs + EU-US DPF).
Objection: Consent can be withdrawn at any time in the cookie banner. Alternatively, disable personalized advertising at https://adssettings.google.com/.

5.3 Meta Pixel and Meta Conversions API

We use the Meta Pixel and the Meta Conversions API (CAPI) to measure the effectiveness of our advertisements on Facebook and Instagram and to target them precisely to specific audiences.

Data processed: hashed email address (only for conversions via CAPI), browser cookies (_fbp, _fbc), IP address, behavioral data on tapcoat.com, event data (e.g., page view, registration).

Legal basis: Art. 6(1)(a) GDPR (consent), § 25(1) TDDDG.
Joint controllership: Tapcoat and Meta Platforms Ireland Limited (Merrion Road, Dublin 4, Ireland) are joint controllers under Art. 26 GDPR in accordance with the Meta Controller Addendum (https://www.facebook.com/legal/controller_addendum).
Third-country transfer: Meta Platforms, Inc., USA — SCCs + EU-US Data Privacy Framework.
Objection: Consent can be withdrawn at any time in the cookie banner. You can opt out of personalized Facebook advertising via your Facebook settings.

5.4 LinkedIn Insight Tag

We use the LinkedIn Insight Tag to measure conversions from LinkedIn campaigns and to build audiences for remarketing on LinkedIn.

Data processed: cookie ID (li_fat_id), IP address, device metadata, URLs visited, conversion events.

Legal basis: Art. 6(1)(a) GDPR (consent), § 25(1) TDDDG.
Joint controllership: Tapcoat and LinkedIn Ireland Unlimited Company (Wilton Place, Dublin 2, Ireland) are joint controllers under Art. 26 GDPR in accordance with the LinkedIn joint controller agreement.
Third-country transfer: LinkedIn Corporation, USA — SCCs + EU-US Data Privacy Framework.
Objection: Consent can be withdrawn at any time in the cookie banner. LinkedIn members can disable tracking in their LinkedIn account settings.

5.5 Hotjar (session recording and heatmaps)

Hotjar records anonymized mouse movements, clicks, scroll depth and, in exceptional cases, screen recordings. All password fields and fields containing sensitive data are technically masked and do not reach Hotjar.

We use Hotjar, provided by Hotjar Ltd. (Level 2, St Julian’s Business Centre, 3 Elia Zammit Street, St Julian’s STJ 3155, Malta), to improve the usability of tapcoat.com.

Data processed: anonymized mouse movements, click and scroll behavior, device type, browser type, timestamps, URLs visited. No intended processing of names, email addresses or password fields.

Legal basis: Art. 6(1)(a) GDPR (consent), § 25(1) TDDDG.
Third-country transfer: Data is stored in the EU (Hotjar is a Maltese company). Any sub-processors in third countries are governed by the Hotjar DPA.
Objection: Consent can be withdrawn at any time in the cookie banner. You can also opt out at: https://www.hotjar.com/legal/compliance/opt-out

6. Registration and use of the Tapcoat dashboard

6.1 Registration process (sign-up)

When you register a Tapcoat account, we collect the following data:

  • First name, last name
  • Email address (used as the login ID)
  • Name of the company / venue
  • Function / role in the company
  • Password (stored exclusively as a bcrypt hash — Tapcoat has no access to the plain-text password)
  • IP address and timestamp of registration (security / fraud prevention)

Legal basis: Art. 6(1)(b) GDPR (performance of a contract — provision of the Tapcoat account).
Mandatory information: email, password, company name. All other fields are optional.

6.2 Usage data in the dashboard

While you use the Tapcoat dashboard, technical usage data is collected:

  • Login times and session duration
  • Actions performed (e.g., pass creation, client configuration) — anonymized as an audit log
  • Error messages and performance metrics (via Sentry, anonymized)
  • Server logs of API requests (IP, timestamp, endpoint) — retained for 30 days

Legal basis: Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(f) GDPR (legitimate interest in security and operations).

6.3 Payment processing and invoicing via Frisbii

Tapcoat subscriptions are billed via Frisbii Germany GmbH (Mainzer Landstraße 51, 60329 Frankfurt am Main) acting as processor. Tapcoat itself does not process credit card numbers or complete bank details.

Data processed: name, company name, billing address, payment method (tokenized), contract data, invoice history, KYC identification data (where required by regulatory requirements).

Legal basis: Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(c) GDPR (retention obligations under tax law).
Retention period for invoice data: 10 years (§ 147 AO, § 257 HGB).

6.4 Error monitoring via Sentry

For quality assurance and troubleshooting, we use Sentry (Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, San Francisco, CA 94105, USA; EU representative: Sentry Software Netherlands B.V., Amsterdam).

Data processed: pseudonymous user ID, stack trace (lines of code where the error occurred), device type, browser version, app version, IP address (truncated on the server side — IP masking enabled).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operational stability and troubleshooting).
Third-country transfer: USA, Sentry DPA + SCCs + EU-US Data Privacy Framework.
Retention period: 90 days (Sentry default).

7. Tapcoat app (iOS and Android)

7.1 Push notifications

The Tapcoat app sends push notifications (e.g., pass updates, security notices) via the infrastructure of Apple (APNs) and Google (FCM).

  • Apple APNs: APNs device token, pass type identifier, IP address — processed by Apple Distribution International Limited, Cork, Ireland.
  • Google FCM: FCM registration token, instance ID, IP address — processed by Google Ireland Limited, Dublin.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract — provision of the app features).
Third-country transfer: Apple Inc. and Google LLC, USA — SCCs + EU-US Data Privacy Framework.

7.2 Over-the-air updates via Capawesome

App updates are delivered via Capawesome Cloud (Genz IT Solutions GmbH, Brückengasse 1b, 78462 Konstanz). In the process, the device ID, app version and IP address are transmitted.

Legal basis: Art. 6(1)(b) GDPR (provision of the current app version).
Third-country transfer: None; data stored in Germany/EU.

7.3 Wallet pass creation (Apple Wallet and Google Wallet)

On the instructions of clients, Tapcoat creates digital cloakroom tickets as wallet passes (Apple Wallet via PassKit, Google Wallet via the Google Wallet API). When creating the wallet passes, Tapcoat acts as a processor for the client, not as an independent controller. Providing data protection information to guests is the responsibility of the client.

Legal basis: Art. 6(1)(b) GDPR (performance of the contract with the client).

8. Hosting and infrastructure

All personal data processed within the Tapcoat platform is stored on servers of the following service providers:

  • DigitalOcean, LLC (DPA): backend hosting (compute, database, object storage) together with Hetzner Online GmbH — location: FRA1, Frankfurt am Main / Falkenstein/Nuremberg, Germany
  • Mittwald CM Service GmbH & Co. KG (DPA): hosting of the marketing website tapcoat.com — location: Espelkamp, Germany
  • Cloudflare, Inc. (DPA): DNS, CDN, DDoS protection, WAF — location: Frankfurt PoP (EU routing)

All providers are contractually bound as processors under Art. 28 GDPR. For US providers, safeguards are provided by Standard Contractual Clauses (SCCs, Module 2) and the EU-US Data Privacy Framework.

9. Communication and marketing

9.1 Transactional emails

As part of the contractual relationship, we send you necessary service emails (e.g., account confirmation, invoices, security notices, pass updates). These emails are required for the performance of the contract and cannot be unsubscribed from.

Legal basis: Art. 6(1)(b) GDPR.

9.2 Marketing emails and newsletter

If you are already a client, we may occasionally send you information about new features, improvements or relevant offers from Tapcoat. This is based on § 7(3) UWG (direct marketing to existing customers). You can object to this use at any time.

For prospective customers without an existing contractual relationship, we send marketing emails only on the basis of express consent.

Legal basis: § 7(3) UWG in conjunction with Art. 6(1)(f) GDPR (existing customers) or Art. 6(1)(a) GDPR (consent for prospective customers).
Service provider: ActiveCampaign LLC, 1 N Dearborn Street, 5th Floor, Chicago, IL 60602, USA (DPA + SCCs + EU-US Data Privacy Framework).
Opt-out: Every marketing email contains an unsubscribe link. You can also object at any time by email to datenschutz@tapcoat.com.

9.3 CRM system (HubSpot)

Contact data of prospective customers and clients is stored and managed in HubSpot CRM to enable sales processes and customer communication.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in structured customer management) or Art. 6(1)(b) GDPR (preparation and performance of a contract).
Service provider: HubSpot Ireland Limited, Dublin 2, Ireland (DPA + SCCs + EU-US DPF).
Retention period: term of the contract plus 3 years (limitation periods). Earlier deletion is possible on request.

10. Operations, monitoring and availability

To ensure trouble-free operation, we use the following monitoring services:

  • Better Stack (Better Stack s.r.o., Prague, CZ): log management, uptime monitoring — processes server logs, account IDs, IP addresses, request metadata — legal basis: Art. 6(1)(f) GDPR
  • Oh Dear (Oh Dear BV, Belgium): external availability monitoring — processes endpoint URLs, response times — legal basis: Art. 6(1)(f) GDPR

11. Scope limitation: guest data and clients’ wallet passes

The data of end customers and guests who use wallet passes issued by Tapcoat clients is not processed on the basis of this privacy policy. In this respect, Tapcoat acts exclusively as a processor within the meaning of Art. 28 GDPR. The controller in each case is the venue / event organizer as the client. The data protection information for guests must be provided by the client (e.g., as a notice posted at the cloakroom or in the ticketing process).

Tapcoat provides clients with a template notice for this purpose.

12. Third-country transfers

Some of the service providers we use transfer personal data to the USA. In every case, this is safeguarded by EU Standard Contractual Clauses (SCCs, Implementing Decision (EU) 2021/914, Module 2) and — where applicable — the European Commission’s adequacy decision on the EU-US Data Privacy Framework of July 10, 2023.

  • Google (Analytics, Ads) — USA — SCCs + EU-US DPF
  • Meta Platforms — USA — SCCs + EU-US DPF
  • LinkedIn Corporation — USA — SCCs + EU-US DPF
  • DigitalOcean, LLC — USA (data remains in FRA1) — SCCs + EU-US DPF
  • Cloudflare, Inc. — USA (data in the EU) — SCCs + EU-US DPF
  • Sentry (Functional Software, Inc.) — USA — SCCs + EU-US DPF
  • ActiveCampaign LLC — USA — SCCs + EU-US DPF
  • HubSpot Ireland Limited — Ireland/USA — SCCs + EU-US DPF
  • GitHub, Inc. — USA — SCCs + EU-US DPF
  • Dropbox International — Ireland/USA — SCCs + EU-US DPF

You can check the current certification status of US providers under the EU-US Data Privacy Framework at https://www.dataprivacyframework.gov/s/participant-search.

13. Retention period

We store personal data only for as long as necessary for the respective processing purposes or as required by statutory retention obligations:

  • Server logs (website): 30 days
  • Contact inquiries: duration of handling + 3 years (limitation period under the BGB)
  • Account data of active clients: term of the contract; after termination, retained permanently as a Free account
  • Account data upon deletion request: immediate anonymization + 30-day export period
  • Invoice and payment data: 10 years (§ 147 AO, § 257 HGB)
  • Consent to marketing emails: until withdrawal (consent) or objection (§ 7(3) UWG)
  • Sentry error reports: 90 days
  • HubSpot CRM data: term of the contract + 3 years
  • Google Analytics raw data: 14 months
  • Hotjar recordings: 365 days (Hotjar default)

14. Your rights as a data subject

You have the following rights under the GDPR vis-à-vis Tapcoat as the controller:

  • Right of access (Art. 15 GDPR): You have the right to know what data we have stored about you.
  • Right to rectification (Art. 16 GDPR): You have the right to have inaccurate data corrected.
  • Right to erasure (Art. 17 GDPR): You have the right to request the deletion of your data, provided no retention obligation prevents this.
  • Right to restriction of processing (Art. 18 GDPR): Under certain conditions, you can request that processing be restricted.
  • Right to data portability (Art. 20 GDPR): You have the right to receive your data in a machine-readable format or to have it transferred to another provider.
  • Right to object (Art. 21 GDPR): You have the right to object at any time to processing based on legitimate interests. In the case of direct marketing (§ 7(3) UWG), an objection is effective at any time.
  • Right to withdraw consent (Art. 7(3) GDPR): You can withdraw consent you have given at any time with effect for the future.
  • Right to lodge a complaint (Art. 77 GDPR): You have the right to lodge a complaint with the competent data protection supervisory authority. For Tapcoat GmbH, headquartered in Frankfurt am Main, this is the Hessian Commissioner for Data Protection and Freedom of Information (HBDI), Gustav-Stresemann-Ring 1, 65189 Wiesbaden, https://datenschutz.hessen.de

To exercise your rights, please contact us by email at datenschutz@tapcoat.com or by post at: Tapcoat GmbH, Hanauer Landstraße 204, 60314 Frankfurt am Main. We process requests within one month (Art. 12(3) GDPR). For complex requests, this period may be extended by two further months.

15. Managing and withdrawing consent

15.1 Cookie consent

You can withdraw your consent to cookies and tracking tools at any time with effect for the future. To do so, click the ‘Cookie settings’ link in the footer of tapcoat.com or directly here: [insert link to cookie settings].

The Consent Management Ordinance (Einwilligungsverwaltungsverordnung, EinwV) has applied since April 1, 2025. You can also manage your preferences centrally via a recognized personal information management service (PIMS) under § 26 TDDDG, if you use such a service.

15.2 Marketing emails

Every marketing email contains an unsubscribe link. Alternatively, you can unsubscribe at any time by email to datenschutz@tapcoat.com.

15.3 Account deletion

You can request the complete deletion of your account via the account settings in the Tapcoat dashboard. After the request, you have 30 days to export your data. Personal data is then deleted, unless statutory retention obligations prevent this.

16. Data security

Tapcoat implements technical and organizational measures to protect your data against loss, alteration and unauthorized access. These include, among others:

  • Encryption of all connections with TLS 1.2 or higher (HTTPS enforced, HSTS enabled)
  • Password hashing using a secure method (bcrypt/argon2)
  • Encryption of data stored in the database
  • Access to production data restricted to the necessary minimum (least privilege)
  • Regular backups with encrypted storage
  • Incident response plan for personal data breaches (Art. 33 GDPR)

The complete description of the technical and organizational measures (TOMs) is documented as Annex 1 to the Data Processing Agreement (DPA) and can be viewed by clients on request.

17. Changes to this privacy policy

We reserve the right to update this privacy policy as needed, in particular in the event of changes to our platform, new services being used or changes in the legal situation. We actively communicate material changes by email to registered clients with at least 30 days’ notice.

The date of the last update is noted at the beginning of this document. A change log is available at tapcoat.com/datenschutz-changelog.

Appendix: Processors used (summary)

The complete list of all processors, joint controllers and independent controllers is documented in Annex 2 to the Tapcoat DPA. The most important processors at a glance:

  • DigitalOcean, LLC — backend hosting (FRA1 + Hetzner DE) — USA (data in DE) + Hetzner DE
  • Molchkragen Media GmbH (formwandler) — development, operations, support — Germany
  • Mittwald CM Service GmbH & Co. KG — website hosting — Germany
  • Cloudflare, Inc. — CDN, DDoS protection — USA (data in the EU)
  • Frisbii Germany GmbH — billing, subscription, KYC — Germany
  • Sentry (Functional Software, Inc.) — error monitoring — USA
  • Better Stack s.r.o. — log management, uptime — EU
  • Capawesome / Genz IT Solutions GmbH — OTA app updates — Germany
  • HubSpot Ireland Limited — CRM, contact form, chat — Ireland/USA
  • ActiveCampaign LLC — email marketing — USA
  • Microsoft Ireland Operations Ltd. — email, Teams, OneDrive — Ireland/USA
  • Dropbox International — document storage — Ireland/USA
  • GitHub, Inc. — code repository — USA
  • GitLab Inc. — code repository — USA

Joint controllers (Art. 26 GDPR): Google Ireland Ltd. (Analytics, Ads), Meta Platforms Ireland Ltd. (Pixel, Ads), LinkedIn Ireland Unlimited Company (Insight Tag).

Last updated: May 2026
Tapcoat GmbH | Hanauer Landstraße 204 | 60314 Frankfurt am Main | datenschutz@tapcoat.com