Back to Taptile

Privacy Policy

Effective date: 30 April 2026

1. Who we are

Taptile (“we”, “us”, “our”) is a software platform operated by Dynatex SaaS Co., Th, a company registered in Thailand. We provide a branded mobile and web portal service primarily used by schools and member-based organisations.

If you have questions about this policy or your personal data, contact us at phil@dynatexsaas.com.

2. What this policy covers

This policy applies to information we collect when you:

  • Visit taptile.app or any tenant portal we host (web)
  • Install and use the Taptile native iOS app
  • Sign up for an admin account or organisation tenancy
  • Receive push notifications, emails, or other communications from Taptile

Each organisation using Taptile (a “Tenant”, e.g. your school) is the data controller for their members' personal data. Taptile acts as a data processor on the Tenant’s behalf.

3. Information we collect

A. Information you give us

  • Account details: name, email, password (hashed), role, organisation
  • Profile information you choose to add (phone, image)
  • Contact details synced from your school management system (NexusCMS, Wonde, etc.) where the school admin has authorised this
  • Content you create or upload as an admin (tiles, articles, images, notifications)

B. Information collected automatically

  • Device push notification token (iOS / web push)
  • Basic analytics: pages viewed, tiles tapped, notifications opened (no third-party trackers)
  • IP address and browser type, used solely for security and abuse prevention
  • Crash and diagnostic logs from the iOS app (via Expo)

C. Information we do NOT collect

  • We do not access your camera, microphone, location, contacts, photos, or files unless you explicitly upload them.
  • We do not use third-party advertising trackers, Facebook Pixel, Google Ads, or similar.
  • We do not sell or rent your personal data to anyone, ever.

4. How we use your information

  • To provide the Taptile service to your organisation
  • To authenticate you and protect your account
  • To deliver push notifications, emails, and content sent by your organisation’s admins
  • To improve product quality (aggregated, non-identifying)
  • To comply with legal obligations (e.g. responding to lawful requests)

5. Lawful basis (UK / EU GDPR & Thailand PDPA)

We rely on the following lawful bases for processing:

  • Contract — to deliver the service you (or your organisation) signed up for
  • Legitimate interests — for security, fraud prevention, and product improvement
  • Consent — for push notifications (you can revoke any time in your device settings)
  • Legal obligation — when required by law

We comply with the UK and EU General Data Protection Regulation (GDPR) for users in the UK and EEA, and Thailand’s Personal Data Protection Act (PDPA) as the operating jurisdiction of Dynatex SaaS Co., Th.

6. Sharing your information

We share data only with the following categories of recipients:

  • Your organisation’s admins — they can see contacts, push tokens, and notification analytics for their tenant
  • Sub-processors we use to run the service — listed in Section 8
  • Legal authorities — only when compelled by lawful process

We never sell your data. We never use it to train machine-learning models.

7. Children

Taptile is intended for use by individuals aged 13 and over. Children under 13 should not create an account. Where Taptile is used in a school context, students under 13 may be enrolled by their school’s administrator under the school’s own data-protection arrangements; Taptile processes that data strictly on the school’s behalf.

8. Sub-processors

We use trusted third-party services to operate Taptile:

  • MongoDB Atlas — primary database (EU region)
  • DigitalOcean — image storage (Frankfurt region)
  • SendGrid (Twilio) — transactional email
  • Expo — iOS push notification delivery and build infrastructure
  • Apple Push Notification Service (APNs) — iOS push delivery
  • Stripe — payment processing (for paid tenant subscriptions)
  • Google — SSO authentication (only if you choose “Continue with Google”)

9. International transfers

Your data is stored primarily in the EU. Some sub-processors (e.g. Apple, Expo, Stripe) may transfer data to the United States under appropriate safeguards including Standard Contractual Clauses and the EU-US Data Privacy Framework where applicable.

10. Data retention

  • Account data: kept while your account is active. Deleted within 30 days of account closure.
  • Notification history: kept for 12 months, then deleted.
  • Backups: kept for 30 days then permanently deleted.
  • Audit logs: kept for 24 months for security and compliance purposes.

11. Your rights

Under UK/EU GDPR and Thailand’s PDPA you have the right to:

  • Access the personal data we hold about you
  • Have inaccurate data corrected
  • Have your data erased (subject to legal retention requirements)
  • Restrict or object to processing
  • Receive your data in a portable format
  • Withdraw consent at any time
  • Lodge a complaint with your local data protection authority — for example the UK Information Commissioner’s Office (ICO) for UK residents, your national supervisory authority for EU residents, or Thailand’s Personal Data Protection Committee (PDPC)

To exercise these rights, contact phil@dynatexsaas.com or, where Taptile processes data on behalf of your school, contact your school's data protection officer first.

12. Security

We use industry-standard measures to protect your data, including:

  • HTTPS encryption for all data in transit
  • Encrypted password storage (bcrypt)
  • Per-tenant data isolation
  • API keys hashed and individually scoped
  • Regular security reviews

13. Changes to this policy

We may update this policy from time to time. Material changes will be announced via in-app notice or email. The effective date at the top of this page indicates the most recent update.

14. Contact us

Questions, requests, or concerns: phil@dynatexsaas.com

Dynatex SaaS Co., Th
Registered in Thailand