Privacy Policy
Last updated: 9 August 2026 · Version 2026-08-09.2 (detailed version)
TapRadar – TOY GmbH
Protecting your personal data is a central concern for TOY GmbH. This privacy policy informs you comprehensively and in detail about which personal data we collect in connection with your use of the TapRadar app and its four functional areas Radar, Stamp, Cards and Home, the TapRadar website, and the TapRadar business-customer dashboard (together "TapRadar" or the "Platform"), for which purposes and on which legal basis we process this data, to whom we disclose data, how long we store it, and what rights you have as a data subject. This policy applies both to end customers using the free TapRadar app and to business customers who have subscribed to one of the paid TapRadar plans Bronze, Gold or Platinum. It is based on Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR") and the relevant Austrian implementing provisions, in particular the Data Protection Act (DSG) and the Telecommunications Act 2021 (TKG 2021).
1. Controller
The controller within the meaning of Art. 4(7) GDPR is:
- TOY GmbH
- Dr. Adolf-Schärf-Straße 1/2/24
- 2353 Guntramsdorf, Austria
- VAT ID: ATU78882167
- Email: support@tapradar.app
- Website: www.tapradar.app
No company data protection officer has been appointed, as the requirements of Art. 37 GDPR are not met. Please direct privacy-related inquiries to the email address above; we process them without undue delay, and no later than one month after receipt.
2. Structure of this policy
To help you navigate quickly, this privacy policy is divided into a general part (items 1 to 4), a specific part describing the four functional areas of the app as well as location and push data in detail (items 5 to 7), a part on business customers, payments and reviews (items 8 to 12), a part on the website, recipients, third-country transfers and retention periods (items 13 to 16), and a part on your rights, data security and other notices (items 17 to 22). A list of official sources can be found at the end of the document.
3. General principles of data processing
We process personal data in accordance with the principles of the GDPR, in particular lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, and integrity and confidentiality (Art. 5 GDPR). Every processing of personal data is based on at least one of the following legal bases:
- Art. 6(1)(a) GDPR – consent of the data subject, in particular for sharing location data, receiving push notifications, and the optional friends and leaderboard feature
- Art. 6(1)(b) GDPR – necessity for the performance of a contract or to take pre-contractual steps, such as providing the Radar, Stamp, Cards and Home app features and managing subscriptions
- Art. 6(1)(c) GDPR – compliance with a legal obligation, such as tax and corporate record-keeping requirements
- Art. 6(1)(f) GDPR – legitimate interests, such as fraud and abuse prevention, IT security, and further development of the platform, provided these are not overridden by the interests or fundamental rights of the data subject
4. Overview: who processes what?
TapRadar connects two user groups: end customers who discover local businesses and collect stamps through the free app, and business customers who manage their customer loyalty through the paid dashboard. Both groups generate data that is processed partly exclusively by TOY GmbH and partly jointly with the respective contractual partner. Items 5 to 12 below describe these data flows in detail, structured by the four app areas as well as by location, push, payment and review data.
5.1 Radar – discover local businesses
In the Radar area, we show you TapRadar partner businesses near you on a map. You can narrow the view using filters (offer, voucher, reward, top-rated, 500-metre radius) and categories such as café, restaurant, hairdresser or market. For each partner business, opening hours, reviews and a plan badge indicating the tariff chosen by that business (Bronze, Gold or Platinum) are shown; this badge relates solely to the business customer and does not constitute personal data about you.
To provide this feature, we process your location (see item 6), the filter and category settings you choose, and your interactions with displayed partner businesses, such as opening a business profile. We use this interaction data to improve search results and increase the relevance of the partner businesses shown. Legal basis: Art. 6(1)(a) GDPR for sharing your location, Art. 6(1)(b) and (f) GDPR for filter, category and interaction data.
5.2 Stamp – collect digital loyalty stamps
In the Stamp area, you can automatically receive a digital stamp by tapping an NFC point or, alternatively, by scanning a QR code at a partner business's till. Your progress, e.g. 7 of 10 stamps, is displayed immediately; once the required number of stamps is reached, you can redeem the stored reward, for example a free coffee or a discount. You also receive points toward your Home level for every stamp.
For this purpose, we process the time and location of each stamp, the partner business concerned, the current stamp count per loyalty card, redeemed rewards and the associated redemption code. Legal basis: Art. 6(1)(b) GDPR. To verify that a stamp was actually collected on site, we additionally match your device location; see item 6 for details.
5.3 Cards – digital wallet for existing loyalty cards
In the Cards area, you can digitally store existing third-party loyalty cards, e.g. from Billa, DM, H&M, Spar or Hofer, in your TapRadar wallet by scanning or manually entering the respective barcode or QR code, and then present it at the till. The brands named are only examples of cards you store yourself; TapRadar is not affiliated with these companies and does not exchange any data with them.
The data stored in the card wallet comes exclusively from you. We do not verify whether the entered cards are genuine, valid, or attributable to the respective third party, and we do not receive any bonus or account data from these companies. You are solely responsible for the accuracy of the stored card data and its acceptance at the respective till.
The card and barcode data you store is encrypted and used exclusively to display it within your own app. Legal basis: Art. 6(1)(b) GDPR, as you specifically instruct us to store the data by adding the card.
5.4 Home – profile and gamification
In the Home area you will find your profile with a 20-tier level system ranging from "Newcomer" to "Champion". You earn points for stamps collected, reviews submitted and friends invited, track a weekly goal, and benefit from a streak system where seven consecutive active days trigger a bonus. You can also invite friends and compare your progress on a leaderboard.
For this purpose, we process your point balance, your level, your streak counter, your goal history, and – if you actively use this feature – the list of friends you have invited or connected with and their aggregated progress data visible to you, provided those persons have also consented to mutual visibility. Legal basis for the core features (level, points, streak, weekly goal): Art. 6(1)(b) GDPR. Legal basis for the optional friends and leaderboard feature: Art. 6(1)(a) GDPR, as this makes data visible to other persons. Levels, points and rankings have no monetary value and are not transferable.
6. Location and GPS data in detail
TapRadar uses your device's location data for two separate purposes: (a) the Radar feature to show partner businesses near you, and (b) verifying customer visits by matching your device's location at the time of an NFC or QR stamp with the stored location of the partner business, to prevent stamping without physical presence.
Depending on your operating system, you can control location sharing granularly, e.g. with options such as "always", "only while using the app", or "once". For the core stamp-verification feature, sharing while using the app is sufficient; permanent background location sharing is only required if you want to use a Platinum partner business's proximity advertising (see item 7.2). Legal basis: Art. 6(1)(a) GDPR in conjunction with your operating system's permission settings, and alternatively our legitimate interest in fraud prevention under Art. 6(1)(f) GDPR. You may revoke location sharing at any time via your device settings; individual features, in particular stamp verification and proximity advertising, will then be unavailable or limited.
7.1 Service notifications from TapRadar
We send service push messages under our own responsibility, e.g. regarding account security, material changes to the platform, or confirmation of transactions. Legal basis: Art. 6(1)(b) and (f) GDPR.
7.2 Marketing and campaign push notifications from business customers
Business customers can send campaigns and push notifications via the dashboard to end customers who are either already customers of the respective partner business (at least one stamp collected) or who are nearby – within the proximity advertising feature available exclusively in the Platinum plan – and have granted location sharing for this purpose. Push notifications are limited to a certain frequency depending on the plan (Gold: up to 2 image/PDF campaigns per month, no push notifications; Platinum: up to 4 campaigns per month plus push notifications, proximity triggering, campaign countdown and retargeting within 30 days of your last visit).
The respective business customer is responsible for the content, lawfulness and fair-trading compliance of a campaign. TOY GmbH provides the technical delivery infrastructure, ensures compliance with frequency limits, and ensures the possibility of opting out at any time. In this respect, TOY GmbH and the respective business customer act as joint controllers within the meaning of Art. 26 GDPR regarding the triggering and delivery of push campaigns; the essence of this allocation of responsibility is summarised in this item, and the substance of the arrangement is made available to data subjects on request to support@tapradar.app.
You can disable the receipt of marketing and campaign push notifications at any time, either completely or per partner business, via your device settings or the in-app settings, without losing access to the app's core features. Legal basis: Art. 6(1)(a) GDPR in conjunction with § 174 TKG 2021.
8. Registration and user account (end customers)
When registering in the TapRadar app, we collect your email address, password (stored encrypted), chosen display name, and optional profile details. Purpose: setting up, managing and securing your user account. Legal basis: Art. 6(1)(b) GDPR.
9. Registration, account and company data (business customers)
For business customers subscribing to a Bronze, Gold or Platinum plan, we additionally process: company name, legal form, business address, VAT ID, contact person (name, email, phone number), opening hours, category and description of the business, as well as uploaded image and PDF advertising material and campaign content. Purpose: contract performance, provision of the business dashboard, invoicing. Legal basis: Art. 6(1)(b) and (c) GDPR.
10. Employee PIN system
Depending on their plan, business customers can set up up to 15 (Platinum), 5 (Gold) or 1 (Bronze) employee accounts with an individual PIN code. For this purpose, we process employee initials or names entered by the business customer, as well as an automated activity log of the stamps and redemptions carried out via the respective PIN. The respective business customer, as employer, is responsible for the lawfulness of this processing towards the employees concerned; TOY GmbH provides the technical infrastructure in this respect. Legal basis on the part of TOY GmbH: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.
11. Payment processing
Payment processing for paid plans is carried out via our payment service provider, Stripe. We ourselves do not store complete payment card data; this is processed exclusively by Stripe. We receive confirmations of payment status and invoice amounts from Stripe, as well as, where applicable, the last four digits of the payment method used, for documentation and billing purposes. Legal basis: Art. 6(1)(b) and (c) GDPR. For further information on data processing by Stripe, please refer to Stripe's privacy policy at stripe.com/privacy.
12. Reviews
When you, as an end customer, submit a review of a partner business, we process the review text, the star rating, the time, and proof of a verified visit (stamp proof). Reviews are shown to the partner business and to other app users together with your display name. Legal basis: Art. 6(1)(a) GDPR in conjunction with Art. 6(1)(f) GDPR. If a review is reported as unlawful, e.g. because it is insulting or evidently not based on an actual visit, we examine the report and the review concerned as part of our reporting and review procedure and inform both the reporting person and the reviewer of the outcome.
13. Use of the website, server log files and cookies
When you access our website www.tapradar.app, our hosting provider automatically processes technical access data (IP address, date and time of access, page accessed, browser and operating system used, referrer URL) in server log files. Purpose: ensuring smooth operation and IT security. Legal basis: Art. 6(1)(f) GDPR. The website uses only technically necessary cookies required for the site to function; we currently do not use tracking or marketing cookies. Should this change in future, we will ask for your consent via a cookie consent banner.
14. Recipients and processors
We only disclose personal data to the extent necessary to provide our services or where we are legally obliged to do so. Our processors and recipients include in particular:
- Hosting and infrastructure providers (server and database operation)
- Stripe (payment processing)
- Push notification service providers (e.g. Apple Push Notification Service, Firebase Cloud Messaging) for service and campaign push
- Email delivery service providers (transactional and service communication)
- IT service providers for maintenance and support
We have entered into data processing agreements pursuant to Art. 28 GDPR with all processors, where legally required. Where a partner business (business customer) views your stamp, visit or campaign data in the dashboard as part of contract performance, it acts in this respect as an independent controller or, in the case of push campaigns, as a joint controller pursuant to item 7.2 of this policy.
15. Transfers to third countries
To the extent that any of the service providers named above process data outside the European Economic Area (EEA), which may in particular concern certain cloud and push services of US providers, we ensure through appropriate safeguards that an adequate level of data protection is maintained, in particular through the conclusion of EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR or the recipient's certification under the EU-U.S. Data Privacy Framework, where applicable.
16. Retention periods
We store personal data only for as long as necessary for the respective purposes:
- Account data (end customers and business customers): for the duration of the user account or contractual relationship; after account deletion, data is generally deleted within 30 days, unless statutory retention obligations prevent this
- Stamp, reward and redemption data: for the duration of the account with the respective partner business; after termination of the business customer contract, related loyalty cards are marked inactive and deleted after 12 months
- Card wallet data (item 5.3): until independently deleted by you or until your account is deleted
- Gamification data (level, points, streak, weekly goal): for the duration of your account
- Friend connections and leaderboard: until removed by you or until your account is deleted
- Invoice and payment data: 7 years pursuant to § 132 BAO and § 212 UGB
- Push delivery and interaction logs: 12 months
- Server log files: generally 30 to 90 days
- Location data for stamp verification: no permanent storage; processed only for the duration of verification, then reduced to an event log (time, result)
- Support communications: 3 years from closure of the case, unless a longer retention period is legally required
17. Your rights as a data subject
Subject to the statutory requirements, you have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
- Right to withdraw consent given, with effect for the future (Art. 7(3) GDPR)
To exercise these rights, an informal message to support@tapradar.app is sufficient. We will process your request without undue delay, and no later than within one month; this period may be extended by a further two months for complex or numerous requests, of which we will inform you.
18. Data security
We employ appropriate technical and organisational measures pursuant to Art. 32 GDPR to protect your data against loss, misuse and unauthorised access, including encryption of data in transit (TLS), encryption of particularly sensitive stored data such as passwords and card wallet data, access restrictions based on the principle of least privilege, regular security updates, and logging of security-relevant events. Our security measures are continuously adapted to the state of the art.
19. No automated decision-making, limited profiling
Levels, points and leaderboards within the app are based on automated, but fully transparent and comprehensible rules, without any legal or similarly significant effect within the meaning of Art. 22 GDPR. Within the proximity advertising feature (item 7.2), limited, location-based profiling takes place to show you notifications from nearby partner businesses; this processing is based exclusively on your consent and has no legal or similarly significant effect within the meaning of Art. 22 GDPR. No automated decision-making with legal effect on users takes place.
20. Protection of minors
TapRadar is not specifically directed at children under 14 years of age. Should we become aware that personal data of a child under the minimum age applicable under national law has been collected without the consent of a legal guardian, we will delete such data without undue delay.
21. Changes to this privacy policy
We reserve the right to amend this privacy policy in order to adapt it to changed legal requirements or new platform features. The version published at www.tapradar.app/datenschutz at the time of your visit or use applies. In the case of material changes based on a changed legal basis, such as an initial consent, we will obtain that consent again.
22. Contact and right to lodge a complaint
For privacy-related questions, you can reach us at support@tapradar.app. Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular the authority responsible for Austria:
- Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
- Barichgasse 40-42, 1030 Vienna, Austria
- Website: www.dsb.gv.at
The Austrian Data Protection Authority's website is currently available in German, with information also available in English. If neither German nor English is your preferred language, you can always contact us informally at support@tapradar.app; we will assist you, in the languages available on this website, in reaching the supervisory authority.
Sources
Official EU and Austrian sources underlying this privacy policy:
- General Data Protection Regulation (GDPR), Regulation (EU) 2016/679: https://eur-lex.europa.eu/eli/reg/2016/679/oj
- Austrian Data Protection Authority: https://www.dsb.gv.at/