1. The one thing to understand first
A published card is public. No login, no barrier — anyone with the link or your tag can open it, and search engines may index it. That is the point of a business card. Everything in this policy follows from that, so publish only what you would hand to a stranger.
2. What we collect
What you give us
- Your email address and password, to sign in. Your account is also given an internal identifier that links your cards, workspace and orders to you.
- What you put on your card: name, job title, organisation, bio, phone numbers, email addresses, website, social links, a photo, and optionally an address.
- For businesses: the organisation name, ABN, logo, website, phone and address, and the details of people invited to the team.
What is collected automatically
- Card opens. We count how often a card is opened so you can see it is being used. We do not record who opened it, we do not build a profile of visitors, and there is no advertising or cross-site tracking on any card.
- Wallet passes. If you add your card to Apple Wallet, your device registers with us so the pass can be kept up to date. That registration gives us a device identifier and a notification token, which we store against your pass. It identifies a device, not you personally, and we use it only to update the pass — never for advertising, tracking or profiling.
- Ordinary server logs and security records, kept briefly to keep the service running and to investigate abuse.
What we never collect
Card numbers. Payments go directly to Stripe; we receive only the result and the last four digits Stripe shows us.
3. Public page versus saved contact
These are deliberately different, and the difference is the privacy design.
- The card page shows your name, title, organisation, city only, bio and links. It never shows your street address, and it never prints your phone number or email as text.
- The contact file— created only when a visitor chooses “Add to Contacts” — carries your phone numbers, email addresses and, only if you have switched it on, your street address. Street sharing is off by default.
Nothing is added to anyone’s address book automatically. Their phone asks them, every time.
4. Who else handles your information
We use a small number of providers, each for one job, and none of them receive your data to use for their own purposes:
- Supabase — the database and accounts. Hosted in Sydney, Australia.
- Vercel — hosting for the website.
- Stripe — payments and subscriptions.
- Brevo — the emails we send you, such as invitations.
- Google Places — address suggestions while you type, if you use that field. Only what you type into that box is sent.
- Apple and Google Wallet — only if you add a card to your wallet.
Some of these operate overseas, so your information may be stored or processed outside Australia. We choose providers that commit to appropriate protections.
We never sell personal information, and we do not share it for anyone else’s advertising.
5. The card page itself makes no third-party requests
Fonts, icons and brand logos are served from our own domain rather than pulled from other companies’ networks. When someone opens your card, no advertising or analytics company learns about it.
Nothing we collect is used for advertising, cross-app tracking or sale, and none of it is shared with a data broker.
6. Where your information lives
The database is hosted in Sydney. Access is restricted at the database level, so one account cannot read another’s data even if the application misbehaves. Connections are encrypted.
7. How long we keep it
- Your account and cards: while your account is open.
- A deleted card: the card is retired and stops resolving immediately. We keep the record, and the retired link stays reserved permanently, so it can never point at somebody else later.
- An unpaid or lapsed subscription: nothing is deleted. Your cards, your photo and everything on them are kept while your account is open — a lapse changes only what a card displays, not what we store — so subscribing again restores them exactly.
- Order and payment records: as long as Australian tax law requires.
8. Your choices and your rights
- See and correct. Everything on your card is editable in your dashboard.
- Delete a card. One action; the link stops working at once.
- Control your address. Street sharing is off unless you turn it on.
- Close your account. One action in your account settings, on the web or in the app. It removes your workspace and your cards, and retires their links permanently, so they can never point at somebody else. We keep only what the law requires us to keep.
- Complain. Write to us first. If we do not resolve it, you can contact the Office of the Australian Information Commissioner.
Reach us at mehdi@topdev.com.au. We aim to respond within 30 days.
TopDev Australia is a trading name of HomeSwim Australia Pty Ltd (ABN 66 640 753 877), and it is the entity accountable for the information described here.
9. If you were given a card by your employer
The business controls that card and can see it, change what you may edit, and remove it. Your EcoTap account stays yours, and a personal card you create is yours alone.
10. Children
EcoTap is for working adults and is not directed at children. We do not knowingly collect information from anyone under 16.
11. Changes
As the product grows this policy will be updated. Material changes will be notified by email or in the dashboard, and the date at the top says when this version was published.