Contents
- Who is responsible for your data
- What the app collects
- Why we use it, and on what legal basis
- Who your data is shared with
- Where your data is stored
- Customer data you enter: your responsibilities
- How long we keep it
- Deleting your account
- Your rights
- Children
- Security
- Languages
- Changes to this policy
- Contact
- Appendix: what still has to be filled in or confirmed
TapTap Pub Privacy Policy
Draft, not legal advice. This is a drafted starting point written from the app's actual code and database schema. It has not been reviewed by a lawyer. Do not publish it as the live policy until a qualified lawyer, able to advise on Benin's digital code and on the GDPR if it applies, has read it. Items marked TO CONFIRM are genuinely unresolved and name who has to resolve them.
Draft prepared: 1 October 2026
Effective date: 15 October 2026
Applies to: the TapTap Pub mobile app for Android and iOS, and the backend services behind it.
Translation note: this document is English only. A French version is required before launch in Benin and is handled by the localisation workstream, not here. Where the two versions differ, decide and state which one governs. See "Languages" below.
1. Who is responsible for your data
TapTap Pub is published by Mocktar Technologies LLC, 4736 Black Forest Dr, Greensboro, NC 27405, United States, referred to below as "we" or "TapTap Pub".
Contact for anything in this policy, including privacy requests: support@mocktar.com
There are two different roles in this app, and the difference matters:
| Data | Who decides what happens to it | Who we are |
|---|---|---|
| Your merchant account, your store, your catalog | We do, together with you | Controller |
| The customer names and phone numbers you type into orders | You do | Processor acting for you |
In plain terms: the account you sign up with is ours to look after. The details of your customers that you record in an order belong to your business. You decide why you hold them and for how long. We only store them and serve them back to you. Section 6 explains what that means for your obligations.
2. What the app collects
Everything in this section was checked against the database migrations in supabase/migrations/ and the app source in src/. Nothing here is a generic placeholder.
2.1 Your merchant account
- Email address. Used to identify you and to sign you in.
- Password. Handled by Supabase Auth. It is stored as a cryptographic hash. Neither we nor the app ever see or store your password in readable form.
- Account identifier, sign-in and session timestamps. Created by Supabase Auth so your session can be refreshed without asking you to sign in again.
2.2 Your store
- Store name.
- WhatsApp number, stored as digits only (between 6 and 15 of them, no plus sign and no spaces).
- Currency code, such as
XOF. - Created and last-updated timestamps.
2.3 Your catalog
For each product: title, description, selling price, cost price, stock on hand, low-stock alert level, a link to the product photo, and whether the product has been archived. Cost price is the number your profit figures are calculated from; it is business-sensitive, and it is never put into a status card or a WhatsApp caption.
2.4 Product photos: stored in a public bucket
Please read this one carefully.
Product photos you upload are stored in a Supabase Storage bucket configured as public. That means:
- Anyone who has or guesses a photo's URL can open it, with no sign-in and no token. They do not need a TapTap Pub account.
- The URL is not listed anywhere public by us and the bucket cannot be browsed, but the photo itself is not protected by a password.
- Only you (and, if your store has staff, your store's members) can upload, replace or delete photos in your store's folder. Reading is open to anyone with the link.
This is a deliberate design choice, not an oversight: a WhatsApp status card has to be fetchable by WhatsApp and by the people who see it, and a private URL would break that. The consequence is real and you should know about it: do not upload a photo containing anything you would not want a stranger to see, no identity documents, no handwritten customer lists, no screenshots of private chats, and no photos of people who have not agreed to it.
Photos are limited to 5 MB and to JPEG, PNG or WebP. They are stored under a path that begins with your store's identifier.
A photo does not outlive the product it belongs to. Because the bucket is public, a file left behind would stay fetchable by its URL indefinitely, so the app deletes one as soon as nothing points at it:
- replacing a product's photo deletes the photo it replaced
- clearing a product's photo and saving deletes the file
- removing a product deletes its photo, even though the product record itself is kept so that past orders still read properly
- deleting your account deletes every photo in your store's folder (section 8)
The file is always deleted after the product has stopped pointing at it, never before, so you never see a broken picture.
One case is not immediate, and we would rather say so than imply otherwise. A photo is uploaded the moment you pick it, before you save the product, so a picture you pick and then abandon is left in the bucket with nothing pointing at it. The same happens if your phone loses its connection in the middle of a deletion. Files in that state are removed by a periodic sweep of the bucket rather than straight away, and you can ask us to delete a specific photo at any time.
2.5 Orders, and the customer details in them
For each order you record: customer name (optional), customer phone number (optional, stored as digits only), a free-text note, the total amount, and the order's status. For each line of the order: the product title, the quantity, the unit selling price and the unit cost, all snapshotted at the moment of sale so that later price edits do not rewrite your history.
The customer name, phone number and note are personal data about someone who is not a TapTap Pub user. You chose to record it. See section 6.
A counter sale with no name and no phone number is perfectly valid: both fields are optional, and leaving them empty is the privacy-friendly default.
2.6 Stock movement history
Every stock change is written to an append-only history: which product, how many units, why (order reserved, order released, manual adjustment, restock) and the resulting balance. This is your audit trail. It is readable by your store's members and it is not editable or deletable from the app. See section 7 on retention.
2.7 Store members, if your store has staff
If your store has more than one user, we store the pairing of each user's account identifier with your store, and their role (owner or staff). We collect no additional profile information about staff, only the account they already have.
2.8 On your device
- A local cache (MMKV) of your store, your catalog and your orders, so the app opens with your data already on screen instead of a spinner, and keeps working when the network does not. Sales and profit figures are deliberately not cached.
- Your sign-in session token, so you are not asked to sign in on every launch.
This cache lives inside the app's private storage area, which the operating system keeps separate from other apps. It is not separately encrypted with its own key, so it relies on your device's own protection. If your phone is unlocked and in someone else's hands, they can see what the app shows. Lock your phone, and sign out before handing the device to someone else. Signing out clears the cached catalog and orders and ends the session.
2.9 Device permissions the app asks for
- Camera: only to photograph a product for your catalog.
- Photo library (read): only to let you pick an existing product photo.
- Photo library (add): only to save a generated status card to your gallery when you ask for it.
We do not read your gallery in the background, and we do not upload any photo you have not chosen for a product.
Note for the publisher, not for merchants: the Android permission list in app.json currently also requests READ_MEDIA_VIDEO and READ_MEDIA_AUDIO, which the app does not use. That is a code change, not a policy change, and it is flagged in docs/launch-checklist.md. This policy describes only the three purposes above, because they are the only ones the app actually exercises.
2.10 What the app does not collect
Checked against the full dependency list in package.json:
- No analytics or product-tracking SDK.
- No advertising, no advertising identifier, no ad network.
- No crash or performance reporting service.
- No location data. The app never asks for location.
- No access to your contacts, call log, SMS, microphone or calendar. The microphone permission is explicitly blocked in the app's configuration.
- No device fingerprinting, and no attempt to identify you across apps.
2.11 Over-the-air updates
The app can receive JavaScript-only updates from Expo's update service, so a fix can reach you without a new Play Store download. To check for an update the app contacts Expo's servers, and that request necessarily carries technical details such as the platform and the app version.
TO CONFIRM: whether that request also carries a per-installation identifier, and what Expo retains in its logs. This must be confirmed against Expo's own documentation and privacy terms before the Play Data Safety form is submitted, because an installation identifier counts as a "Device or other ID" in Google Play's terms. Who confirms: the repo owner. If the answer is unclear or unwanted, the update feature can be removed.
3. Why we use it, and on what legal basis
| What | Why | Basis |
|---|---|---|
| Email, password, session | To create your account and keep you signed in | Performance of our contract with you |
| Store, catalog, orders, stock history | To provide the service you signed up for: your catalog, your status cards, your sales record | Performance of our contract with you |
| Product photos | To build the status cards you share | Performance of our contract with you |
| Camera and gallery access | To let you add a photo or save a card | Your consent, given at the operating-system prompt and withdrawable in your phone's settings at any time |
| Tenancy and security checks | To keep one merchant's data out of another merchant's hands | Our legitimate interest in a secure service |
| Responding to a lawful request | Where we are legally obliged to | Legal obligation |
We do not use your data for advertising, we do not profile you, and we make no automated decisions about you. We do not sell data to anyone.
Which law applies
- Benin. Personal data is governed by Loi n° 2017-20 du 20 avril 2018 portant code du numérique en République du Bénin, whose Book V covers personal data, with the Autorité de Protection des Données à caractère Personnel (APDP) as the supervisory authority.
- The GDPR (EU Regulation 2016/679) is relevant to the extent that users are in the EU, or that the data is hosted in the EU. We have written this policy to the standard the GDPR expects, because it is the stricter of the two and because of the open hosting question in section 5.
We do not claim to be certified or to have been formally found compliant with either regime. We have described honestly what we do. The following must be settled before launch:
- TO CONFIRM: APDP formalities. Whether this processing must be declared to, or authorised by, the APDP before launch, and who files it. Who confirms: the repo owner, with the APDP directly or a lawyer qualified in Benin.
- TO CONFIRM: GDPR applicability. Whether the app will be offered to users in the EU at launch, and whether an EU representative is needed. Who confirms: the repo owner, with legal advice.
4. Who your data is shared with
We share data only with the service providers the app needs in order to run. Each one processes it on our instructions, not for their own purposes.
| Who | What they get | Why |
|---|---|---|
| Supabase | Everything stored in the backend: account, store, catalog, orders, the customer details you entered, product photos | They host the database, the authentication service and the file storage. They are our hosting provider. |
| Expo / EAS | Technical request details when the app checks for an update; build artefacts | App building and over-the-air updates |
| Google Play | Your download and install record, held by Google under Google's own policy rather than ours | Distribution of the app |
| Your device's operating system | A status card image when you share it, and the caption when it is copied to the clipboard | So the system share sheet can pass it to WhatsApp |
WhatsApp and Meta
The app never sends anything to WhatsApp by itself. When you tap to share, the app hands a status card image and a caption to your phone's share sheet, or opens a wa.me link, and from that point WhatsApp and Meta handle it under their terms and privacy policy, not ours.
What leaves the app at that moment is: the product photo, the product title, the price, the description, your store name, your promo text, and a link that is either your storefront link or a WhatsApp chat link containing your store's own WhatsApp number. Your cost prices, your profit figures and your customers' details are never included in a status card.
We do not pass customer phone numbers to WhatsApp. If you message a customer on WhatsApp, that is you using WhatsApp.
We do not
Sell your data, rent it, trade it, hand it to advertisers or data brokers, or use it to train anything.
5. Where your data is stored
The backend runs on Supabase, in one region chosen when the project was created.
Where your data is stored. The hosted Supabase project runs in the United States, in the us-east-2 region (Ohio). Your shop, your catalog, your orders and your product photos are stored there.
That is outside Benin, so using TapTap Pub involves an international transfer of personal data, including the customer names and phone numbers you type in. It also means the data does not sit in the EU, so the GDPR does not apply to it by virtue of where it is stored. It would still apply if the app were offered to users in the EU, which is the open question in section 5 below.
TO CONFIRM: data processing agreement. Whether a signed data processing agreement (DPA) with Supabase is required, and whether one is in place. Supabase publishes a DPA; whether it has been accepted for this project has not been verified here. The same question applies to Expo. Who confirms: the repo owner, with legal advice on whether it is required under the Benin digital code and under the GDPR if that applies.
6. Customer data you enter: your responsibilities
When you type a customer's name, phone number or a note into an order, you are handling someone else's personal data. For that data:
- You are the controller. You decided to collect it, and you decide why you keep it.
- We are your processor. We store it and show it back to you. We do not use it for anything else, we do not contact your customers, and we do not share it with anyone except the hosting provider named in section 4.
So you are the one responsible for:
- Having a reason you are allowed to rely on. Recording a buyer's name and number in order to fulfil the order they placed is usually defensible. Building a marketing list out of it is a different thing and needs its own basis, usually their consent.
- Being straightforward with your customers. If someone asks why you have their number, tell them. Do not record details a customer has asked you not to keep.
- Collecting only what you need. Both fields are optional. A walk-in sale needs neither.
- Keeping it no longer than you need it. Delete orders you no longer have a reason to keep. The app lets you delete an order.
- Answering your own customers' requests. If a customer asks you for a copy of what you hold, or asks you to delete it, that request is yours to answer. We will help you carry it out (write to the contact address above), but we will not answer it on your behalf without your instruction, because the data is yours to control.
- Not entering special-category data. Do not record health details, religion, political views or anything similar in an order note.
If you are a customer of a merchant and you want your details removed, contact that merchant. They hold your data. If you cannot reach them, write to us at the address above and we will try to put you in touch.
TO CONFIRM: processor terms. A proper controller-to-processor clause, of the kind data protection law requires, is not yet written into the Terms of Service. This section describes the intended split of responsibilities, but it is a description, not a contract. Who confirms and drafts it: the repo owner, with a lawyer.
7. How long we keep it
| Data | Kept |
|---|---|
| Account, store, catalog, orders | For as long as your account exists |
| An order you delete | Deleted from the database, along with its order lines |
| A product you delete | Archived, not erased. It is hidden from your catalog but kept, so that past orders still show a readable product name. Its photo is not kept: see the next row. |
| A product photo | Deleted as soon as nothing points at it. Replacing a photo deletes the one it replaced, removing a photo deletes the file, and removing the product deletes its photo too. A file is only ever deleted once the product has stopped pointing at it, so this is never visible as a broken picture. |
| A photo you picked but never saved | Left in the bucket until a periodic sweep removes it. The file is uploaded as soon as you pick it, so a product form you abandon can leave one behind. Ask us and we will delete it sooner. |
| Stock movement history | Append-only. It is not deletable from the app, because it is the audit trail that makes your stock numbers trustworthy. |
| Local cache on your device | Until you sign out, clear the app's data, or uninstall the app |
| Everything, after account deletion | Removed when the account is deleted. See section 8. Deleting the account cascades to the store, the catalog, the orders, the order lines and the stock history. |
TO CONFIRM: backups. Supabase keeps backups of the hosted database, so a deleted row can persist in a backup for a period set by the project's plan. That window must be read off the Supabase project and stated here. Who confirms: the repo owner.
8. Deleting your account
You can delete your account from inside the app: Store settings, then Delete account. You are shown exactly what will be erased, you type your store name to confirm, and the deletion runs immediately. There is no grace period and no undo.
What is erased depends on your role in the store, because a shop with more than one person in it does not belong only to you:
| Your role | What is deleted |
|---|---|
| The only owner | The store, the whole catalog, every order and order line, the stock history, the memberships, and the product photos in storage. All of it. |
| One of several owners | Only your own access. The store, its catalog and its history stay with the other owners, and the record of who created the store moves to one of them. |
| Staff | Only your own access. Nothing of the shop is yours. |
Your login is deleted in the same operation. In the rare case where the login row cannot be removed, the app says so plainly rather than reporting success: your shop data is gone either way, and you can write to us to have the login removed as well.
If you cannot use the app, for example because you no longer have the phone it was installed on, there is a page on our website that explains how to request deletion by email, and it does not require installing anything. Write from the address your account uses. We will confirm it is you, delete the account, and confirm when it is done. Target: within 30 days of the request.
TO CONFIRM: backups. Deletion removes your data from the live database immediately. Our hosting provider keeps backups, so a copy can survive in a backup for a period we have not yet confirmed and written into section 7. That window is the one honest gap in this section.
9. Your rights
Subject to the law that applies to you, you can ask us to:
- Tell you what we hold about you, and give you a copy.
- Correct anything inaccurate. Most of it you can correct yourself in the app.
- Delete your account and data (section 8).
- Export your data in a portable form.
- Object to, or restrict, processing in the cases the law allows.
- Withdraw consent to camera or gallery access, in your phone's settings, at any time. The app keeps working; you simply cannot take photos inside it.
How to exercise any of these: email support@mocktar.com. We will answer within 30 days. We will not charge you for it, and we will not make the service worse because you asked.
If you are unhappy with how we answer:
- In Benin, you can complain to the Autorité de Protection des Données à caractère Personnel (APDP).
- If the GDPR applies to you, you can complain to your national data protection authority.
Remember: if the data is about you as a merchant's customer, the merchant holds it and your request goes to them first. See section 6.
10. Children
TapTap Pub is a business tool for merchants. It is not designed for, directed at, or marketed to children. You must be old enough to run a business and to enter a contract in your country in order to use it. We do not knowingly collect data from children, and the app has no social features, no chat and no public profile.
Merchants: please do not record children's details in orders.
If you believe a child has created an account, write to us and we will delete it.
11. Security
What is actually in place:
- All traffic between the app and the backend goes over HTTPS.
- Passwords are hashed by Supabase Auth. They are never stored in readable form and never reach our own code.
- Row Level Security is enabled and forced on every table. Every query is filtered to the stores you are a member of, in the database itself rather than in the app, so a bug in the app cannot expose another merchant's data. This is covered by an automated test suite that has been checked to actually fail when the rule is removed.
- Every privileged database function checks your store membership before it does anything.
- Uploads are restricted to your store's own folder, and to images of at most 5 MB.
- The device cache is cleared when you sign out.
What is honestly not in place, and you should know it:
- Product photos are publicly readable by URL (section 2.4).
- The on-device cache is not separately encrypted; it relies on your phone's own protection.
- There is no two-factor authentication yet.
- There is no self-service password reset in the app yet. If you forget your password, write to the contact address.
- No independent security audit has been carried out.
No service can promise perfect security, and we do not.
12. Languages
This policy is published in French and in English. The French version governs. If the two differ, the French text is the one that applies.
The reason is that French is the version a merchant in Benin actually reads. Binding someone to an English text they never read is hard to defend in a francophone jurisdiction, and consumer protection law there tends to agree. The cost of this choice is a maintenance rule, so state it plainly: an edit to the English version has no effect until it is mirrored into French.
Still to confirm with a lawyer qualified in Benin: that this clause is drafted in a form their courts will give effect to. The decision is made; the wording needs review.
13. Changes to this policy
If we change this policy we will update the date at the top and publish the new version at the same address. For a change that materially affects you (a new category of data, a new recipient, a new purpose) we will tell you in the app or by email before it takes effect, and where the law requires your consent we will ask for it rather than assume it.
14. Contact
- Privacy and data requests: support@mocktar.com
- Postal address: 4736 Black Forest Dr, Greensboro, NC 27405, United States
- Published by: Mocktar Technologies LLC
Appendix: what still has to be filled in or confirmed
| # | Item | Who resolves it |
|---|---|---|
| 1 | Publisher legal name, address, privacy contact email, effective date | Repo owner |
| 2 | Supabase hosting region, EU or US (section 5) | Repo owner, from the Supabase dashboard |
| 3 | Whether a DPA with Supabase and Expo is required, and whether one is signed | Repo owner, with legal advice |
| 4 | Whether an APDP declaration or authorisation is needed before launch | Repo owner, with the APDP or a Benin-qualified lawyer |
| 5 | Whether the GDPR applies, and whether an EU representative is needed | Repo owner, with legal advice |
| 6 | What expo-updates transmits and what Expo retains (section 2.11) | Repo owner, from Expo's documentation |
| 7 | Supabase backup retention window (section 7) | Repo owner |
| 8 | In-app and web account deletion routes (section 8), a Play blocker | Repo owner, in code |
| 9 | Controller-to-processor terms for customer data (section 6) | Repo owner, with a lawyer |
| 10 | Which language version governs (section 12) | DECIDED: French governs. Wording still to be reviewed by a lawyer |
| 11 | Full review of this draft by a qualified lawyer | Repo owner |
About this document This page is generated from the source document kept in the project repository at docs/privacy-policy.md. There is no second copy of the text: editing the document changes this page.