ReceipTap

ReceipTap Data Processing Agreement

Version 2026-08-18.1 · last updated 2026-08-18

This Data Processing Agreement ("DPA") is between J.A.C. GLOBAL APPROACH LTD. () and the business using ReceipTap ("you," "the business"). It's incorporated by reference into our Terms of Service — by accepting the Terms, you're also agreeing to this DPA, even though it's published at its own page and versioned on its own schedule. It governs how we handle personal data belonging to your customers — the shoppers who tap a puck and save a receipt — not your own account data, which our Privacy Policy already covers.

Jump to
Roles: who's the controller, who's the processor What this covers Processing only on your instructions Security measures Subprocessors Where the data goes Helping with your customers' requests If something goes wrong Deleting or returning data Demonstrating compliance Liability Changes to this DPA Governing law

Roles: who's the controller, who's the processor

When one of your customers taps a puck and chooses to save their receipt — entering an email, or signing in with Google — personal data about them gets collected and stored. For that data, you're the controller: you decide why it's being collected (to give your customer their receipt, to build a relationship with them, to send them offers if they've agreed) and what happens with it once you have it. We're the processor: we hold and handle that data as your service provider, on your instructions, not on our own judgment about what to do with it.

↑ Back to top


What this covers

Categories of data subjects

The customers who tap a ReceipTap puck at your register and choose to save a receipt.

Categories of personal data

Nature and purpose of processing

Storing and displaying receipts back to the customer in their ReceipTap wallet, generating AI category and tax-deductibility suggestions for their own purchases, and passing their email and consent choice to you so you can run your own review requests, loyalty offers, and marketing — as described in our Privacy Policy.

Duration

For as long as your ReceipTap subscription is active, and afterward only for the retention periods described below.

↑ Back to top


Processing only on your instructions

We process your customers' personal data only to provide the ReceipTap service to you, as described in our Terms of Service and Privacy Policy — that's the documented instruction this DPA is itself the record of. We don't sell it, and we don't use it for our own marketing or for any other business's benefit. If we're ever required by law to disclose it, we'll tell you first unless the law prohibits that.

Anyone on our side with access to this data — our own staff and the subprocessors listed below — is bound by confidentiality obligations that cover it.

↑ Back to top


Security measures

Passwords are never stored in plain text — they're one-way hashed before being saved. Payment card details never reach our own servers; they're held entirely by Stripe. Access to your dashboard and your customers' data requires an authenticated login session, and our production traffic runs over HTTPS.

↑ Back to top


Subprocessors

We use the following subprocessors, each bound by their own confidentiality and data-protection obligations to us:

If we add, replace, or drop a subprocessor, we'll update this list and this page's version number — and, the next time you visit your dashboard afterward, you'll be asked to review and accept the new version before continuing, the same way any other change to this DPA works. You're not required to take any action for this to happen; it isn't something we do by hand.

↑ Back to top


Where the data goes

Your customers' data is stored in Canada. A few subprocessors above briefly touch part of it outside Canada in the course of providing their service to us: Google, to confirm a sign-in; Anthropic, for category suggestions (business name and item list only, as noted above); and Resend, only if a password reset is requested.

↑ Back to top


Helping with your customers' requests

If one of your customers asks you to access, correct, or delete their data, you can look them up and delete their data with your business directly from your dashboard — no need to come to us first. If you need help with a request our tools don't cover, contact us at privacy@receiptap.com.

↑ Back to top


If something goes wrong

If a security incident happens that puts your customers' personal data at risk, we'll notify you without undue delay after becoming aware of it, so you can meet your own legal obligations as the controller.

↑ Back to top


Deleting or returning data

Our policy is to delete a customer's saved receipts and account 84 months after they're created, and to remove or de-identify your own business data 90 days after you close your ReceipTap account.

↑ Back to top


Demonstrating compliance

↑ Back to top


Liability

↑ Back to top


Changes to this DPA

When we make a real change to this DPA — most commonly adding, replacing, or dropping a subprocessor — we publish the new version here and update the "last updated" date at the top. The next time you visit your dashboard after a real change, you'll be asked to review and accept the new version before continuing.

↑ Back to top


Governing law

This DPA is governed by the laws of Ontario, Canada, same as our Terms of Service.

Contact us

Privacy Officer
J.A.C. GLOBAL APPROACH LTD.
privacy@receiptap.com