If you contact TapSpace, we receive the information you include, such as your name, email, business name, and request details. We use it to respond, review an inquiry, or support the relevant service. Directory entries and Suites can contain business names, images, descriptions, links, and contact details approved for the relevant public or protected experience.
The directory’s Get Started link opens a Tally-hosted form. The Signal Pilot’s project-inquiry form uses Framer’s form service and anti-abuse checks; it asks for contact and project details. Some business-specific forms follow different routes: the DJ booking form prepares an email for the visitor to review and send using their email app. A direct inquiry to a listed business is handled through that business’s chosen contact service. The precise recipients and downstream integrations vary by form and are not fully verified here.
The identified services include Framer for directory and Suite hosting, asset delivery, event scripts, and native forms; Vercel for inspected TapSpace Core hosting; Supabase for Core database, routing, and operator authentication; Tally for the linked intake form; and Instagram when an embedded post loads. The business you contact also receives your inquiry through its selected channel. This describes identified integrations, not a complete provider or subprocessor register.
Planned business-content uploads are disabled and have not launched for public submissions. They are separate from the live text-only story form. Please do not send passwords, payment details, private NFC programming links, or information about someone else that you are not authorized to share.
Browsing the public directory does not grant protected Save Contact access. Some Suite contact features require authorized tap access and the business’s approved sharing settings. Where Save Contact is available, the visitor chooses whether to use it. A saved contact is then held by the visitor’s device or contact service.
The current Core implementation uses a contact-session cookie with a 15-minute expiry and Secure, HttpOnly, and SameSite=Lax protections. A server record stores a hash of the session token, its associated Space and tap item, authorization information, and creation and expiry times. The 15-minute limit controls access; it does not delete session records, analytics, logs, or contacts saved to a phone. Operator sign-in uses separate authentication cookies.
First-party Core routing records can include timestamped Suite views, matching NFC/QR events, redirects, Space identity, tap or QR item, occupancy association, and source attribution. A matched tap item’s last-seen state may be updated. These records support routing, access checks, and understanding how a Space is reached. A TapCard identifier is not a verified visitor-device fingerprint. Suite-linked or item-linked events are not treated as anonymous simply because a visitor’s name is absent.
Framer-hosted pages load Framer assets and its event script. The exact events and optional fields sent by this site, provider settings, and provider retention have not all been verified. Some Suites can load Instagram embeds, which connect the visitor’s browser to Instagram; this differs from an ordinary social-profile link. Cookies, browser storage, hosting or security logs, and the information handled by an outside service depend on the feature and provider. We do not claim that all TapSpace services are free of cookies or tracking, or that providers never process IP addresses or browser information.
The live story form accepts text feedback. Your story is required; display name, business name, Instagram handle, Instagram post link, and follow-up email are optional. Submissions enter a private owner-review queue and are not posted automatically.
You separately choose permission to share your words on the website and Instagram, to show submitted attribution, and to receive follow-up email about your story. Sharing words without attribution permission allows an anonymous quote. Email is not included with the quote, and the form does not sign you up for marketing. An Instagram link, mention, or hashtag does not grant reuse permission for images, video, or audio.
The existing story-specific policy remains unchanged: unapproved submissions and private follow-up details are deleted after 90 days; approved quotes and consent records are kept while the quotes are used. The owner reviews and carries out removal; deletion is not automatic. Withdrawing permission stops new reuse and prompts review of removal from channels TapSpace controls.
Read the story privacy notice for the full terms and choices. For story permissions or removal, email thesignalpilot@gmail.com.
The following targets are approved for implementation planning. Cleanup has not been verified as implemented across the services, and these targets are not a claim that historical records have already been removed. Records may remain beyond a target while handling and cleanup are reviewed. Removal is owner-reviewed; automated deletion is not being promised.
Unconverted inquiries and check-ins, where collected: removal target 90 days after the last genuine activity.
Contact profiles: kept while active, with a removal target within 30 days of confirmed closure.
Identifiable tap events: retention target 30 days.
Expired session rows: removal target 7 days after expiry. The 15-minute contact-access limit remains unchanged.
Minimal operator audit records and genuinely de-identified totals: retention target 12 months.
Permanent TapCard identities are preserved when a contact closes; the target is to remove closed contact data without destroying the card’s identity. Data still linked to a Suite, card, or identifiable person is not described as anonymous. The separate testimonial rules above continue to apply.
Provider logs, backups, exact service settings, and their deletion schedules remain unverified. These targets do not establish provider or backup retention durations, and removal from an active database does not prove removal from every backup, provider log, or copy saved by a visitor. Contact us about a specific record or request so its handling can be reviewed.
For general support, privacy questions, or a request about your information, email hello@thesignalpilot.com. The Contact page identifies sales, support, and story-specific contacts.
Include the relevant public page or Suite URL and a short description so the owner can review your request. Additional information may be needed to identify the record or confirm that a request concerns your information; do not send unnecessary sensitive details or credentials. We do not promise an unverified automatic deletion mechanism or a universal response deadline. For information held by a listed business, contact that business through its own channels. For a contact saved to your phone, use your device or contact service’s controls.
This version’s effective date is shown above. Updates to this notice will appear on this page with a revised date. Changes to how existing information is used require owner review against the choices and commitments already made to the people who provided it.