Privacy Policy
Effective October 23, 2025 · Last updated October 23, 2025
Effective Date: October 23, 2025
Last Updated: October 23, 2025
INTRODUCTION
Welcome to Tapout Rewards. This Privacy Policy explains how Tapout Rewards, LLC ("Tapout Rewards," "we," "us," or "our") collects, uses, discloses, and protects information about you when you use our mobile application, website, and related services (collectively, the "Services").
We take your privacy seriously, especially when it comes to information about minors. Please read this Privacy Policy carefully to understand our practices regarding your information.
By using the Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, do not use the Services.
Contact Information:
- Email: [insert privacy email]
- Mail: [insert business address]
- Phone: [insert phone number]
1. INFORMATION WE COLLECT
We collect several types of information from and about users of our Services.
1.1 Information You Provide Directly
Parent/Guardian Account Information:
- Full name
- Email address
- Phone number
- Password (encrypted)
- Payment information (credit card, bank account details)
- Billing address
Teen User Information (Provided by Parents):
- First name and last initial or full name (at parent's discretion)
- Age or date of birth
- Phone number (optional)
- Device information
Tapout Configuration Information:
- Tapout schedules (bedtime, homework, dinner, etc.)
- Selected apps to block during tapouts
- Allowance amounts and payment preferences
- Custom rules and settings
- Parent notes or labels for tapout sessions
Communications:
- Customer support inquiries
- Feedback and survey responses
- Messages sent through the Services
1.2 Information Collected Automatically
Usage Data:
- Tapout session data (start time, end time, completion status)
- App blocking events
- Session completion rates and streaks
- Login and access times
- Features used within the app
Device Information:
- Device type, model, and operating system
- Unique device identifiers
- Mobile network information
- NFC hardware capability
- App version and settings
Technical Data:
- IP address
- Browser type and version
- Time zone setting
- Crash reports and diagnostic data
- Performance metrics
1.3 Information from Third Parties
Payment Processors:
- Transaction confirmation data
- Payment status and history
- Fraud detection information
iOS Screen Time API:
- App usage data during tapout sessions (for blocking enforcement only)
- Screen time statistics (when enabled by parent)
Analytics Providers:
- Aggregated usage statistics
- Feature engagement metrics
1.4 Location Information
We DO NOT collect precise location data. The Services do not track your teen's location or use GPS technology. Location services are not required to use Tapout Rewards.
We may collect general location information (city/state level) based on IP address for:
- Fraud prevention
- Compliance with local laws
- Displaying relevant support resources
2. HOW WE COLLECT INFORMATION
We collect information through various methods:
2.1 Direct Collection
- Information you enter when creating an account
- Data you provide when configuring tapout schedules
- Content you submit through customer support
2.2 Automatic Collection
- Through cookies and similar tracking technologies on our website
- Through the mobile app's built-in analytics
- Via NFC tap events recorded by the app
2.3 Third-Party Collection
- From payment processors when you make purchases
- From iOS Screen Time API when enforcing app blocks
- From cloud storage providers (iCloud) if you enable backup features
3. HOW WE USE YOUR INFORMATION
We use the information we collect for the following purposes:
3.1 To Provide and Maintain the Services
Core Functionality:
- Create and manage user accounts
- Process tapout sessions and enforce app blocking
- Calculate and distribute allowances
- Send notifications about tapout events
- Synchronize data across devices
- Provide customer support
Service Improvements:
- Analyze usage patterns to improve features
- Test new functionality
- Debug and fix technical issues
- Optimize app performance
3.2 To Process Payments and Prevent Fraud
- Process subscription fees and allowance payments
- Verify payment methods
- Detect and prevent fraudulent transactions
- Manage billing and invoicing
- Process refunds when applicable
3.3 To Communicate With You
- Send transactional emails (account creation, password resets, receipts)
- Provide customer support responses
- Send important service updates or changes
- Notify you of new features (if you've opted in)
- Request feedback or surveys (optional)
3.4 To Ensure Safety and Security
- Verify user identities
- Protect against unauthorized access
- Enforce our Terms and Conditions
- Comply with legal obligations
- Respond to legal requests and prevent harm
3.5 For Analytics and Research
- Understand how users interact with the Services
- Measure the effectiveness of features
- Conduct research to improve family digital wellness
- Generate aggregated, de-identified statistics
Note: We only use aggregated, de-identified data for research purposes. Individual user data is never sold or shared for research without explicit consent.
3.6 With Your Consent
We may use information for other purposes with your explicit consent, which you can withdraw at any time.
4. HOW WE SHARE YOUR INFORMATION
We do not sell your personal information. We share information only in the following limited circumstances:
4.1 Within Your Family Account
Parent-Teen Data Sharing:
- Parents can view all tapout session data for their registered teens
- Teens can view their own session history and earned allowances
- All family members sharing an account can see shared schedules and settings
4.2 With Service Providers
We share information with third-party vendors who perform services on our behalf:
Payment Processing:
- Stripe or other payment processors
- Only payment information necessary to process transactions
- Subject to their respective privacy policies
Cloud Infrastructure:
- Amazon Web Services (AWS) or similar providers
- For secure data storage and hosting
- Subject to strict data processing agreements
Customer Support:
- Customer service platforms
- Only information necessary to resolve your inquiry
Analytics:
- Google Analytics (website only)
- Firebase Analytics (mobile app)
- Only aggregated, non-personally identifiable data when possible
Email Services:
- For transactional and marketing emails (if opted in)
All service providers are contractually obligated to:
- Use data only for providing services to us
- Maintain appropriate security measures
- Comply with applicable privacy laws
- Not use the data for their own purposes
4.3 For Legal Reasons
We may disclose information if we believe it's necessary to:
- Comply with applicable laws, regulations, or legal processes
- Respond to lawful requests from public authorities (court orders, subpoenas)
- Enforce our Terms and Conditions
- Protect our rights, property, or safety
- Protect the rights, property, or safety of our users or the public
- Prevent fraud or other illegal activity
- Investigate potential violations of our policies
4.4 Business Transfers
If we are involved in a merger, acquisition, sale of assets, bankruptcy, or other business transaction, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice in the app before your information becomes subject to a different privacy policy.
4.5 With Your Consent
We may share information for other purposes with your explicit consent.
4.6 Aggregated or De-Identified Data
We may share aggregated or de-identified information that cannot reasonably be used to identify you, such as:
- Statistical data about app usage patterns
- Trends in teen digital wellness
- General effectiveness of screen time management techniques
5. CHILDREN'S PRIVACY (COPPA COMPLIANCE)
We take children's privacy very seriously and comply with the Children's Online Privacy Protection Act (COPPA).
5.1 Age Requirements
- The Services are intended for use by parents/guardians (18+) and their teen children (13-17)
- We do not knowingly collect information from children under 13 without verifiable parental consent
- Parents must create accounts on behalf of their teens
5.2 Parental Consent
Before collecting any personal information from a teen user, we require:
- Verified parental consent during account setup
- Parent acknowledgment of this Privacy Policy
- Parent authorization for data collection and use
Parents provide consent by:
- Creating the family account with payment information
- Registering teen users within their account
- Agreeing to the Terms and Conditions and Privacy Policy
5.3 Information Collected from Teens
With parental consent, we collect from teen users:
- First name and last initial (or full name at parent's discretion)
- Age or date of birth
- Device identifiers
- Tapout session data (times, completion status)
- App usage data during tapout sessions (for blocking purposes only)
We do NOT collect from teens:
- Precise geolocation data
- Photos or videos
- Social media account information
- Biometric data
- Any information not necessary for core functionality
5.4 How Teen Information Is Used
Teen information is used only to:
- Enable tapout sessions and app blocking
- Calculate and distribute allowances
- Provide service notifications
- Enable parent monitoring features
- Improve the Services
5.5 Parental Rights
Parents have the right to:
- Review: Request to review any personal information collected from their teen
- Delete: Request deletion of their teen's personal information at any time
- Refuse: Refuse to allow further collection or use of their teen's information
- Modify: Update or correct their teen's information
To exercise these rights, contact us at: [privacy email]
We will respond to requests within a reasonable timeframe, typically within 30 days.
5.6 Teen Data Retention
- Teen data is retained only as long as the account is active
- When a teen "ages out" (turns 18), parents can convert the account or delete it
- Upon account deletion, teen data is permanently deleted within 90 days (except as required by law)
5.7 Third-Party Sharing of Teen Data
We do not share teen personal information with third parties except:
- As necessary to provide the Services (e.g., payment processing)
- As required by law
- With explicit parental consent
We NEVER sell teen personal information to third parties.
5.8 Notification of Privacy Policy
We inform parents about our privacy practices through:
- This Privacy Policy prominently displayed during signup
- Email notification upon account creation
- In-app notices about data practices
- Direct communication regarding any material changes
6. DATA RETENTION
6.1 How Long We Keep Your Information
Account Data:
- Retained while your account is active
- Retained for 90 days after account deletion (for recovery purposes)
- Permanently deleted after 90 days unless legal retention is required
Transaction Data:
- Payment and allowance records retained for 7 years (tax and legal requirements)
- Can be provided to you upon request
Usage Data:
- Tapout session history retained while account is active
- Aggregated analytics retained indefinitely (de-identified)
- Individual session data deleted 2 years after account closure
Support Communications:
- Retained for 3 years for quality assurance and legal purposes
Legal and Safety Data:
- Information related to legal matters retained as required by law
- Fraud prevention data retained according to industry standards
6.2 Deletion of Your Information
You can request deletion of your information at any time by:
- Using the account deletion feature in the app
- Contacting us at [privacy email]
- Sending a written request to our mailing address
Upon deletion request, we will:
- Immediately revoke access to the Services
- Delete personal information within 90 days
- Retain only information required by law or legitimate business purposes
7. DATA SECURITY
7.1 How We Protect Your Information
We implement appropriate technical and organizational security measures to protect your information, including:
Technical Measures:
- Encryption in transit (TLS/SSL)
- Encryption at rest for sensitive data
- Secure password hashing (bcrypt or similar)
- Regular security audits and vulnerability assessments
- Intrusion detection systems
- Secure API communications
Organizational Measures:
- Limited employee access to personal information
- Background checks for employees with data access
- Confidentiality agreements with all personnel
- Regular security training for staff
- Incident response procedures
Infrastructure Security:
- Secure cloud hosting with industry-leading providers
- Regular backups and disaster recovery plans
- Network segmentation and firewalls
- DDoS protection
7.2 Payment Security
- We use PCI-DSS compliant payment processors
- We do not store full credit card numbers on our servers
- Payment information is tokenized and encrypted
- All transactions use secure HTTPS connections
7.3 NFC Security
- NFC communications are encrypted
- Tapout tags are uniquely paired to accounts
- Deactivated tags cannot be used
- Tags cannot be cloned or duplicated
7.4 Your Responsibility
You are responsible for:
- Keeping your password secure and confidential
- Logging out of shared devices
- Monitoring your account for unauthorized access
- Notifying us immediately of any security breach
Security Best Practices:
- Use a strong, unique password
- Enable two-factor authentication if available
- Don't share your account credentials
- Keep your device's operating system updated
7.5 Data Breach Notification
In the event of a data breach that affects your personal information, we will:
- Notify you via email within 72 hours of discovery
- Provide details about the breach and affected data
- Describe steps we're taking to address the breach
- Advise you on protective measures you can take
- Notify relevant authorities as required by law
No security system is perfect. While we strive to protect your information, we cannot guarantee absolute security. You use the Services at your own risk.
8. YOUR PRIVACY RIGHTS
8.1 Access and Control
You have the following rights regarding your personal information:
Right to Access:
- Request a copy of all personal information we hold about you
- Receive information in a structured, commonly used format
Right to Rectification:
- Correct inaccurate or incomplete information
- Update your account details at any time
Right to Deletion:
- Request deletion of your personal information
- "Right to be forgotten" in applicable jurisdictions
Right to Restriction:
- Request we limit how we use your information
- Object to certain types of processing
Right to Data Portability:
- Receive your data in a machine-readable format
- Transfer your data to another service (where technically feasible)
Right to Object:
- Object to processing based on legitimate interests
- Opt out of marketing communications
Right to Withdraw Consent:
- Withdraw consent for data processing at any time
- Does not affect the lawfulness of prior processing
8.2 How to Exercise Your Rights
To exercise any of these rights:
- Email: [privacy email]
- Mail: [business address]
- In-App: Use the "Privacy Settings" or "Account Settings" section
We will respond within:
- 30 days for most requests
- 45 days for complex requests
- We may request additional information to verify your identity
8.3 Account Settings
You can control certain information through your account settings:
- Update profile information
- Modify notification preferences
- Configure tapout schedules
- Manage linked payment methods
- Export your data
- Delete your account
8.4 Marketing Communications
You can opt out of marketing communications by:
- Clicking "unsubscribe" in any marketing email
- Adjusting preferences in account settings
- Contacting us directly
Note: You cannot opt out of transactional emails necessary for the Services (e.g., receipts, security alerts, account notifications).
9. CALIFORNIA PRIVACY RIGHTS (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
9.1 Categories of Information Collected
In the past 12 months, we have collected the following categories of personal information:
- Identifiers (name, email, phone number)
- Payment information
- Internet or network activity (usage data, device information)
- Geolocation data (general city/state only)
- Inferences drawn from usage patterns
9.2 California Consumer Rights
Right to Know:
- Request disclosure of personal information collected
- Request disclosure of categories of sources
- Request disclosure of business purposes for collection
- Request disclosure of third parties we share with
Right to Delete:
- Request deletion of personal information collected from you
- Subject to certain exceptions
Right to Opt-Out:
- Opt out of the "sale" of personal information
- Note: We do not sell personal information
Right to Non-Discrimination:
- We will not discriminate against you for exercising your rights
- Same quality of service regardless of rights exercise
9.3 How to Exercise California Rights
Designated Methods:
- Email: [privacy email]
- Phone: [toll-free number]
- Online Form: [URL to privacy request form]
We will verify your identity before processing requests.
Authorized Agents:
- You may designate an authorized agent to make requests on your behalf
- Agent must provide written authorization or power of attorney
- We may still require you to verify your identity
9.4 California "Shine the Light" Law
California residents may request information about disclosures of personal information to third parties for direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes.
9.5 California Minors
California residents under 18 have the right to request removal of content they posted publicly. Contact us at [privacy email] to request removal.
10. INTERNATIONAL DATA TRANSFERS
10.1 Data Storage and Processing
- Our Services are based in the United States
- Your information may be transferred to and processed in the United States
- The United States may have different data protection laws than your jurisdiction
- By using the Services, you consent to this transfer
10.2 European Economic Area (EEA) Users
If you are located in the EEA, we rely on the following legal bases for processing:
- Consent: When you provide explicit consent
- Contract: To fulfill our contract with you (provide Services)
- Legal Obligation: To comply with legal requirements
- Legitimate Interest: For business operations and improvements
Your EEA Rights:
- All rights listed in Section 8 (Your Privacy Rights)
- Right to lodge a complaint with your local supervisory authority
- Right to object to processing based on legitimate interests
Data Transfer Mechanisms:
- We use Standard Contractual Clauses approved by the European Commission
- Our service providers comply with applicable data protection laws
10.3 Other International Users
If you are located outside the United States:
- Your information will be transferred to the United States
- You may have rights under your local privacy laws
- Contact us to exercise any applicable rights
11. THIRD-PARTY SERVICES AND LINKS
11.1 Third-Party Services We Use
Our Services integrate with third-party services, including:
Payment Processors:
- Stripe (privacy policy: stripe.com/privacy)
- PayPal (privacy policy: paypal.com/privacy)
Analytics:
- Google Analytics (privacy policy: google.com/analytics/terms)
- Firebase (privacy policy: firebase.google.com/support/privacy)
Cloud Infrastructure:
- Amazon Web Services (privacy policy: aws.amazon.com/privacy)
Customer Support:
- [Your support platform] (privacy policy: [URL])
Each third-party service has its own privacy policy. We encourage you to review their policies.
11.2 Third-Party Links
Our Services may contain links to third-party websites, apps, or resources. We are not responsible for:
- The privacy practices of third-party sites
- The content of third-party sites
- Any data collected by third parties
We encourage you to review the privacy policies of any third-party sites you visit.
11.3 Social Media
We may have social media pages (Facebook, Instagram, Twitter, etc.). Information you provide on social media platforms is governed by their privacy policies, not ours.
12. CHANGES TO THIS PRIVACY POLICY
12.1 How We Update This Policy
We may update this Privacy Policy from time to time to reflect:
- Changes in our practices
- Changes in applicable laws
- New features or services
- Feedback from users
12.2 Notice of Changes
For Material Changes:
- We will notify you at least 30 days before changes take effect
- Notification via email to your registered address
- Prominent notice in the app or website
- Update the "Effective Date" at the top of this policy
For Non-Material Changes:
- We will update the "Last Updated" date
- Changes take effect immediately upon posting
- We encourage you to review this policy periodically
12.3 Your Acceptance
Continued use of the Services after changes constitutes acceptance of the updated Privacy Policy.
If you do not agree with changes:
- Stop using the Services
- Delete your account
- Contact us with concerns
12.4 Version History
Previous versions of this Privacy Policy are available upon request at [privacy email].
13. CONTACT US
13.1 Privacy Questions and Concerns
If you have questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us:
- Email: [privacy email]
- Phone: [phone number]
- Mail: [Company Name], Attn: Privacy Officer, [Street Address], [City, State ZIP]
Response Time: We aim to respond to all inquiries within 5-10 business days.
ADDITIONAL INFORMATION
Cookie Policy
Our website uses cookies and similar tracking technologies. By using our website, you consent to our use of cookies as described below.
Strictly Necessary Cookies:
- Enable core website functionality
- Remember your login status
- Cannot be disabled
Performance Cookies:
- Google Analytics (tracks website usage)
- Help us understand how visitors use our site
- Aggregated and anonymous data
Functional Cookies:
- Remember your preferences
- Provide enhanced features
- Improve user experience
How to Control Cookies:
- Browser settings to block or delete cookies
- Opt out of Google Analytics: tools.google.com/dlpage/gaoptout
- Note: Blocking cookies may limit functionality
DO NOT TRACK SIGNALS
Some browsers have "Do Not Track" features. Our Services do not currently respond to Do Not Track signals because there is no industry standard for how to respond.
ACCESSIBILITY
We are committed to making our Privacy Policy accessible to everyone. If you have difficulty accessing this policy or need it in an alternative format, please contact us at [privacy email].
EFFECTIVE DATE
This Privacy Policy is effective as of October 23, 2025 and will remain in effect except with respect to any changes in its provisions in the future, which will be in effect immediately after being posted on this page.
SUMMARY
We know privacy policies can be long and complex. Here's a quick summary:
- We collect: Account info, tapout data, usage stats, payment info
- We use it for: Running the app, processing payments, improving features
- We share with: Payment processors, cloud hosts, support tools (never advertisers)
- We protect: Encryption, secure hosting, limited access
- Teens: Full COPPA compliance, parental consent required
- Your rights: Access, delete, correct, export your data anytime
- We DON'T: Sell your data, track location, or share info for marketing
For complete details, please read the full policy above.
BY USING TAPOUT REWARDS, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY AND AGREE TO ITS TERMS.
Last Updated: October 23, 2025
© 2025 Tapout Rewards, LLC. All rights reserved.