Privacy by design
Privacy and storage
This notice explains how Tap In handles personal data, browser storage, payments, support messages and optional analytics.
Last updated:
Operator and data controller
Tap In and wifisign.win are operated by the following Romanian limited liability company:
- Controller
- ROGIO WEB SERVICES S.R.L.
- Registered office
- Strada Subpădure nr. 3, sat Livezeni, comuna Livezeni, județul Mureș, România
- Trade Register number
- J26/1175/23.11.2015
- Fiscal identification code
- 35259017
- Privacy contact
- support@wifisign.win
What stays in your browser
The sign is created on your device. These records are not advertising trackers and are not used to build profiles.
Wi-Fi draft
The network name, password, sign wording, design choices and optional logo are stored in sessionStorage so a refresh does not erase the draft. Harmless template, palette and paper preferences may be stored in localStorage for the next visit. The session draft is removed when the browser tab or session closes, and none of this content is uploaded.
Pending checkout
The locale, Stripe Checkout Session reference and a random purchase reference are stored in localStorage. They become invalid after 24 hours and are removed the next time Tap In can access them. They contain no Wi-Fi name or password.
Purchase unlock
A signed, non-sensitive entitlement is stored in localStorage and expires 24 hours after payment. The server verifies it without receiving Wi-Fi details.
Cookie choice
Your accepted or rejected optional-cookie choice, timestamp and policy version are stored in localStorage. The choice becomes invalid after 180 days and the record is removed the next time Tap In can access it.
Data handled by service providers
Website delivery and security — Cloudflare
Cloudflare processes request metadata such as IP address, requested URL, time, headers and security signals to deliver and protect the site. Tap In has not enabled Worker Logs, Logpush or tail consumers and keeps no separate server-log database.
Payments — Stripe
If you choose to pay, your browser opens Stripe Checkout. Stripe receives the payment, contact, transaction, device and fraud-prevention data entered or generated there. Tap In receives only the Checkout Session reference and payment status needed to unlock the purchase; it never receives card details.
Support email
If you email support, the operator processes your email address, message and any technical context you provide to answer you. Do not send a Wi-Fi password. Support correspondence is kept for up to 12 months after the request is resolved, unless it must be retained longer for a legal claim.
Optional analytics
Google Analytics is active only for visitors who accept optional cookies. Before acceptance, after rejection or if consent cannot be saved, Tap In does not load the Analytics script, set Analytics cookies or send Analytics data to Google.
After consent, Tap In sends a sanitized page view containing only the site origin and language-specific path. It may also send editor-step events containing only known template, paper and export-action identifiers. URL queries or fragments, Wi-Fi details, custom wording, logos, colors, filenames, payment references and entitlement tokens are excluded. Advertising storage, ad personalization and Google Signals are disabled. Analytics cookies last no more than 180 days, and GA4 event and user data retention is set to two months. You can withdraw consent at any time through Cookie settings.
Purposes and legal bases
- Contract and pre-contract steps (GDPR Art. 6(1)(b)): create and verify a payment, deliver the 24-hour unlock and answer purchase-related support.
- Legal obligation (GDPR Art. 6(1)(c)): retain transaction and accounting records for the period required by Romanian law.
- Legitimate interests (GDPR Art. 6(1)(f)): securely deliver the site, prevent abuse and answer general support requests, balanced against visitor rights.
- Consent (GDPR Art. 6(1)(a)): optional Analytics only, after you choose to accept it.
Recipients
Data may be handled by Cloudflare for hosting, security and email routing; Stripe and its financial/service partners for payments; the operator’s mailbox provider for support; professional accounting or legal advisers where necessary; and public authorities where law requires it. Google receives sanitized analytics data only after you accept optional cookies.
International transfers
Cloudflare and Stripe operate internationally. Transfers outside the European Economic Area are governed by their data-processing agreements and applicable safeguards, which may include adequacy decisions, the EU-US Data Privacy Framework and Standard Contractual Clauses.
Your rights
Subject to the conditions in the GDPR, you may request:
- access to and a copy of your personal data
- correction or deletion
- restriction of processing
- data portability
- objection to processing based on legitimate interests
- withdrawal of Analytics consent without affecting earlier lawful processing
Send a rights request to the privacy contact above. The operator may ask for proportionate information to verify your identity and will normally respond within one month.
Automated decisions
Tap In does not make decisions based solely on automated processing that produce legal or similarly significant effects. Stripe may use automated fraud-prevention systems under its own privacy information.