Tapline

Last updated 5 August 2026

Privacy

What we collect

What you type into your page

Your handle, display name, bio, avatar emoji, theme choice, and every link title and destination. This is the page itself, so it is served at /your-handle and is visible to anyone who has the link — and to search engines. Don’t put anything in it you wouldn’t put on a poster.

Visit and tap counts

When someone opens your page we increment a view counter and store a row with the time and the referring hostname. When they tap a link we do the same for that link, then redirect them. This is what powers your analytics.

We deliberately do not store IP addresses, user agents, device fingerprints, or full referring URLs against those events. The referrer is reduced to its hostname before it is written — so we can tell you “42 came from instagram.com” without holding a record of the specific post.

Your contact email (optional)

There is one field for this, in your editor, and it is optional. We store it so that if you lose your edit link and write to us, a human has something to check you against — without it, a lost link is usually unrecoverable. If a Pro purchase is applied to your page and the field is empty, we fill it in with the address used at checkout, so the page and the payment can be tied together later.

What it is not used for: it is never rendered on your public page, never sent marketing, and it is not the address your receipt goes to. Receipts and Pro codes go to the email collected at checkout, which is stored separately alongside the order (see below). Nothing else in the product reads this field.

Emails your visitors give you

Pro pages can show an email capture block. Addresses submitted there belong to you, not us — we store them so you can export them as a CSV. We do not email that list, sell it, or use it for anything else. If you collect addresses, you are responsible for how you contact those people.

Buyer details from checkout

Payments run through Stripe via the NanoCorp platform, which is the merchant of record. Card numbers never reach Tapline. What we receive and store is the checkout session id, the amount, the currency, and the buyer’s email address, so we can mint and honour a Pro claim code.

We send exactly one kind of email, to that address: the receipt carrying your claim code, once when the payment clears, and again if you ask us to resend it. It goes out through the NanoCorp platform’s sending service. There is no newsletter, no drip sequence, and no list — that receipt is the only mail Tapline originates.

Site analytics

Tapline loads one analytics script, provided by the NanoCorp platform and built on PostHog. It records pageviews, clicks, JavaScript errors, and performance vitals so we can tell which parts of the product are broken or slow. It sets cookies and a localStorage entry of its own to recognise a returning browser — those are in addition to Tapline’s own, all of which are itemised under cookies and local storage below. Session recording and feature-flag polling are switched off.

Being straight with you: this script is loaded in the app’s root layout, so it is present on published creator pages too, not only on our marketing pages. That means visits to your page are counted twice over — once in your own view/tap counters, and once in our product analytics. It is not fed back to you, not tied to your page’s counters, and not used to target anyone. We would rather write that down than let you find it in the page source.

What we don’t do

  • We don’t sell or rent data to anyone.
  • We don’t run any advertising or ad-retargeting trackers, anywhere — the one analytics script described above is for product diagnostics.
  • We don’t build profiles of your visitors — the tap log has no identifier that could link two visits to the same person.
  • We don’t hold passwords, because there aren’t any.

Cookies and local storage

This is the complete list of what Tapline itself puts in your browser. Not a category summary — the actual names. If we add one, it gets added here.

  • tl_edit_<handle> — a cookie holding the edit token that proves you own that page, one per page you publish. httpOnly, so page scripts can’t read it, and it lasts a year. Without it there would be no way to know you’re the owner.
  • tl_pending_upgrade — a cookie carrying only your handle across the trip out to hosted checkout and back, so the payment lands on the right page. httpOnly, and it expires in two hours. It is deleted as soon as the purchase lands on your page, and in any case it is gone within those two hours whether that happens or not. Every buyer gets this one; nobody who doesn’t start an upgrade does.
  • tapline.draft.v1 — not a cookie. This is a localStorage entry holding the page you are currently building — display name, bio, and every link title and URL — so that a refresh mid-build doesn’t lose your work. It never leaves your browser until you press publish, and publishing clears it.

The analytics script described above sets its own cookies and its own localStorage entry, on every page it loads. Those are the tracker’s, not ours, and they are how a returning browser is recognised as the same one.

None of the above is an advertising cookie, and none of it is shared with a third party for their own purposes.

Who else sees the data

Tapline runs on the NanoCorp platform, which provides the hosting (Vercel), the database (Neon), payments (Stripe), and the analytics backend. Those providers process data on our behalf in order to run the service. We don’t share your data with anyone else.

How long we keep it

Page content and counters stay as long as the page exists. When a page goes, its links, view rows, tap rows and captured emails go with it — that cascade is enforced by the database, not by us remembering to tidy up. Order records are kept for accounting.

To be clear about the mechanism, because “delete the page” can sound like a button: there isn’t one yet. Deletion is something you ask us for by email and we do by hand, as described next. We would rather tell you that than have you hunt the editor for a control that doesn’t exist.

Deleting your page and your data

Email hello@linkinbio.nanocorp.app from the contact address on the page, or with the edit link, and tell us the handle. We delete the page and everything attached to it. If you want a copy of your captured emails first, export the CSV from your editor — after deletion we can’t recover it.

A word about what this document is

This describes how Tapline actually behaves today, in plain language, rather than claiming certifications we haven’t been audited for. If a specific compliance question matters for your situation, ask us directly and we’ll answer honestly about what we do and don’t do.

Changes

If we change how any of this works we’ll update this page and move the date at the top. Material changes to what we collect will be called out on the page itself, not slipped in.

Contact

hello@linkinbio.nanocorp.app — a person reads it. See also our terms.