Privacy Policy
Last updated: June 7, 2026
Tap Strategies, LLC ("Tap Strategies," "we," "us," or "our") builds custom technology and strategy solutions for our clients. This Privacy Policy explains what information we collect, how we use it, and how we protect it — including data we access from connected third-party systems such as QuickBooks Online on a client's behalf.
1. Who this policy covers
This policy applies to visitors of our website and to the clients who engage Tap Strategies. It primarily describes the information we collect and control. Where we access and process a client's own business data through a connected system, we do so under that client's instructions — see Section 2.
2. Our role: controller vs. processor
For information we collect directly (such as website inquiries), Tap Strategies is the data controller. For a client's business data that we access from connected systems to build and operate their solution, the client is the controller and Tap Strategies acts as a processor / service provider on the client's behalf. Our handling of that client data is governed by the client's engagement agreement and any applicable data processing terms, which take precedence over this policy for that data.
3. Information we collect
- Information you give us directly. When you contact us, we collect your name, email address, and anything you include in your message.
- Client business data from connected systems. With a client's explicit authorization, we access business and financial data from the systems they connect — for example accounting data from QuickBooks Online (via Intuit), and operational data from other business platforms. This may include invoices, payments, vendor and expense records, account balances, jobs, labor and material costs, and related business records. We access this data on a read basis to build and operate the client's solution.
- Basic site analytics. Standard, non-identifying technical information (such as browser type and pages viewed) may be collected to operate and improve the website.
4. How we use information
- To build, operate, maintain, and improve the solutions we provide to our clients.
- To analyze and present a client's own data back to that client.
- To respond to inquiries and provide support.
We use client business data only to provide our services to that client. We do not sell personal or business data, and we do not use it for advertising or share it with third parties for their own purposes.
5. How we share information & sub-processors
We share information only as necessary to provide our services: with infrastructure and hosting providers that store data securely on our behalf (our "sub-processors," such as cloud hosting and database providers), with the connected systems a client has authorized (such as Intuit/QuickBooks Online), and where required by law. We require our sub-processors to protect data consistent with this policy. We never sell personal or business data.
6. Connected accounts (QuickBooks Online and others)
When a client connects an account such as QuickBooks Online, the connection is authorized by the client through that provider's secure authorization (OAuth) flow. We store the resulting access credentials in encrypted form and use them solely to read the data needed for the client's solution. A client may disconnect at any time — from within the connected provider or by contacting us — after which we stop accessing that system and delete the stored credentials.
7. How we protect information
We use reasonable technical and organizational safeguards, including encryption of sensitive credentials, access controls, and per-client data isolation. Access to client data is limited to what is necessary to operate that client's solution. No method of transmission or storage is perfectly secure; while we work to protect information, we cannot guarantee absolute security. We will notify affected parties of a data breach as required by applicable law.
8. Data retention & deletion
We retain information for as long as needed to provide our services and as set out in the applicable engagement agreement, and we delete or return client data on request or after the engagement ends, subject to legal obligations. Website inquiry data is kept only as long as needed to respond and maintain our records. Clients and individuals may request access to, correction of, or deletion of their data by contacting us.
9. Cookies & Do Not Track
Our website uses only the cookies and similar technologies needed to operate the site and understand basic, aggregate usage. We do not use cookies for advertising. Because there is no common industry standard for "Do Not Track" signals, our site does not currently respond to them.
10. Children's privacy
Our services are intended for businesses and are not directed to children. We do not knowingly collect personal information from children under 13 (or under 16 where applicable).
11. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, and to know how it is used. Residents of California and certain other states may have additional rights, including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the "sale" or "sharing" of personal information — and we do not sell or share personal information. To exercise any right, contact us at chris@tapstrategiesgroup.com; we will not discriminate against you for doing so.
12. Data location
We store and process information in the United States. If you access our services from outside the U.S., you understand your information may be processed in the U.S.
13. Governing law
This policy and any dispute relating to it are governed by the laws of the State of Texas, without regard to its conflict-of-laws rules.
14. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
15. Contact us
Questions about this policy or your data? Email chris@tapstrategiesgroup.com. Tap Strategies, LLC is the entity responsible for the information described in this policy.