Security & compliance

Protection and privacy, built in from the first visitor.

Selling online means you are responsible for a stranger's payment details and a growing database of people who trusted you with their information. TapToBuy is built so that responsibility is handled by default — data is protected in transit and at rest, and the privacy obligations that usually arrive as a legal surprise are wired in before your first sale.

Read the privacy policy

Data protection

Encryption is the default, not an upgrade.

A storefront moves sensitive information constantly: card details on the way to a payment processor, customer records at rest in a database, and session data traveling between a buyer's phone and the platform. TapToBuy treats encrypting that data in transit and at rest as table stakes rather than a premium tier, so protection does not depend on a setting you might forget to turn on.

We are deliberately careful about the exact cryptographic claims we make in marketing copy, because security you can trust is security that is stated precisely. Rather than assert a specific protocol version, cipher, or key-management guarantee here, we describe the standard we hold ourselves to and let the specifics be confirmed by documentation rather than a landing page.

In transit

Data moving between buyers and the platform is encrypted in transit.

At rest

Stored customer and order data is encrypted at rest using financial data encryption standards.

Recognized standards

We align our practices to recognized industry pfsecurity standards and hold ourselves to that bar.

Global privacy

Compliance that works from your very first visitor.

The moment someone from Brazil, the EU, or California lands on your store, a set of privacy laws applies to you whether or not you have read them. Most creator tools leave you to discover this later — usually when a request or a complaint forces the issue. TapToBuy flips that order by building the obligations of LGPD, GDPR, and CCPA into the product so you are covered before you have a problem to solve, not after.

That means the machinery regulators expect is already running underneath your store: a way to collect and honor consent, a record of what data you hold and why, and a repeatable process for assessing risk when you do something new. You get to run your business while the compliance surface is maintained for you.

LGPD, GDPR & CCPA

Tooling for Brazil's LGPD, the EU's GDPR, and California's CCPA is built in, so multiple jurisdictions are covered from your first international visitor.

Consent orchestration

Collect, record, and honor visitor consent in one place, so what a buyer agreed to is tracked rather than assumed.

DPIA workflows

Run data protection impact assessments through a guided workflow when you launch something new, instead of improvising a risk review under pressure.

Data mapping

Keep a living map of what personal data you hold and where it flows, which is the foundation every privacy regime expects you to maintain.

Recurring audits

Privacy and security posture is reviewed on a recurring basis rather than checked once at launch and quietly left to drift.

You own the data

The customer list every sale builds belongs to you and can be exported on demand — ownership and portability are part of the compliance story, not a fight with support.

How it fits together

Protection, consent, and ownership in one flow.

  1. 1

    A visitor arrives

    Consent orchestration captures what the visitor agrees to up front, and the applicable LGPD, GDPR, or CCPA obligations apply automatically based on where they are.

  2. 2

    A sale is recorded

    Payment and customer data is encrypted in transit and at rest, and the buyer is added to a database you own.

  3. 3

    Your footprint stays mapped

    Data mapping keeps a current record of what you hold and why, and DPIA workflows are ready whenever you introduce something new.

  4. 4

    You stay in control

    Recurring audits keep the posture honest over time, and you can export your customer data whenever you decide to.

Sell with protection and privacy handled.

Launch on a platform that encrypts data by default and builds LGPD, GDPR, and CCPA compliance in from the first visitor — while your customer list stays yours to export.