Security

Security you can
stake your business on

Your venue data — orders, staff records, revenue history — is valuable and sensitive. Here is exactly how we protect it.

AES-256 + TLS 1.3

Encrypted everywhere

All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Your order history, staff records, and customer data are never sent over an unencrypted connection.

UK & EU law

GDPR compliant

Tappsy is built for compliance with UK GDPR and the Data Protection Act 2018. Data is stored in UK/EU data centres. We act as a data processor on your behalf and sign a Data Processing Agreement on request.

Least-privilege

Role-based access

Every user account operates on the least-privilege principle. Owners, managers, and bar staff each see only what they need. Sensitive operations like voids and refunds require manager approval.

TOTP (RFC 6238)

Two-factor authentication

Owner and manager accounts support TOTP-based two-factor authentication (Google Authenticator, Authy, 1Password). 2FA is enforced at every login and cannot be bypassed. Terminal registration also requires 2FA when enabled.

No US data transfer

UK-based infrastructure

Tappsy runs on UK and EU infrastructure. No customer data is transferred to servers outside the UK or EU. We use enterprise-grade cloud providers with ISO 27001 certification.

Daily snapshots

Automated backups

Your data is backed up daily with point-in-time recovery. Backups are encrypted, stored in a geographically separate location, and tested regularly. Retention period: 30 days.

Professional plan

Full audit log

Every action taken in the system — voids, refunds, logins, menu changes, permission changes — is recorded with timestamp and user attribution. Audit logs are immutable and available to export.

Professional plan

99.9% uptime SLA

We publish our uptime history publicly at status.tappsy.io. Professional plan customers receive a contractual 99.9% uptime SLA with service credits for any shortfall.

GDPR

Your responsibilities, made easy

When you take table bookings or run a loyalty scheme, your venue is a data controller. Tappsy acts as your data processor — we only process personal data as you instruct us to, and never for our own purposes.

We maintain a Record of Processing Activities and can provide this to you or to the ICO on request. All sub-processors are listed in our DPA and are subject to GDPR-equivalent obligations.

Customers on the Professional plan receive a named Data Protection contact.

Lawful basis

We process operational data under the performance of a contract. Marketing communications require explicit opt-in.

Data minimisation

We collect only what is necessary. Staff PINs are bcrypt-hashed and never stored in plain text.

Data subject rights

Your customers can request access, rectification, or deletion of their data. We support these requests within the statutory 30-day window.

International transfers

We do not transfer personal data outside the UK or EU. All infrastructure is located in compliant regions.

Responsible disclosure

If you discover a security vulnerability in Tappsy, please report it to us before disclosing it publicly. We commit to acknowledging your report within 48 hours and resolving confirmed vulnerabilities within 30 days.

security@tappsy.io

We do not currently operate a bug bounty programme, but we acknowledge all good-faith reports publicly if desired.

FAQs

Security questions

Who can access my venue data?
Only you and the staff you invite. Tappsy employees cannot access your operational data without explicit permission from the account owner, which is only requested during a support escalation and logged.
Where is my data stored?
All data is stored on servers located in the UK and EU. We do not use data centres outside these regions for customer data.
Can I get a Data Processing Agreement?
Yes. We offer a standard DPA to all customers on request. Email legal@tappsy.io and we will send it within one business day.
How do you handle a data breach?
In the event of a data breach, we will notify affected customers within 72 hours as required by UK GDPR, and report to the ICO where required. We maintain an incident response plan and run regular drills.
What happens to my data when I cancel?
We hold your data for 30 days after cancellation so you can export everything. After that, it's permanently and irreversibly deleted from our systems and backups.

Any questions about our security posture?

We're happy to go into more detail. Enterprise customers can request a security questionnaire response and our infrastructure documentation.