Skip to content

Christmas 2026 slots open 1 November. 38 cities live. Same-day wrap from £6. 1,412 vetted wrappers. Courier collection in a 30 minute window

TapToWrapWrapped in an hour

Legal

Privacy Policy

Version 12 November 2025 TapToWrap Ltd 7 minute read

Version date: 12 November 2025. This notice applies to everyone whose personal data TapToWrap Ltd handles, whether you book a wrap through taptowrap.co, receive a wrapped gift from one of our couriers, sign up as a professional wrapper, enquire about a corporate contract, or simply browse the site. It replaces every earlier version. If you have arrived here from a cookie banner and want the cookie detail rather than the full picture, read the cookie policy instead.

Who is responsible for your data

TapToWrap Ltd is the controller. We are registered in England and Wales, company number 15042118, with a registered office at 2nd Floor, 31 Redchurch Street, London E2 7DJ, United Kingdom. Our VAT number is GB 442 118 907. We have run the network since 2023 and it now covers 1,412 vetted wrappers across 38 cities.

Our data protection contact reads everything sent to privacy@taptowrap.co and answers within five working days. You can also write to the registered office marked for the attention of the data protection lead, or call +44 20 4525 8810 between 08:00 and 20:00 GMT, seven days a week.

Wrappers on the network are separate controllers for their own bench records. Where a wrapper handles your details to complete a booking we placed, they act on our instructions.

What we collect

We collect the minimum a wrap needs, plus what the law and our card processor require. In practice that means:

  • Booking details. Your name, email address, mobile number, the postcode you tapped, item size, wrap tier, slot time, and any note you leave for the wrapper.
  • Collection and delivery addresses. For courier wrap we hold the pickup address, the delivery address, the recipient first name, and access instructions such as a buzzer code or a safe place.
  • A description of the gift contents. We ask what the item is so the wrapper brings the right paper and the right box. Keep it functional, and tell us nothing about health, beliefs, or anyone’s private life, because we do not need it.
  • Payment data. Card details are entered in a Stripe field and go straight to Stripe. We receive a payment token, the card brand, the last four digits, the expiry month, and the authorisation outcome.
  • Advertising identifiers. If you reach us from a Google Ads click we store the gclid, plus any UTM parameters in the link, so we can tell which campaigns pay for themselves.
  • Device and connection data. IP address, browser and operating system version, screen size, referring page, and the pages you viewed. Cloudflare also logs request metadata to filter automated traffic.
  • Wrapper onboarding data. For supply side applicants: identity documents, right to work evidence, two references, bank details for payouts, and photographs of finished work.
  • Support and quality records. Emails, SMS threads, call notes, ratings, damage claims, and photographs submitted with a claim.

Why we use it, and our lawful basis

Under Article 6 of the UK GDPR and the EU GDPR we rely on four bases and nothing else.

  • Performance of a contract, Article 6(1)(b). Taking your booking, passing it to a wrapper, arranging courier collection, taking payment, handling cancellations, and answering support requests about a live order.
  • Legal obligation, Article 6(1)(c). Keeping VAT and accounting records, responding to lawful requests, and running right to work checks on wrappers.
  • Legitimate interests, Article 6(1)(f). Fraud and chargeback prevention, network safety, service quality monitoring, aggregate reporting such as our 61 minute median turnaround, and defending claims. We weigh our interest against your rights each time and record the outcome.
  • Consent, Article 6(1)(a). Non-essential cookies, advertising measurement, and marketing email. Consent is optional, granular, and you can withdraw it at any time without affecting a booking.

How long we keep it

RecordRetention periodReason
Completed booking and invoice6 years from the end of the tax yearVAT and company law
Gift contents description90 days after the slotClaims window plus a buffer
Collection and delivery addresses13 months after the slotRepeat delivery and dispute handling
Payment token, card brand, last four digits6 yearsRefunds and chargeback defence
Cancelled or abandoned booking12 monthsFraud pattern review
Support threads and call notes24 monthsQuality and complaint history
Damage claim file and photographs7 years from settlementInsurance and limitation periods
Wrapper identity and right to work evidence2 years after deactivationStatutory checks and appeals
Wrapper payout records6 yearsTax and accounting
Marketing consent and withdrawal log3 years after withdrawalProof of consent
Analytics events in Google Analytics 414 monthsShortest available retention
Server and security logs90 daysAbuse investigation

When a period ends we delete the record or reduce it to an aggregate count. Backups roll off within 35 days.

Who processes data for us

Every supplier below is bound by a written processing agreement, may act only on our instructions, and may not use your data for its own purposes except where noted.

ProcessorWhat it doesWhere it processes
StripeCard capture, authorisation holds, payouts to wrappersIreland, with support access from the United States
TwilioBooking and slot SMS, courier arrival alertsIreland and the United States
Google Analytics 4Consented site analytics and conversion reportingEuropean Union and the United States
Google AdsCampaign measurement and consented remarketing audiencesEuropean Union and the United States
CloudflareContent delivery, bot filtering, denial of service protectionGlobal edge network
MailchimpNewsletter delivery and consent recordsUnited States

Stripe is also a controller for the regulatory checks it must perform as a payment institution. We disclose data to our accountants, insurers, and legal advisers when a claim or audit requires it.

Sending data outside the UK and the EEA

Some suppliers above process data in the United States. For UK transfers we use the International Data Transfer Addendum to the European Commission clauses, issued by the Information Commissioner. For EEA transfers we use the 2021 standard contractual clauses. In each case we run a transfer risk assessment and require encryption in transit and at rest. Ask privacy@taptowrap.co for a copy of the clauses, with commercial terms redacted.

Your rights

If you are in the UK, the EEA, or Switzerland you can ask us to do any of the following, free of charge.

  • Confirm what we hold and give you a copy of it.
  • Correct anything inaccurate, including a mistyped delivery address.
  • Delete data we no longer need, subject to the retention table above.
  • Restrict processing while a dispute about accuracy is open.
  • Receive booking data you gave us in a portable machine readable file.
  • Object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent for cookies, advertising measurement, or email.

Email privacy@taptowrap.co from the address or mobile number you booked with. We reply within one month, and will say inside that month if a complex request needs longer. No automated decision produces legal effects for you, and we do not profile you to set prices.

Notice for California residents

Under the California Consumer Privacy Act as amended by the California Privacy Rights Act, you have the right to know the categories and specific pieces of personal information we hold, and rights to delete, to correct, to opt out of sharing for cross context behavioural advertising, and to limit the use of sensitive personal information. We do not sell personal information for money. We do share advertising identifiers with Google for measurement and remarketing when you consent, and declining the advertising toggle in our banner is a valid opt out. We honour the Global Privacy Control, we do not collect sensitive personal information as the Act defines it, and we will not discriminate against you for exercising a right. Email privacy@taptowrap.co with California in the subject line, or call +44 20 4525 8810. An authorised agent may act for you in writing.

Children

Bookings require you to be 18 or over and we do not knowingly collect data from children. A recipient of a gift may be a child, in which case we hold a first name and an address only, supplied by the adult who booked. If you believe a child has given us more than that, tell us and we will erase it.

Security

Traffic runs over TLS. Booking records sit in an encrypted database with role based access, so staff and wrappers see only the fields a job needs. Full card numbers never touch our servers. Administrative access requires two factor authentication and is reviewed each quarter. We report a notifiable breach to the Information Commissioner within 72 hours, and to you where the risk is high.

Complaints

Raise it with us first, because most issues are a mistyped field or a stale record and we can fix those the same day. If you are not satisfied, complain to the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow SK9 5AF, or through ico.org.uk. In the EEA you may complain to your local supervisory authority.

Changes to this notice

We update this notice when the service or a supplier changes, and the version date at the top moves with it. If a change materially affects how we use your data we will email account holders at least 14 days beforehand.

Contact us

Write to privacy@taptowrap.co for anything in this notice, hello@taptowrap.co for general questions, partners@taptowrap.co for corporate contracts, or support@taptowrap.co for a live booking. You can call +44 20 4525 8810 from 08:00 to 20:00 GMT, seven days a week, or post to TapToWrap Ltd, 2nd Floor, 31 Redchurch Street, London E2 7DJ, United Kingdom.