Legal
Privacy Policy
Version date: 12 November 2025. This notice applies to everyone whose personal data TapToWrap Ltd handles, whether you book a wrap through taptowrap.co, receive a wrapped gift from one of our couriers, sign up as a professional wrapper, enquire about a corporate contract, or simply browse the site. It replaces every earlier version. If you have arrived here from a cookie banner and want the cookie detail rather than the full picture, read the cookie policy instead.
Who is responsible for your data
TapToWrap Ltd is the controller. We are registered in England and Wales, company number 15042118, with a registered office at 2nd Floor, 31 Redchurch Street, London E2 7DJ, United Kingdom. Our VAT number is GB 442 118 907. We have run the network since 2023 and it now covers 1,412 vetted wrappers across 38 cities.
Our data protection contact reads everything sent to privacy@taptowrap.co and answers within five working days. You can also write to the registered office marked for the attention of the data protection lead, or call +44 20 4525 8810 between 08:00 and 20:00 GMT, seven days a week.
Wrappers on the network are separate controllers for their own bench records. Where a wrapper handles your details to complete a booking we placed, they act on our instructions.
What we collect
We collect the minimum a wrap needs, plus what the law and our card processor require. In practice that means:
- Booking details. Your name, email address, mobile number, the postcode you tapped, item size, wrap tier, slot time, and any note you leave for the wrapper.
- Collection and delivery addresses. For courier wrap we hold the pickup address, the delivery address, the recipient first name, and access instructions such as a buzzer code or a safe place.
- A description of the gift contents. We ask what the item is so the wrapper brings the right paper and the right box. Keep it functional, and tell us nothing about health, beliefs, or anyone’s private life, because we do not need it.
- Payment data. Card details are entered in a Stripe field and go straight to Stripe. We receive a payment token, the card brand, the last four digits, the expiry month, and the authorisation outcome.
- Advertising identifiers. If you reach us from a Google Ads click we store the gclid, plus any UTM parameters in the link, so we can tell which campaigns pay for themselves.
- Device and connection data. IP address, browser and operating system version, screen size, referring page, and the pages you viewed. Cloudflare also logs request metadata to filter automated traffic.
- Wrapper onboarding data. For supply side applicants: identity documents, right to work evidence, two references, bank details for payouts, and photographs of finished work.
- Support and quality records. Emails, SMS threads, call notes, ratings, damage claims, and photographs submitted with a claim.
Why we use it, and our lawful basis
Under Article 6 of the UK GDPR and the EU GDPR we rely on four bases and nothing else.
- Performance of a contract, Article 6(1)(b). Taking your booking, passing it to a wrapper, arranging courier collection, taking payment, handling cancellations, and answering support requests about a live order.
- Legal obligation, Article 6(1)(c). Keeping VAT and accounting records, responding to lawful requests, and running right to work checks on wrappers.
- Legitimate interests, Article 6(1)(f). Fraud and chargeback prevention, network safety, service quality monitoring, aggregate reporting such as our 61 minute median turnaround, and defending claims. We weigh our interest against your rights each time and record the outcome.
- Consent, Article 6(1)(a). Non-essential cookies, advertising measurement, and marketing email. Consent is optional, granular, and you can withdraw it at any time without affecting a booking.
How long we keep it
| Record | Retention period | Reason |
|---|---|---|
| Completed booking and invoice | 6 years from the end of the tax year | VAT and company law |
| Gift contents description | 90 days after the slot | Claims window plus a buffer |
| Collection and delivery addresses | 13 months after the slot | Repeat delivery and dispute handling |
| Payment token, card brand, last four digits | 6 years | Refunds and chargeback defence |
| Cancelled or abandoned booking | 12 months | Fraud pattern review |
| Support threads and call notes | 24 months | Quality and complaint history |
| Damage claim file and photographs | 7 years from settlement | Insurance and limitation periods |
| Wrapper identity and right to work evidence | 2 years after deactivation | Statutory checks and appeals |
| Wrapper payout records | 6 years | Tax and accounting |
| Marketing consent and withdrawal log | 3 years after withdrawal | Proof of consent |
| Analytics events in Google Analytics 4 | 14 months | Shortest available retention |
| Server and security logs | 90 days | Abuse investigation |
When a period ends we delete the record or reduce it to an aggregate count. Backups roll off within 35 days.
Who processes data for us
Every supplier below is bound by a written processing agreement, may act only on our instructions, and may not use your data for its own purposes except where noted.
| Processor | What it does | Where it processes |
|---|---|---|
| Stripe | Card capture, authorisation holds, payouts to wrappers | Ireland, with support access from the United States |
| Twilio | Booking and slot SMS, courier arrival alerts | Ireland and the United States |
| Google Analytics 4 | Consented site analytics and conversion reporting | European Union and the United States |
| Google Ads | Campaign measurement and consented remarketing audiences | European Union and the United States |
| Cloudflare | Content delivery, bot filtering, denial of service protection | Global edge network |
| Mailchimp | Newsletter delivery and consent records | United States |
Stripe is also a controller for the regulatory checks it must perform as a payment institution. We disclose data to our accountants, insurers, and legal advisers when a claim or audit requires it.
Sending data outside the UK and the EEA
Some suppliers above process data in the United States. For UK transfers we use the International Data Transfer Addendum to the European Commission clauses, issued by the Information Commissioner. For EEA transfers we use the 2021 standard contractual clauses. In each case we run a transfer risk assessment and require encryption in transit and at rest. Ask privacy@taptowrap.co for a copy of the clauses, with commercial terms redacted.
Your rights
If you are in the UK, the EEA, or Switzerland you can ask us to do any of the following, free of charge.
- Confirm what we hold and give you a copy of it.
- Correct anything inaccurate, including a mistyped delivery address.
- Delete data we no longer need, subject to the retention table above.
- Restrict processing while a dispute about accuracy is open.
- Receive booking data you gave us in a portable machine readable file.
- Object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent for cookies, advertising measurement, or email.
Email privacy@taptowrap.co from the address or mobile number you booked with. We reply within one month, and will say inside that month if a complex request needs longer. No automated decision produces legal effects for you, and we do not profile you to set prices.
Notice for California residents
Under the California Consumer Privacy Act as amended by the California Privacy Rights Act, you have the right to know the categories and specific pieces of personal information we hold, and rights to delete, to correct, to opt out of sharing for cross context behavioural advertising, and to limit the use of sensitive personal information. We do not sell personal information for money. We do share advertising identifiers with Google for measurement and remarketing when you consent, and declining the advertising toggle in our banner is a valid opt out. We honour the Global Privacy Control, we do not collect sensitive personal information as the Act defines it, and we will not discriminate against you for exercising a right. Email privacy@taptowrap.co with California in the subject line, or call +44 20 4525 8810. An authorised agent may act for you in writing.
Children
Bookings require you to be 18 or over and we do not knowingly collect data from children. A recipient of a gift may be a child, in which case we hold a first name and an address only, supplied by the adult who booked. If you believe a child has given us more than that, tell us and we will erase it.
Security
Traffic runs over TLS. Booking records sit in an encrypted database with role based access, so staff and wrappers see only the fields a job needs. Full card numbers never touch our servers. Administrative access requires two factor authentication and is reviewed each quarter. We report a notifiable breach to the Information Commissioner within 72 hours, and to you where the risk is high.
Complaints
Raise it with us first, because most issues are a mistyped field or a stale record and we can fix those the same day. If you are not satisfied, complain to the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow SK9 5AF, or through ico.org.uk. In the EEA you may complain to your local supervisory authority.
Changes to this notice
We update this notice when the service or a supplier changes, and the version date at the top moves with it. If a change materially affects how we use your data we will email account holders at least 14 days beforehand.
Contact us
Write to privacy@taptowrap.co for anything in this notice, hello@taptowrap.co for general questions, partners@taptowrap.co for corporate contracts, or support@taptowrap.co for a live booking. You can call +44 20 4525 8810 from 08:00 to 20:00 GMT, seven days a week, or post to TapToWrap Ltd, 2nd Floor, 31 Redchurch Street, London E2 7DJ, United Kingdom.