Four cookies, all first-party, three of them strictly necessary. Nothing at all is set on the devices of people who scan your cards.
Last updated 1 Aug 2026
This is a template, not legal advice
These terms ship with the TapCard codebase as a realistic starting point. They have not been reviewed by a lawyer and they are not tailored to your business, your jurisdiction or your actual practices. Have them reviewed before you launch publicly — particularly the sections on liability, refunds and personal data.
| Name | Purpose | Lifetime | Type |
|---|---|---|---|
tc_session | Keeps you signed in. Contains a signed token pointing at a server-side session record, not your details. HttpOnly, so JavaScript cannot read it. | 30 days | Strictly necessary |
tc_cart | Remembers what is in your basket. Contains product variant ids and quantities only — no prices, no personal data. Readable by the page so the basket count updates instantly. | 30 days | Strictly necessary |
tc_aid | A random identifier that lets us tell “one person browsed then bought” from “two people”. Not linked to your identity, never shared, never used across other sites. | 12 months | First-party analytics |
tc_recent | Lets you see the confirmation page for an order you just placed as a guest, without signing in. Holds up to five order numbers. HttpOnly. | 30 days | Strictly necessary |
Notably, we set nothing at all on the devices of people who scan your stands. The /go/ redirect issues no cookie, records no IP address, and sends a no-referrer header so the destination is not told which card sent the visitor. See the privacy policy for the full detail.
When you pay by card you are sent to the payment provider’s own hosted page. That page is theirs, sets its own cookies, and is governed by its own policy — Stripe or Paystack depending on how this store is configured. We do not control what happens there, and we never see your card details.
Every browser lets you view, block and delete cookies. Blocking the two strictly necessary ones will break this site in predictable ways: you will not stay signed in, and your basket will empty on every page load.
If you want the analytics identifier gone specifically, delete the tc_aid cookie for this site. Nothing else will change.
This codebase supports Google Analytics 4 and Plausible. Both are off unless an environment variable supplies an id, and the loader script is not sent to the browser at all when they are off.
Google Analytics sets its own cookies and, in most jurisdictions, requires prior consent. If you enable it, you need to add a consent banner and update this page. Plausible sets no cookies and generally does not.
Current status: No third-party analytics are enabled on this deployment.
TapCard.pk
Johar Town, Lahore, Punjab, Lahore 54782, Pakistan
shoptapcard@gmail.com · +92 300 1234567