Privacy

Privacy Policy

This policy explains what data CosmoOps Tap collects when you create a digital profile card, how it's stored, and the choices you have over it.

Last updated: 5 August 2026

1. Overview

CosmoOps Tap is a Smart Contact Link product operated by CosmoOps (OPC) Private Limited (Puducherry 605001, India): you create a digital profile, we generate a public link for it (cosmo-tap.app/p/your-username), and anyone with that link can view your profile and save your contact details to their phone as a vCard.

This policy covers the account data, profile data, and usage data involved in running that product.

2. Information We Collect

Account information: your name, email address, and a securely hashed password when you sign up.

Profile information you choose to add: display name, bio, phone number, avatar image, and social links. All of these fields are optional except display name and email.

Usage information: pages visited and basic device/browser information, collected in aggregate through Google Tag Manager for product analytics.

3. How We Use Your Information

To create and operate your account and public profile card.

To generate your shareable public link and the downloadable vCard (.vcf) contact file.

To understand aggregate usage patterns so we can improve the product.

To send essential account-related notices, such as password reset confirmations.

4. Public Profile Visibility

The purpose of CosmoOps Tap is to let you share a public profile, so any field you fill in — display name, bio, phone number, avatar, or social links — is visible to anyone who opens your public link. Fields you leave blank simply don't appear on the card.

You control this visibility directly: add, edit, or remove any profile field at any time from your dashboard, and the public link updates immediately.

5. Where Your Data Is Stored

Account and profile records live in Cloud Firestore (Google Firebase), organized into separate collections for accounts and public profile data.

Avatar images are stored in Firebase Storage and served over HTTPS.

All reads and writes to this data go through our server using the Firebase Admin SDK — your browser never talks to Firestore or Storage directly.

6. How We Protect Your Data

Passwords are never stored in plain text. Each password is hashed with a unique per-user salt (scrypt) before it touches our database.

Sessions are managed with a signed, HttpOnly, Secure session cookie — not exposed to client-side scripts and rejected if tampered with.

All traffic to and from CosmoOps Tap is encrypted in transit over HTTPS/TLS.

7. Data Retention

We keep your account and profile data for as long as your account remains active.

Password reset requests expire automatically after a short window and cannot be reused once expired or used.

If you delete your account, your profile is taken down from its public link and the underlying records are removed within a reasonable period.

8. Your Rights and Choices

You can view, edit, or delete your profile information at any time from your dashboard.

To request full account deletion or a copy of your data, contact us using the details below.

9. Cookies

CosmoOps Tap uses a small number of cookies to keep you signed in and to understand product usage. See our Cookie Policy for details.

10. Children's Privacy

CosmoOps Tap is not directed at children and we do not knowingly collect information from children under the age required by applicable law in their jurisdiction.

11. Changes to This Policy

We may update this policy as the product evolves. Material changes will be reflected by updating the "Last updated" date above.

12. Contact Us

Questions about this policy can be sent to hello@cosmoops.com.