1. Overview
CosmoOps Tap is a Smart Contact Link product operated by CosmoOps (OPC) Private Limited (Puducherry 605001, India): you create a digital profile, we generate a public link for it (cosmo-tap.app/p/your-username), and anyone with that link can view your profile and save your contact details to their phone as a vCard.
This policy covers the account data, profile data, and usage data involved in running that product.
2. Information We Collect
Account information: your name, email address, and a securely hashed password when you sign up.
Profile information you choose to add: display name, bio, phone number, avatar image, and social links. All of these fields are optional except display name and email.
Usage information: pages visited and basic device/browser information, collected in aggregate through Google Tag Manager for product analytics.
3. How We Use Your Information
To create and operate your account and public profile card.
To generate your shareable public link and the downloadable vCard (.vcf) contact file.
To understand aggregate usage patterns so we can improve the product.
To send essential account-related notices, such as password reset confirmations.
4. Public Profile Visibility
The purpose of CosmoOps Tap is to let you share a public profile, so any field you fill in — display name, bio, phone number, avatar, or social links — is visible to anyone who opens your public link. Fields you leave blank simply don't appear on the card.
You control this visibility directly: add, edit, or remove any profile field at any time from your dashboard, and the public link updates immediately.
5. Where Your Data Is Stored
Account and profile records live in Cloud Firestore (Google Firebase), organized into separate collections for accounts and public profile data.
Avatar images are stored in Firebase Storage and served over HTTPS.
All reads and writes to this data go through our server using the Firebase Admin SDK — your browser never talks to Firestore or Storage directly.
6. How We Protect Your Data
Passwords are never stored in plain text. Each password is hashed with a unique per-user salt (scrypt) before it touches our database.
Sessions are managed with a signed, HttpOnly, Secure session cookie — not exposed to client-side scripts and rejected if tampered with.
All traffic to and from CosmoOps Tap is encrypted in transit over HTTPS/TLS.
7. Data Retention
We keep your account and profile data for as long as your account remains active.
Password reset requests expire automatically after a short window and cannot be reused once expired or used.
If you delete your account, your profile is taken down from its public link and the underlying records are removed within a reasonable period.
8. Your Rights and Choices
You can view, edit, or delete your profile information at any time from your dashboard.
To request full account deletion or a copy of your data, contact us using the details below.
9. Cookies
CosmoOps Tap uses a small number of cookies to keep you signed in and to understand product usage. See our Cookie Policy for details.
10. Children's Privacy
CosmoOps Tap is not directed at children and we do not knowingly collect information from children under the age required by applicable law in their jurisdiction.
11. Changes to This Policy
We may update this policy as the product evolves. Material changes will be reflected by updating the "Last updated" date above.
12. Contact Us
Questions about this policy can be sent to hello@cosmoops.com.