Tag Docket

Legal

Privacy Policy

What we collect, why, who else processes it, and what we deliberately don’t hold.

Draft. This policy has not yet been reviewed by a lawyer. It describes how Tag Docket handles data today, as accurately as we can put it. Questions in the meantime: hello@tagdocket.com.

Effective: [CONFIRM] date of publication

Tag Docket is operated by MM Sanford, LLC. For data an agency puts into Tag Docket about its clients and campaigns, the agency decides what goes in and we process it on the agency’s behalf. For account, billing and contact data, we are responsible for it directly. [CONFIRM controller/processor roles and whether a data processing agreement is offered.]

What we do not store

  • Passwords. There are none. You sign in with a link emailed to you.
  • Who scanned a code. A short-code scan adds one to that code’s count and updates its last-scanned time. We do not store the scanner’s IP address, device, browser or location. The browser’s user-agent string is read at the moment of the redirect only to leave link-preview bots and crawlers out of the count, and is not kept.
  • Trackers. We run no third-party analytics, advertising trackers or session recorders on this site or in the app.

Information you give us

  • Account data. Your name, work email, the agency you belong to, your role and which clients you can reach. Sign-in links are sent and verified through Firebase Authentication, a Google service.
  • Registry content. Clients, campaigns, your taxonomy of dimensions and values, pairing rules, templates, and the links, short codes and QR codes you make, including their destinations. Each change is recorded in an audit trail with the email address of the person who made it, and stays attributed to them after they leave the agency.
  • Imported files. Spreadsheets you import, as the rows you choose to write.
  • Branding. For the white label, the agency website you paste in, and the colour and logo taken from it.
  • Messages you send us. Anything you write in the contact form or by email, along with the agency you tell us about.
  • Billing data. Paid plans are billed through Stripe. Card details are entered on Stripe’s systems and never reach ours. We keep a customer reference, your plan and your subscription status.

Google Analytics 4 connections

Each agency has its own Google service account; none is shared between agencies. It can read a client’s GA4 property only after someone with admin rights on that property adds it by hand in GA4. We cannot grant ourselves access, and removing the service account in GA4 revokes it at once. We use that read access to verify the connection and to evaluate how the client’s campaign traffic was tagged. [CONFIRM what GA4 report data, if any, is stored and for how long.]

Pages we fetch for you

The landing-page check fetches the destination you enter, to see whether it loads, redirects, carries an analytics tag or already has UTM parameters. The white-label check fetches the agency website you paste in. Both fetch only public web pages at the address you supply, identify themselves in the request, and refuse private and internal network addresses.

Information collected automatically

  • Short-code scans. A count and a last-scanned time per code, as described above. Nothing about the person scanning.
  • Hosting logs. Our hosting provider’s standard request logs record details such as IP address, browser and time for operating and securing the service. [CONFIRM log retention.] Contact-form submissions store a one-way hash of the sender’s IP rather than the address, which is enough to limit abuse.
  • Browser storage. Only what signing in requires, plus conveniences such as remembering the email address you last used. No advertising or analytics cookies, so there is no consent banner.

This site loads its typefaces from Google Fonts, so your browser fetches those files from Google and Google sees the request.

How we use it

To run the service, send sign-in links, answer you when you get in touch, bill you, and keep the system secure and working. We do not sell personal data, we do not share it for advertising, and we do not use registry content to train machine-learning models.

Who else processes it

  • Google Cloud (Cloud Run, region us-east5, Ohio) hosts the app.
  • Firebase Authentication (Google) sends and verifies sign-in links.
  • Neon hosts the Postgres database, on AWS in us-east-2 (Ohio).
  • Stripe processes payments for paid plans.
  • Google Analytics Data API is used for the GA4 connections your agency sets up.
  • Firebase (Google) hosts this website and stores contact-form submissions, and Resend delivers those submissions to our inbox.

Each processes data only to provide its service to us. We will update this list before adding another, and note the change in the effective date above.

Keeping agencies separate

Each agency’s data is scoped to that agency. A member list never shows which other agencies a person belongs to, and a member limited to certain clients cannot see that other clients exist.

Export and moving to another agency

Records about a client belong to that client. An agency can export a client’s records at any time, free, in a readable format with values written out in full. If a client moves to another agency on Tag Docket, the receiving agency requests the transfer and the client approves it with a one-time approval link for their own email address. [CONFIRM how that link is delivered.] Once approved, the client’s records move to the receiving agency, and the outgoing agency keeps a read-only archive of the work it did.

How long we keep it

Registry content is kept while the agency’s account exists. Cancelling a plan deletes nothing, and retiring a client archives it rather than deleting it, because printed codes must keep resolving. [CONFIRM: deletion on a written request to close an account, and how long backups persist afterwards.]

Contact-form messages are kept while they are useful for the conversation they belong to, and deleted when they are not. [CONFIRM a period.]

Your rights

You can see and export your agency’s data from inside the app at any time, and ask us to correct or delete personal data about you. If you are a client of an agency that uses Tag Docket, ask that agency first; we will help them answer. Depending on where you are, laws such as the GDPR or the CCPA may give you further rights, including the right to object or to complain to a supervisory authority. Ask us and we will help you exercise them.

Where data is held

Tag Docket runs in the United States. If you are outside the United States, using the service means your data is processed there. [CONFIRM transfer mechanism for EU/UK users.]

Children

Tag Docket is a business tool and is not directed to anyone under 18.

Changes to this policy

We post changes here and update the effective date. We email account owners about material ones before they take effect.

Contact

Privacy questions, or a request about your own data: hello@tagdocket.com. MM Sanford, LLC, Green Bay, WI.