Legal

Privacy Policy

This policy describes how NobleTap collects, uses, and protects information in connection with our kiosk platform, client dashboard, and mobile application.

Last updated: August 30, 2026

1. What NobleTap Is

NobleTap ("we," "our," or "us") provides a tap-to-give kiosk platform for schools, faith groups, nonprofits, and community organizations. Our platform includes physical kiosk hardware, a web-based client dashboard at app.getnobletap.com, and a companion mobile application ("NobleTap Mobile") for authorized organization staff.

NobleTap Mobile lets authorized staff review donation activity, hardware and display status, and fund performance; administer Monthly Giving and Quran Class records; manage connected devices, displays, and prayer settings; receive push notifications; and compose organization email — including AI-assisted email drafting and AI flyer generation. NobleTap does not act as a payment processor; donations are processed by Stripe into your organization’s connected account.

This Privacy Policy applies to NobleTap’s client-facing services, including the client portal, the NobleTap Mobile iOS application, and this website.

2. Information We Collect

Account information. Your name, email address, a user identifier, and the organizations you are authorized to access. Accounts are provisioned by NobleTap or your organization; the app does not offer self-service sign-up.

Content you create. Email descriptions, event details, tone, language, and template selections; flyer instructions; email subjects and bodies; audience selections; and images you attach by link.

Images you select. Photos or image files you choose from your photo library or Files as a flyer reference. The app converts your selection on-device into a size-limited copy with camera metadata (such as location and device details) removed before upload; your original photo is never modified.

Generated content. Flyers and email drafts produced at your request.

Records your organization’s staff enter. Donor and family records for Monthly Giving and Quran Class administration — such as names, email addresses, phone numbers, and mailing addresses — along with donation and subscription activity associated with your organization.

Device information. A push-notification token and a device identifier when you enable notifications, and administrative records for kiosk hardware and displays your organization operates.

3. AI Features & OpenAI

When you use AI email drafting or AI flyer generation, NobleTap shows a consent prompt before anything is shared. Content flows through NobleTap’s servers and is shared with OpenAI only after you accept that prompt. Selecting Not Now cancels that request: NobleTap does not submit it or share its content.

  • For flyers: your flyer instructions and any reference image you selected.
  • For emails: your email instructions and setup choices — including event details, tone, language, template, general audience setting, and any included image links.
  • Your recipient list is not included in OpenAI generation requests.
  • No email is sent automatically. Sending always requires your separate, manual action.

NobleTap has not opted into sharing OpenAI API content for model improvement. OpenAI may retain API data for abuse monitoring for up to 30 days, subject to documented legal or safety exceptions.

4. Storage & Hosting

NobleTap’s application runs on Render, and data is stored with Supabase.

  • Reference images are stored in a private bucket while your flyer is generated and are deleted when the generation job completes, with a recurring cleanup for jobs that end unexpectedly.
  • Generated flyers are stored in a bucket that is public by link: listing its contents is denied and the links use long random identifiers, but anyone who possesses a valid link can retrieve that image while it remains stored. This is what allows a flyer to display inside delivered emails.
  • Your flyer instructions and job details (status, timestamps, and identifiers linked to your user and organization) are retained with the job record.

5. Email Delivery

When you choose to send an email, delivery is performed by GoHighLevel (LeadConnector) on your organization’s behalf. Emails are sent only when you trigger them.

6. Payment Processing

Donations are processed by Stripe. Card details are entered on and handled by Stripe’s systems; NobleTap displays donation records — such as amounts, funds, timestamps, donor names or emails where provided, and card brand — for your organization’s administration.

7. Face ID & Notifications

Face ID. If you enable Face ID unlock, authentication is performed entirely by iOS on your device. NobleTap receives only a success or failure result; no biometric data is collected, transmitted, or stored by NobleTap.

Push notifications. If you enable notifications, a push token for your device is stored so NobleTap can deliver alerts (for example, donation and device-health notifications) through Apple’s push service. You can disable notifications at any time in iOS Settings.

8. What We Don't Collect

The NobleTap Mobile app contains no advertising, no third-party analytics or crash-reporting SDKs, and does not use the iOS advertising identifier (IDFA) or App Tracking Transparency, because it does not track you across other companies’ apps or websites.

The app does not access your contacts, microphone, camera, or precise location.

9. Security

Traffic between the app, NobleTap’s servers, and our processors uses HTTPS/TLS. Access to organization data requires authentication, and each account can access only the organizations it belongs to. Private storage buckets are not readable without authorization, and database access is restricted with row-level controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Data Retention & Deletion

Account and organization records are retained while your organization uses NobleTap. Reference images are deleted when flyer generation completes, as described above. Generated flyers, email drafts, flyer instructions, and job records are retained until deleted upon request.

To request access to or deletion of your information — including generated flyers or job records — contact app.nobletap@gmail.com. Deleting a flyer that was already embedded in a delivered email removes the hosted image, so it will no longer display in copies of that email.

11. Your Choices

  • Decline any individual AI request by selecting Not Now — that request is not submitted and its content is not shared.
  • Use NobleTap without the AI features entirely.
  • Disable push notifications in iOS Settings.
  • Disable Face ID unlock in the app’s settings.
  • Contact app.nobletap@gmail.com about access, correction, or deletion.

12. Children's Privacy

NobleTap Mobile is intended for authorized adult staff of subscribing organizations and is not directed to children. Records that organizations maintain about program participants (such as Quran Class enrollment) are entered and managed by the organization’s own staff.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will update the "Last updated" date at the top of this page, and for significant changes we may provide additional notice.

14. Contact

Questions or requests about this policy: app.nobletap@gmail.com.