Back to home

Privacy Policy

Last updated: June 29, 2026

This Privacy Policy explains how Griffith Software Labs LLC, a limited liability company organized under the laws of the State of Wyoming, USA, which operates the Tapline service ("Tapline", "we", "us", "our"), collects, uses, and shares personal data when you visit tapline.sh, create an account, or use our market-data API and related services (the "Services"). It also describes your rights and how to exercise them.

For the personal data described here, Tapline is the data controller. Our payment processing is handled by Stripe (see Section 5), which processes payment data on our behalf and acts as an independent controller for the payment-card and fraud-prevention data it collects.


1. Who this applies to

This policy applies to visitors to our website and to customers and authorized users of the Services. It does not apply to third-party websites or services we link to, which have their own policies.

2. The personal data we collect

Information you provide:

  • Account data — name, email address, company name, and account credentials when you register.
  • Billing data — name, billing address, and country, and the transaction records associated with your purchases. Card and payment-instrument details are collected and processed by Stripe, not by us; we do not store full payment-card numbers.
  • Enquiry data — when you contact us (for example, by email), the name, email address, company, and any message you choose to provide so we can respond.
  • Communications — the content of messages, support requests, and feedback you send us.

Information collected automatically:

  • Technical and usage data — IP address, browser type, device and operating-system information, referring pages, the API endpoints and dashboard features you use, request volumes, timestamps, and log data, collected to operate, secure, and improve the Services.
  • Cookies and similar technologies — see Section 9.

3. How the API itself handles data

The Services return structured data from publicly visible Airbnb and YouTube pages — including listing attributes, nightly rates, availability, reviews, transcripts, video metadata, comments, channels, playlists, formats, and engagement data. The Services are built to deliver content- and market-level data for software products, analytics, pricing, and monitoring, not to profile or identify individuals. Some outputs — for example, public guest reviews or video comments — may include limited personal data, such as a display name or the text of a review or comment, that the source has already made publicly available. We do not enrich, cross-reference, or use this data to identify individuals or to build advertising profiles, and we do not sell it; we process API requests only to fulfil your query and to keep operational logs. Where an output contains personal data, you act as the controller for your use of that output and are responsible for handling it lawfully — including providing any required notices and establishing a legal basis — as set out in our Terms of Service.

4. How and why we use personal data

PurposeExamplesLegal basis (GDPR/UK GDPR)
Provide the ServicesCreate and manage your account, authenticate API keys, deliver responsesPerformance of a contract
Billing and paymentsProcess subscriptions and renewals via Stripe, maintain transaction recordsPerformance of a contract; legal obligation
Support and communicationRespond to requests, send service and security noticesPerformance of a contract; legitimate interests
Security and fraud preventionDetect, investigate, and prevent abuse, fraud, and unauthorized accessLegitimate interests; legal obligation
Improve the ServicesAnalyze usage trends, debug, and develop featuresLegitimate interests
Advertising measurementMeasure website traffic and attribute sign-ups and subscriptions to our ads via Google Analytics and Google AdsLegitimate interests (consent where required)
Marketing (optional)Send product updates where you have opted inConsent (withdrawable at any time)
Legal complianceMeet tax, accounting, and other legal obligations; respond to lawful requestsLegal obligation

Where we rely on legitimate interests, we have balanced those interests against your rights.

5. How we share personal data

We do not sell your personal data. We share it only with the following categories of recipients, and only as needed:

  • Stripe — our payment processor, for checkout, billing, and fraud prevention. See Stripe's Privacy Policy.
  • Hosting and infrastructure — Hetzner Online GmbH (Germany), to host and run the Services.
  • Google (Analytics & Ads) — Google Analytics 4 and Google Ads, to measure website traffic and the performance of our advertising. We share a Google Click ID (GCLID) and, on sign-up and subscription, a hashed (irreversible) version of your email address via Google's Enhanced Conversions, so we can attribute conversions to the ad that referred you. See Google's Privacy Policy.
  • Professional advisers and authorities — lawyers, accountants, auditors, and regulators or law enforcement where required by law or to protect our rights.
  • Business transfers — a successor entity in connection with a merger, acquisition, or sale of assets, subject to this policy.

Other than the Google Analytics and Google Ads measurement described above, we do not use third-party email-marketing or customer-support processors; ongoing support is handled directly by our team on our own infrastructure. If we introduce another such provider, we will update this policy and our sub-processor list beforehand. These providers process personal data on our behalf under contracts that require appropriate safeguards. We keep an up-to-date list of sub-processors and can provide it on request.

6. International transfers

We and our providers may process personal data in countries other than yours. Where we transfer personal data out of the UK, EEA, or other regulated regions, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision.

7. How long we keep personal data

We keep personal data only as long as necessary for the purposes above:

  • Account data — for the life of your account and a short period after closure.
  • Billing and tax records — for the period required by applicable tax and accounting law (commonly up to 6–7 years).
  • Technical and log data — typically up to 12 months, unless needed longer for security or legal reasons.
  • Marketing data — until you opt out or after a period of inactivity.

We may retain anonymized or aggregated data, which no longer identifies you, without time limit.

8. Your rights

Depending on where you live, you may have the right to: access a copy of your personal data; correct inaccurate data; delete your data; restrict or object to processing; data portability; and withdraw consent at any time. To exercise any of these, email [email protected]. We will respond within the time required by applicable law (generally one month under GDPR/UK GDPR, or 45 days under California law).

EEA/UK residents: you may lodge a complaint with your local supervisory authority.

California residents (CCPA/CPRA): you have the right to know what personal information we collect and how we use and disclose it, to request deletion or correction, and to not be discriminated against for exercising these rights. We do not sell or "share" personal information for cross-context behavioral advertising as those terms are defined under California law.

9. Cookies

We use strictly necessary cookies to run the site and authenticate your session. We also use analytics and advertising cookies from Google Analytics and Google Ads to understand site traffic and measure the performance of our advertising — including a Google Click ID stored in a first-party cookie (tap_gclid) for up to 90 days so we can attribute a sign-up or subscription to the ad that referred you. You can manage cookies through your browser settings, opt out of Google Analytics via Google's opt-out browser add-on, and control ads personalization in your Google Account settings. Where local law requires prior consent for non-essential cookies, we will request that consent before setting them.

10. Security

We use technical and organizational measures appropriate to the risk — including encryption in transit, access controls, and monitoring — to protect personal data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

11. Children

The Services are not directed to, and we do not knowingly collect personal data from, anyone under 18. If you believe a child has provided us personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. We will post the new version with an updated date and, for material changes, provide additional notice. Continued use of the Services after the effective date constitutes acceptance.

13. Contact us

Griffith Software Labs LLC (operator of Tapline)

30 N Gould St Ste N, Sheridan, WY 82801, USA

Privacy enquiries and data-rights requests: [email protected]