Privacy policy

Privacy policy

Version 1.0. Effective September 29, 2026. Last changed September 29, 2026.

VIC2RY, INC. ("we", "us"), a Canadian corporation, operates tapsplain at tapsplain.com. This policy says what personal information we collect, why we have it, where it goes, how long we keep it and what you can make us do about it.

Every request in this policy goes to info@vic2ryconsulting.com, or by post to VIC2RY, INC. (o/a tapsplain), Suite 200, 140 Yonge Street, Toronto, Ontario M5C 1X6, Canada.

1. Whose information we hold

Four groups, with different rules for each.

  1. Business owners who buy tapsplain (clients): name, email, phone, business name, billing address, Google Business Profile link, logo, and the answers on the intake form. Card numbers go to Stripe and never reach us; we see the last four digits and the card brand.
  2. Sales partners: name, email, phone, province, e-Transfer address, the agreement they accepted with the time and IP address, the result of an identity check, and a Social Insurance Number where a T4A is required.
  3. Customers of our clients, who use a feedback page. Most give us nothing that identifies them: a set of taps and, sometimes, a comment. If a customer asks the business to contact them, they choose to type a name and a phone number or email.
  4. Visitors and people who use our free tools: your email if you ask us to send you something, the business name you looked up, and, if you ticked the box, the consent record for the follow-up emails.

2. Why we have it

  • Clients: to take payment, build and run the page, email responses and reports, send renewal reminders, answer support, and keep the records tax law requires.
  • Sales partners: to check who you are, pay commission, issue tax slips, keep your acceptance record, and run the program. Stripe performs the identity check. We keep the result and the name Stripe read off the document. We never receive or store the image of your ID or your selfie.
  • Customers of our clients: we collect this on the client's behalf. The client is the organisation accountable for it and we act as their service provider, handling it only to deliver the service. A name and contact detail goes to that business and nobody else.
  • Visitors: to send you what you asked for, and, only if you ticked the box and then confirmed by clicking the link in the first email, three short follow-up emails. Each one has an unsubscribe link.

We don't sell personal information. We don't use it for advertising, and we put no advertising or analytics trackers on feedback pages.

3. Consent, and taking it back

You give us most of this by choosing to type it in. You can withdraw consent at any time by writing to us, except where we're required to keep something (a tax record, an acceptance record for an agreement you signed). Withdrawing consent may mean we can't keep providing the service, and we'll tell you plainly when that's the case rather than quietly degrading it.

Unsubscribing from marketing email is one click and takes effect immediately. It doesn't stop the transactional email your service depends on, such as a response notification or a renewal reminder.

4. Cookies, storage and fonts

  • A session cookie when you log into the partner or admin area. It expires when you log out.
  • A referral cookie named `tp_ref`, set when you arrive through a client's referral link, holding the referral code for 365 days so the discount applies when you order.
  • Local storage on feedback pages, which keeps a customer's answers in their own browser for up to 24 hours so a refresh doesn't lose them. It never leaves the device except as part of a submission.

No analytics cookies, no advertising cookies, no cross-site tracking, no profiling. We don't use technology that identifies, locates or profiles a person.

Our pages load the Nunito typeface from Google Fonts, so your browser contacts Google's servers and Google can see your IP address as part of that request.

5. Where it is stored, and who else handles it

Our servers and our providers may be located in Canada, the United States or the European Union (for example, Germany). If you are in Canada, that means your information may be stored and processed outside Canada, where the courts and authorities of those countries can compel access under their own laws. We put contractual protections comparable to our own on every provider before sending anything.

  • Stripe, to take payments and to verify the identity of sales partners.
  • Resend, to send responses, reports and receipts.
  • Google (Places API), for business lookups in our sales tools. We keep a business name, address, rating, review count and place ID, and refresh them rather than reuse anything older than 30 days.
  • An AI model provider, reached through our own gateway, to write the short narrative in a monthly report and to draft sales emails. It receives aggregated scores and counts, and comment text with phone numbers and email addresses stripped out first.
  • Our hosting provider, which runs the servers everything above sits on.

Two limits on the AI provider worth stating plainly: we never send it the contact details a customer leaves for a call back, and our agreement does not permit our data to be used to train anyone's model.

We also disclose information where the law requires it, and we will tell you when that happens unless we're prohibited from doing so.

6. How long we keep it

  • Responses from clients' customers: 24 months, then de-identified. Contact details and free text come out; scores and counts stay.
  • Client and order records: the relationship, plus 7 years, because tax and limitation rules require it.
  • Sales partner records: 7 years after the relationship ends.
  • Leads from free tools: 24 months after your last contact with us, and sooner if you never confirmed your email.
  • Unsubscribe and do-not-contact records: indefinitely, because keeping the record is the only way to keep honouring the request.

7. How we protect it

Contact details left on feedback pages are encrypted in our database. All connections use HTTPS. Admin access needs a password and is logged. Passwords are stored as one-way hashes, never recoverable. Backups are encrypted.

No system is perfectly secure. We keep a register of confidentiality incidents. Where a breach creates a real risk of significant harm, we report it to the Privacy Commissioner of Canada, tell the people affected, and tell any client whose customers' information was involved so they can meet their own obligations.

8. Your rights

Ask us for the personal information we hold about you, ask us to correct it, or ask us to delete it. Email info@vic2ryconsulting.com. We answer within 30 days and we don't charge for it. We may ask you to confirm who you are before we hand anything over, and we'll ask for no more than we need to be sure.

If you left your details on a client's feedback page, send the request to that business, because they're the ones accountable for it. If you'd rather send it to us, we'll pass it on and help them answer.

Unhappy with our answer? Complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca, or to your provincial commissioner.

If you live in Quebec, Law 25 also gives you the right to have information transferred to you in a structured, commonly used technical format, and the right to be told when a decision about you is made only by automated means. We make no such decisions: every report narrative is a summary of numbers you can see for yourself, and nothing on our side decides anything about a person.

9. Children

Feedback pages are for the general public and never ask for a date of birth. Our own services are sold to businesses and are for adults.

10. Automated tools and the report narrative

The monthly report contains a short written summary produced by a language model from your own aggregated numbers and comments. It summarises, it doesn't decide, and the numbers behind it are printed next to it in the same report so you can check the claim.

11. Changes

When this policy changes we update the version and both dates at the top. For changes that matter, we email clients and partners before they take effect.

12. Who to contact

The person responsible for protecting personal information at VIC2RY, INC. is the President, Amirehsan Sajad, reachable at info@vic2ryconsulting.com or at the postal address above. Write to that address for access, correction, deletion, a complaint, or a question about this policy.