Who
User accounts, roles and staff identifiers help show who completed or reviewed the work.
Trust & security
TapTick is designed to control who can access your operation, protect data in transit and keep the record of what happened connected to what was done next.
No internet service can promise absolute security. TapTick uses proportionate controls and transparent terms for the data involved.
Trust in the record
For food safety, a trustworthy system must also make the operational record easy to understand: who completed the work, when it happened, what was found and how an exception was resolved.
User accounts, roles and staff identifiers help show who completed or reviewed the work.
Timestamps and scheduled work help place each record in its operational context.
Checks, readings, comments, photos and site events build a clearer account than an isolated tick.
Corrective actions, rechecks, manager review and resolutions keep the response connected to the original issue.
Application controls
TapTick combines individual authentication with site and organisation membership. Staff, managers and administrators receive different capabilities, and sensitive access rules are checked by the application rather than relying only on hidden buttons.
Authorised users sign in through managed authentication rather than sharing a public admin area.
Operational staff, site managers and wider organisation roles are given access appropriate to their responsibilities.
Application services verify the user’s permitted sites and roles when protected data or actions are requested.
Teams can be added through controlled invitations and managed from the relevant site or organisation area.
Infrastructure
TapTick uses managed providers for hosting, application services, database infrastructure, transactional email and payments. This lets us use specialist platforms rather than attempting to reproduce every security capability ourselves.
Hosts and delivers the TapTick application and runs the server-side functions used by the service.
Provides managed PostgreSQL infrastructure for customer accounts, site configuration and operational records.
Delivers transactional messages such as invitations, alerts and service communications.
Processes payment information and provides billing services without TapTick storing full card details.
TapTick source changes are managed through GitHub and deployed to the production service through Netlify.
Clear about certification scope: some infrastructure providers maintain independent security certifications and assurance programmes. Those certifications apply to the provider and do not mean TapTick itself is separately certified.
Privacy and ownership
As between the customer and TapTick, customers retain ownership of the operational data entered into the service. TapTick processes that data to provide, secure, maintain and support the service. We do not sell personal data.
Documentation
The Trust & Security page explains the approach. The legal documents provide the contractual and data-protection detail.
How personal data is collected, used, shared and retained.
Read policy → InfrastructureThe principal providers used to deliver the TapTick service.
View providers → GDPRProcessor terms for customer organisations using TapTick.
Read DPA → ContractCustomer data, service availability, retention and account terms.
Read terms →Need more detail?
Tell us what your organisation needs to review and we will respond with the most relevant information available.
Try TapTick in your own site
30 days free, no credit card required. Then €25 per active site/month, excluding VAT.