Qtap is a loyalty platform for small and independent businesses. This document explains what we do with personal data that belongs to you as a Qtap merchant, including the business owner, authorized signatories, and any staff members who use the Qtap Dashboard.
Qtap is operated by Qtap Inc. , registered in Doha, Qatar. This is the entity that acts as the controller of your personal data for the purposes of this policy. Our parent company is Qtap Loyalty LLC , registered in Delaware, USA. The parent company does not directly process your personal data.
You can reach us at:
This policy is written to comply with Qatar's Personal Data Privacy Protection Law (Law No. 13 of 2016, the "PDPPL"), the EU General Data Protection Regulation ("GDPR"), and comparable data protection laws.
This policy applies to you if you are:
If you are a customer using the Qtap mobile app, a different privacy policy applies, published at qtap.qa/legal/privacy.
If you are wondering how customer data is handled when a merchant uses Qtap, that is covered by the Customer Privacy Policy and the Qtap Data Processing Addendum, not by this document.
Under PDPPL and GDPR, we must tell you the legal basis for each use.
| What we do | Legal basis |
|---|---|
| Running your merchant account and your subscription | Contract (Merchant Services Agreement) |
| Billing you and processing payments | Contract plus legal obligation for tax and accounting |
| Providing support | Contract plus legitimate interest in running the service |
| Sending you service updates, downtime alerts, and billing notifications | Contract |
| Sending you product news, newsletters, and promotional messages | Consent (you can opt out at any time) |
| Preventing fraud, abuse, and security incidents | Legitimate interest |
| Meeting tax, accounting, and commercial record-keeping laws | Legal obligation |
| Improving our service through aggregated analytics | Legitimate interest |
You can withdraw any consent you gave, such as for newsletters, at any time. Withdrawal stops the use from that point forward and does not affect anything that already happened.
We share your data only with the companies that help us run the service for you, and only for the purposes below.
| Who | What they do | Where |
|---|---|---|
| Supabase Inc. | Database and authentication hosting | United States |
| Stripe | Processes your subscription payments and stores your payment method | United States |
| Resend | Sends transactional and billing emails | United States |
| Twilio | Sends SMS notifications where you have opted in | United States |
| Sentry | Captures error and crash reports | United States |
| PostHog | Dashboard analytics (which features get used) | United States or EU |
| Accounting and legal advisors | Tax filings, audits, and legal advice | Qatar and other countries |
We do not sell your data. We do not share it with advertising networks. We do not share it with other merchants.
We will disclose data when a court or competent regulator orders us to, when we have a legal obligation to report something, or when we need to protect someone's safety. Where permitted, we will notify you before we do.
If Qtap is acquired or merges with another company, your data may be transferred as part of the business assets. We will notify you before such a transfer and give you the chance to close your account if you object.
Your data is processed in Qatar, the United States, and the European Union, depending on which of our service providers is handling it at a given time.
Transfers outside Qatar are protected by:
If you are based in the European Economic Area, the United Kingdom, or another jurisdiction with strict cross-border rules, you can request a copy of the specific safeguards for any transfer by emailing privacy@qtap.qa.
| Category | Retention |
|---|---|
| Active account data | For the duration of your subscription |
| Billing records and invoices | 10 years (minimum required by Qatari tax law) |
| Support communications | 3 years after the last interaction |
| Login logs | 2 years |
| Marketing consent records | 3 years after withdrawal |
| Data after account termination | Personal identifiers deleted within 30 days, except where law requires longer retention |
For what happens to customer data when your merchant account is closed, see the DPA and the Customer Privacy Policy.
Under PDPPL and GDPR, you have the following rights:
Email privacy@qtap.qa to exercise any of these rights. We respond within 30 days. If the request is complex, we may extend by another 30 days and tell you why.
Some of your data is tied to the business you represent, not to you personally. If your role at the business ends (for example, you leave the company), the business may continue to hold the account. In that case, requests about business data need to come from the current authorized signatory.
We apply the following security practices:
Staff accounts you create are your responsibility. Use strong passwords, enable MFA where available, and revoke access for staff who leave your business.
The Qtap Dashboard uses cookies and similar technologies to keep you logged in, remember your preferences, and understand how the dashboard is used. A separate cookie notice is available at qtap.qa/legal/cookies and in the dashboard footer.
The Qtap Dashboard is for use by businesses and adult staff members only. You must be at least 18 years old to use it.
When we change something material, we will:
Minor updates (typos, formatting) go live immediately and are reflected in the "Last updated" date at the top.
If you prefer to contact the Qatar regulator directly, the NCGAA can be reached at https://assurance.ncsa.gov.qa.