Point-in-time data, not a route
TapInn verifies position when the employee checks in or checks out. A break is recorded with a timestamp only, without location. We do not build a movement history.
Privacy
TapInn is built for geo-verified working hours without continuous tracking. We use position only when needed for a specific registration, not to follow employees through the day.
This is an English translation provided for convenience; the Norwegian version is the legally binding text.
TapInn verifies position when the employee checks in or checks out. A break is recorded with a timestamp only, without location. We do not build a movement history.
Data is used to document working hours, location, breaks, discrepancies, approval and payroll basis.
The goal is to store what is needed for time tracking and after-the-fact checks, nothing more.
Explained simply
Location is used for specific actions in the app: check-in and check-out. The start and end of a break are recorded with a timestamp only, without location. The purpose is to confirm that the registration happens within the correct work area.
If the employer uses tasks, TapInn can store checklists, comments and photos submitted by the employee themselves. This is used for documentation of completed work or discrepancies.
The employer gets access to the information needed for operations, follow-up and payroll. Employees should be able to see their own registrations and what the hours are based on.
Data is retained as long as needed for the employment relationship, payroll, documentation and statutory requirements -- see the retention periods further down. Deletion and access requests can be sent to TapInn or to the employer.
TapInn's versioned data processing agreement describes data types, instructions, access, security, sub-processors, audit and deletion. The agreement is part of the customer's signing.
The approved payroll basis is exported as a CSV file by the employer. The employer can give its accountant a separate, limited access to the payroll basis.
If you choose to sign in with a passkey (Face ID, Touch ID or fingerprint), the biometric check itself happens on your own device. TapInn only stores a public key and an identifier for the passkey -- never fingerprints or face data.
Privacy notice
Version 2026-08-27, last updated 27 August 2026. This notice applies to the use of TapInn's websites, self-service signup, customer portal, employee app and support. This is an English translation provided for convenience; the Norwegian original is the legally binding version.
APREX AS, org. no. 937 881 444, Åslyveien 19, 3170 SEM, provides TapInn. We are the data controller for information about website visitors, customer and prospect contact persons, support enquiries, and contract and invoice administration. For information about employees who use TapInn at work, the employer (the customer) is the data controller and APREX is the data processor under the Data Processing Agreement -- there it is the employer who determines the purpose, and we process only on their instructions.
Contact details, role and place of work; work sessions, timestamps for check-in, break and check-out, and point-in-time location at check-in and check-out; shift schedule, availability, absence and shift swaps; messages, tasks, comments, photos and documents; sign-in and security data such as password hash, passkey (public key), sessions, IP address at sign-in and device tokens for push notifications. What is actually collected depends on which modules the employer has enabled.
For customer contacts and signing: contract (GDPR Article 6(1)(b)). For security, error correction and aggregated usage statistics: legitimate interest in operating the service safely (Article 6(1)(f)). For accounting and contract documentation: legal obligation (Article 6(1)(c)). For employee data in the employer’s TapInn, the employer must have the basis -- normally the employment contract and the Norwegian Working Environment Act’s rules on working hours and control measures. We do not use consent as the basis for core features, because consent in an employment relationship is rarely free enough.
For customers with billing country Norway, APREX processes invoice details as controller for contract and accounting purposes. For customers outside Norway, when card payment is switched on, Link is the seller and an independent controller for card and transaction data. APREX then does not receive card numbers. Card payment via Link is not switched on in production for this version. Questions about payment go to hei@tapinn.no.
Position data is only used as point-in-time data for specific events. This means we register where you were when you checked in and when you checked out, but not where you move throughout the day. A break is recorded with a timestamp only, without location. We build no route history and no movement profiles.
When the employer creates a location, the address is looked up at Kartverket (the Norwegian Mapping Authority) from our servers, and the map view in the portal is fetched as map tiles from Kartverket. Kartverket then sees the address search and the administrator’s IP address, in the same way as when using kartverket.no. Employee positions are never sent to Kartverket.
The customer’s administrators have access to employee data in their own tenant, including timesheets, shift schedules, absence, messages and reports. Access is role-based, and each customer can only see its own data. The employer can give its accountant a limited access to the approved payroll basis.
Passwords are stored only as a hash. A passkey is stored as a public key and an identifier; the biometrics stay on your device. Repeated sign-in attempts and frequent calls are counted briefly per IP address or user to stop abuse -- the counters are deleted automatically after minutes to hours.
If you contact TapInn support, the request may be logged in our support system via a secure TapInn proxy. Product keys or other sensitive configuration are never exposed directly in the clients.
Customer data: for as long as the customer relationship lasts, then for as long as accounting and contract documentation requires (the Norwegian Bookkeeping Act: five years). Employee data in the employer’s TapInn: for as long as the employer decides within its own legal basis; deletion and anonymisation are carried out on the employer’s instructions or when the customer relationship ends. Trial accounts that are not confirmed may be deleted, after notice, 90 days after the trial period expired. Sessions and tokens: until sign-out or expiry. Security counters: minutes to hours. Copies in backups are phased out in step with the ordinary backup cycle and are only used for restoration.
You have the right to access, rectification, deletion, data portability, restriction, and to object to processing based on legitimate interest. For employee data in the employer’s TapInn, the request is normally directed to the employer; we help with the technical disclosure. We respond within one month.
If you believe we process personal data in breach of the rules, we hope you will tell us first. You always have the right to lodge a complaint with the Norwegian Data Protection Authority, Datatilsynet (datatilsynet.no).
TapInn uses necessary sub-processors for operations, database, usage statistics, email, push notifications, security, support and error monitoring: Vercel, Neon, Vercel Analytics / Speed Insights, CoreDesk, Postmark, Sentry, Redis Ltd, Google Firebase Cloud Messaging, Apple Push Notification service. Production operations at Vercel, the database at Neon and the security counters at Redis run in the EU (Frankfurt, Germany). The full list with purpose, data categories and region is on the sub-processor page.
Two services may involve a transfer outside the EEA: transactional email via Postmark (USA) and push notifications to Android via Google Firebase Cloud Messaging. The basis is the EU Standard Contractual Clauses (SCCs) in the providers’ data processing agreements, with supplementary measures where necessary. No other personal data is transferred outside the EEA.
TapInn uses Vercel Analytics for aggregated, cookieless usage statistics, Speed Insights for anonymous Core Web Vitals, and Sentry for error monitoring without personally identifying default fields. This is used for operations, security and product improvement, not for advertising or the sale of personal data. Vercel measurement is disabled on token-bearing setup, reset, offer and signup pages; Speed Insights is also disabled on internal superadmin pages.
The websites use one cookie for your language choice, and signed-in surfaces use necessary cookies for session and security. No marketing cookies. See the cookie page for names and lifetimes.
Questions about privacy, access or the data processing agreement can be sent to hei@tapinn.no. Please state whether you are contacting us as a private individual, an employee or a customer contact.
Contact
APREX AS is the data controller for TapInn. Questions about privacy, access, rectification or the data processing agreement can be sent to us directly.