We collect the minimum we need to print your order, deliver it and account for it. This page explains what that is, the legal basis for holding it, how long we keep it, and how you can get it back or have it erased.
We do not sell personal data, we do not build advertising profiles, and there is no automated decision-making in how your order is handled.
Card and wallet payments are handled entirely by our payment providers. Card numbers never reach our systems and we cannot store them.
Logo files you upload are used to produce your order and nothing else. We do not publish them or reuse them in marketing without asking you first.
Tap Tiles is the data controller for the personal data described here. We are established in Malta, and we process personal data under the EU General Data Protection Regulation (Regulation (EU) 2016/679) and the Maltese Data Protection Act (Chapter 586 of the Laws of Malta) together with its subsidiary legislation.
For anything about your data be it a copy, a correction, an erasure, or a question about this page, write to the studio and mark it for the attention of data protection. One person handles these and we reply within a month.
Malta's supervisory authority is the Office of the Information and Data Protection Commissioner (IDPC). Section 08 explains how to complain to them.
We ask for as little as an order needs. The right-hand column is the lawful basis under Article 6 GDPR that lets us hold each item.
If you do not give us the items marked Contract we cannot take the order, because we cannot produce or deliver it. Everything else is optional.
Artwork you upload is used to make your order and to produce the digital proof you approve. We keep the file with the order record so we can reprint from the same source if you order again or if something needs replacing under the guarantee.
We do not licence, sell or publish your artwork. If we would like to show your build in the gallery or on social media, we ask you first and you are free to say no. Ask us to delete an uploaded file at any time and we will, unless we still need it for an open order or a tax record.
Card, Apple Pay, Google Pay and Revolut Pay payments are processed by regulated payment providers acting as independent controllers for the payment itself. You enter your card details with them, not with us. We receive only the confirmation described in section 02.
Those providers run their own fraud checks under their own privacy notices and financial-crime obligations. We cannot see or store your full card number, and we cannot charge a stored card without you authorising it.
The site keeps your bag, your configurator build and your proof state in your browser's local storage. That is strictly necessary to give you the shop you asked for, so it does not need consent under the Maltese Processing of Personal Data (Electronic Communications Sector) Regulations.
Anything beyond that analytics or measurement cookies , is only set if you agree, and you can withdraw that agreement at any time by clearing site data in your browser or telling us. We use no advertising or cross-site tracking cookies.
Clearing your browser data will empty your bag and any unsaved build. Your placed orders are unaffected.
We share the minimum needed, with parties who process it on our instructions under a written data-processing agreement:
Filament suppliers receive colour references, never your personal data. We do not sell or rent personal data to anyone, for any purpose.
Your data is processed inside the European Economic Area wherever possible. Where a provider processes data outside the EEA, the transfer relies on an adequacy decision of the European Commission or on the Commission's Standard Contractual Clauses, with additional safeguards where they are needed.
When a retention period ends we delete the data or anonymise it so it can no longer identify you.
Under the GDPR and the Data Protection Act you can ask us to:
Requests are free and we answer within one month, extendable by two months for complex requests, in which case we tell you why. We may ask for enough information to confirm who you are before releasing data.
If you are not satisfied with how we handle it, you can lodge a complaint with the Office of the Information and Data Protection Commissioner in Malta, or with the supervisory authority in your own EU country of residence. You can also seek a judicial remedy.
Access to order records is limited to the people who need it to produce and ship your order. Data in transit is encrypted, files are held on access-controlled systems, and payment credentials never touch our infrastructure. If a breach ever poses a risk to your rights, we notify the IDPC within 72 hours and tell you directly where the law requires it.
Our products are sold to businesses and adults. We do not knowingly collect data from children, and the site is not directed at them.
If this policy changes we update the effective date at the top and, for anything material, tell customers with an active order by email.
This policy is provided in good faith as a plain-language description of how Tap Tiles handles personal data under Regulation (EU) 2016/679 (GDPR) and the Data Protection Act (Cap. 586). It is not legal advice, and it does not limit any right you have under data protection law.
We answer every request ourselves, and always within a month.