Last updated: 19.09.2026
This notice explains how Black Bubble Solutions Ltd trading as Tipd collects and uses personal information through www.tipd.co, app.tipd.co, the Tipd mobile application, payment pages and related support. It covers visitors, guests and donors, Recipients, Team administrators and people involved in identity or business verification.
Black Bubble Solutions Ltd is registered in England and Wales, company number 09553653, at 3rd Floor, 86–90 Paul Street, London, United Kingdom, EC2A 4NE. We are a controller for information we use to operate Tipd, administer accounts, protect the service and meet our own legal obligations. Our data-protection contact is Christopher Anderson at support@tipd.co.
This is an information notice, not a request for blanket consent. Our legal basis depends on the particular activity. Using Tipd or accepting its Terms does not by itself give consent to optional analytics or marketing.
Account and profile information includes names, usernames, email addresses, account credentials, contact information, profile images and text, account settings, Team membership and permissions. We also process check-in and checkout status and related times, including scheduled checkout events, to allocate shared tips.
Verification information may include identity and address documents, date of birth, nationality, bank details, business registration information, business activity and information about representatives, directors, beneficial owners or controllers. The information required depends on the account and the checks needed. Tipd receives documents through the app, sends them to Ryft for verification and removes its copies after five days. An invited business representative or person with significant control may supply information for KYB without receiving a Ryft payment account. Ryft may retain its copies for longer under its own obligations.
Payment records include amounts, currencies, fees, dates, transaction and provider references, payment status, allocations, payouts, refunds and disputes, and information returned by the payment provider to identify and administer payments. Full card details and security codes are handled by Ryft's payment interface and providers; Tipd does not store full card numbers or card security codes in its application database.
Guest information includes any optional name or free-text thank-you message you submit and information you provide for a receipt or support. You do not need to create a Tipd account to pay. If you elect to make a Gift Aid declaration, we collect the declaration and the donor details needed for the recipient organisation's reporting, including name and home address.
Technical information includes IP address, approximate country inferred from IP, browser or device information, access times, service activity and security or error records. On Webflow forms, Cloudflare Turnstile bot protection may analyse browser and interaction signals, such as mouse movements and input activity, to detect automated submissions; Cloudflare states that Turnstile does not access, store or transmit user communications, form entries or other page inputs. Country information can be used to determine the applicable payment fee and tax treatment, as well as for fraud checks. We do not currently collect precise GPS location for Team check-in or allocation. Scanning a QR code or tapping an NFC link opens a page; Tipd does not collect NFC device data as part of that action.
Communications include enquiries, demo bookings, support messages, complaints and evidence you supply. Avoid including sensitive information in a public profile or guest message. If a particular verification process requires biometric or other specially protected information, additional information and the relevant lawful conditions must be provided for that process; ordinary identity or bank information is not automatically special-category data under UK GDPR.
We obtain information directly from you, from your device when you use the service, from Administrators who invite or manage Team members, and from Ryft and other providers involved in processing, verification, security and support. We may review business registers and other lawful public sources to check business legitimacy or investigate misuse. We do not treat publicly available information as free of data-protection requirements.
We use information to create and manage accounts, provide payment pages, allocate tips, administer payouts, deliver messages and answer support requests. Where you are a party to our service contract, the basis is performance of that contract. Where you act for an organisation, we generally rely on our legitimate interests in providing and administering the service to that organisation.
We use relevant account, identity, business and transaction information to prevent fraud, protect funds, verify authority, investigate disputes and enforce proportionate restrictions. We rely on legitimate interests in protecting Payers, Recipients and our business, and on legal obligations where a particular obligation applies to Tipd. A requirement imposed on us by a provider is not automatically a statutory obligation on Tipd. Ryft determines its own lawful bases for checks and records required of it.
We use transaction and administrative records for accounting, tax, legal claims and other record keeping. The basis is compliance with applicable legal obligations, or legitimate interests in maintaining evidence and resolving claims where no specific legal obligation applies.
We process donor declarations and supporting information to provide the requested Gift Aid collection and export facility. The recipient organisation is responsible for its claim and its own use of donor data. Tipd's own purposes include operating and protecting that facility; we rely on legitimate interests for those purposes, subject to donors' rights, and any applicable legal obligations. A Gift Aid declaration is not consent to unrelated marketing.
On our marketing website, www.tipd.co, we use Google Analytics to understand visits, Meta/Facebook Pixel for marketing measurement and advertising-related activity, and Brandjet for website and campaign measurement, recognising visitors or organisations, lead generation and supporting marketing outreach. With your consent, these tools may process online identifiers, IP and device information, pages visited, interactions and referral information. Brandjet may also process visitor and advertising-click identifiers and device characteristics used for fingerprinting. Google Analytics is controlled by the Analytics category; Meta and Brandjet are controlled by the Marketing category. Meta may associate website events with information it holds about you under its own arrangements. We use consent for these optional website technologies and the associated processing; accepting the Terms is not that consent. See the Cookie Policy for providers and controls.
We do not run optional analytics or advertising tracking in the Tipd web application, guest payment pages or native app. Necessary session, payment, security and service records still operate, and we use transaction records for service reporting, accounting and proportionate risk analysis. Those records are not optional website marketing tracking. Our Natively app displays the Bubble web application within an embedded browser and uses the necessary device storage supporting that service.
We use contact details to send necessary service, security and policy communications. These are part of providing the service or protecting legitimate interests. Any optional promotional communication must have the permission or other lawful basis required for that channel; you can object to direct marketing at any time. Optional website advertising-related sharing is described above; it is separate from necessary service communications. You can reject or withdraw optional tracking through the website controls. We do not treat a payment or Gift Aid declaration as consent to promotional messages.
Where we rely on legitimate interests, we consider the impact on you and your reasonable expectations. You can ask for more information or object as described below. Some information is required to provide the service or complete verification; without it, an account, payment or payout may be unavailable or restricted. Optional profile content, messages and Gift Aid declarations are not required merely to make a normal tip.
Names or usernames, profile photographs, profile text and suggested amounts can appear on public individual or Team tipping pages. These can be personal information even though they are publicly visible. Tip histories, bank details and verification documents are not public profile information.
We do not routinely disclose a guest's payment or contact details to Recipients. If you choose to submit a message or name, that content is made available to the relevant Recipient or Team through the service. Authorised Administrators can see Team performance, including guide tips. They can also access Gift Aid declarations and the associated donor information for their organisation.
Administrators and recipient organisations are responsible for their own lawful use of information they access or export. Other members are not entitled to use that access for unrelated marketing or disclose donor or member information without authority.
We use providers to deliver the relevant parts of the service, including:
We share only information relevant to the service each provider performs. A provider may act as our processor for some activities and as an independent controller for others. In particular, Ryft acts as a processor for information handled on our behalf and as a controller where it determines its own purposes, including applicable compliance activities. See Ryft's Privacy Policy for its handling of information.
We may also disclose relevant information to professional advisers, insurers, banks, card issuers, regulators, courts or law enforcement where necessary and lawful to handle a claim, protect rights, investigate suspected crime or meet an obligation. In a business transfer, relevant information may be shared subject to appropriate confidentiality and data-protection requirements; it is not unrestricted permission to sell data for unrelated purposes.
Cookies and similar technologies support necessary sessions, security, payment functionality and choices. Optional analytics and marketing technologies operate on the marketing website with consent. Our Cookie Policy explains the distinction. Our website provides cookie-preference controls on www.tipd.co. A first-party local-storage record remembers your choices, notice version, decision time and expiry for six months. This implementation stores that preference in your browser, rather than sending a consent receipt to a central Tipd database. The web application, payment pages and native app use necessary technologies without optional tracking; they do not rely on the website banner for consent. A third-party website you choose to visit has its own arrangements.
Our providers operate internationally and information may be hosted, accessed or processed outside the United Kingdom, including in the United States and the European Economic Area. The location of a company or its registered office does not establish where all data is hosted.
Where a restricted transfer occurs, it must use a lawful transfer route, such as an applicable adequacy decision or approved contractual safeguards with any required assessment and supplementary measures. The route depends on the provider, destination and applicable law. You can contact us for details of the safeguards relevant to your information. We do not rely on your acceptance of our Terms as blanket consent to international transfers.
We keep personal information for the purposes explained in this notice and delete or anonymise it when it is no longer needed. A username, Team name or payment reference can still identify someone; retained transaction records are not automatically anonymous. Our financial year ends on 31 May.
Ordinary financial and transaction evidence is normally kept for six years after the end of the last company financial year to which it relates and deleted in the following 1 June retention cycle. This supports accounting, payment reconciliation and relevant audit evidence. We retain the necessary transaction details, allocations, fees, tax information, provider references and identifying information needed for those purposes, rather than the whole account profile.
Each Gift Aid declaration applies to one donation. The declaration and necessary donor details are normally kept for six years after the 31 May financial year-end covering that donation and deleted in the following 1 June cycle. This aligns the declaration with its linked donation and audit records and can mean retention for nearly seven years from the donation. Recipient organisations remain responsible for their own HMRC records and should retain necessary exports, including before closing an account.
Records required for EU VAT One Stop Shop (OSS) reporting are kept for ten years from the end of the calendar year of the relevant transaction, then deleted in the following 1 June cycle. The annual deletion cycle adds five months beyond that calendar-year period. Only information needed for the OSS record is retained on this basis; it does not extend every account field or Gift Aid declaration to ten years.
We use an annual financial-record deletion cycle to reconcile linked records and apply recorded audit or legal holds consistently. Where a particular legal obligation, unresolved balance, investigation or legal claim requires longer retention, we keep only the necessary records for that purpose, restrict their use and review the continuing need. Account closure does not restart the ordinary retention periods. An unresolved balance may require limited identifying and ownership records until it is resolved.
For routine voluntary account closure, we normally allow 28 days to withdraw the request before deleting unnecessary profile and account information. Closing an account does not erase records still needed under the periods or exceptions above. A request to exercise a statutory erasure right is considered without undue delay under the applicable legal timetable; the cooling-off period is not an automatic reason to postpone it.
Tipd removes uploaded verification documents after five days. Ryft may retain its own financial, account and verification records for longer under its applicable terms and legal duties. Closing a Tipd profile, closing a Ryft payment account and erasing retained data are separate processes. We assist with relevant provider requests but do not promise that Ryft erases all information when a Tipd account closes or on Tipd's timetable.
Support and security records are kept only as long as necessary for the enquiry, protection of the service and relevant evidence or legal requirements. Necessary records of contractual notices and agreements may remain to establish the terms applying to retained transactions or claims. Cookie lifetimes and optional website analytics retention are separate from the financial-record schedule; see the Cookie Policy and website controls.
Deleted information may remain temporarily in restricted backups until overwritten through the applicable backup cycle. It is not used for ordinary business purposes during that period; if a backup is restored, applicable deletion instructions must be reapplied. Information exported by an organisation is handled under its own privacy and retention arrangements.
We use appropriate technical and organisational measures to protect information and limit access to authorised purposes. No system is completely secure. Protect your login and report suspected misuse promptly.
Payment and fraud controls may flag, reject or restrict activity, and providers may operate their own automated checks. If a decision materially affects your account or payment and you believe it is wrong, contact us to request an explanation and human review where applicable. We may need to refer a provider decision to that provider. Applicable rights are not removed by an automated result or a contractual disclaimer.
Tipd recipient and administrator accounts are for adults aged 18 or over. We do not knowingly open those accounts for children. A person under 18 may make a payment only where lawful and with the authority and any permission required to use the payment method. We do not verify the age of every guest, so we do not claim that no child's information is ever processed.
If you are concerned about a child's account, payment or information, contact us. We will assess the circumstances, provide appropriate assistance and remove or restrict information where required, while retaining any records that must lawfully remain.
Depending on the law that applies and the processing involved, you may ask to access or obtain a copy of your information, correct it, erase it, restrict processing or receive portable data. You may withdraw consent where we rely on it without affecting processing that was lawful before withdrawal.
You have the right to object to processing based on legitimate interests, subject to applicable law, and to object to use of your information for direct marketing at any time. We will stop direct marketing following an objection.
Contact support@tipd.co to exercise a right or ask about account deletion. We may need proportionate identity checks, particularly where a request affects financial information. We respond within the applicable legal time limits, normally one month for UK GDPR requests, and explain any lawful extension, exception or refusal. The routine 28-day account process does not override those rights or deadlines.
You may complain to the Information Commissioner's Office in the UK or to another competent data-protection authority where you have that right. You do not have to complain to us first. If your request concerns information separately controlled by Ryft or a recipient organisation, their notice explains how to contact them; we will assist in directing a request where appropriate.
We will update this notice when our processing changes and provide additional notice of material changes where appropriate. New consent will be requested where required; changing a notice does not itself create consent.
Data-protection contact: Christopher Anderson, support@tipd.co. Telephone: +44 (0)161 706 1952.