tabfather.

Privacy policy

Effective October 10, 2026. Tabfather is operated by Larry Parks.

Information we process

We process account names, email addresses, authentication records, and the information businesses and their crews enter to run events. This can include client contacts, booking details, agreements, receipts, payment references, staff certifications, schedules, inventory, photographs, incident notes, and approval history.

Card and bank details are collected by Stripe through its payment and onboarding interfaces. Tabfather stores payment references and status; it does not store full card numbers, bank login credentials, or Social Security numbers.

How information is used

We use information to authenticate accounts, operate the service, deliver requested messages, process subscriptions, maintain records, prevent misuse, and respond to support requests. We do not sell personal information or use it for advertising profiles.

Businesses control the event records they enter and the people who can access them. Contact the business named in your event portal for questions about its event agreement, staff records, or use of your information.

Devices and notifications

Session cookies keep you signed in. Device storage supports offline work and synchronization. Event information can remain on a device until its stored data is cleared; use a trusted device and sign out after use. Push notifications require permission.

Location is requested for specific actions such as clocking in or out. Tabfather does not continuously track location. Camera and photo access are used when you choose to capture or attach evidence. You can decline or revoke device permissions.

Service providers and sharing

Vercel hosts the application, Supabase provides authentication, the database, and file storage, Resend delivers email, and Stripe processes payments and subscriptions. These providers process information necessary to perform those services. The production database is hosted in the United States.

A business may connect additional providers for messaging, calendars, accounting, verification, or other workflows. Data is sent to a connected provider when the business enables or uses that integration. Provider terms and privacy policies also apply.

Businesses can share restricted event links with clients, venues, and insurers. Anyone holding a link can access its permitted content until the link expires or is revoked. We may disclose information when legally required or necessary to protect accounts and the service.

Retention and account closure

Records are retained while they are needed to operate an account. Business owners can export their records and request account closure. Closure stops operational access but does not automatically erase contracts, incident evidence, compliance history, or financial records associated with other people or required business obligations.

Retention and deletion requests receive individual review, including the business’s record obligations and rights of other participants. Backups may retain earlier copies until those backups expire. Contact us to request access, correction, deletion, or a retention review; we may need to verify your identity and authority over the records.

Security and changes

We use encrypted connections, access controls, and private file storage. No online service can guarantee absolute security. Keep credentials and shared links private and report suspected unauthorized access to us.

We will update the effective date when this policy changes and provide notice of material changes through the service or account email. For privacy questions or requests, contact larry@leapaheadlabs.com.