⚠️ Draft — pending attorney review. This policy is a working draft provided for transparency about our intended data practices. It is not yet final and will be reviewed and revised by counsel before launch. It is not legal advice.
Privacy Policy
Last updated: July 21, 2026 · Draft v0.2
1. Who we are
SymphonicBail is software operated by TapCorp, LLC ("SymphonicBail," "we," "us"). We provide a business platform that licensed bail-bond agencies use to run their operations — managing clients, bonds, payments, court dates, documents and reporting.
2. Controller and processor roles
SymphonicBail serves two groups, and our role differs for each:
- Agency users (the bail-bond agencies and their staff who hold accounts). For their account and usage information, we act as a data controller.
- The people an agency manages (defendants, indemnitors/co-signers and their references). The agency enters and controls this information to run their business; we process it on the agency's behalf as a service provider/processor. The agency is responsible for having a lawful basis to collect it and for honoring the rights of those individuals. If you are a defendant or indemnitor and want to access, correct, or remove your information, please contact the bail-bond agency you are working with; we will support them in responding.
3. Information we process
Agency account information
Names, work email addresses, role, and authentication credentials of agency staff; agency business details; and usage and audit logs of actions taken in the platform.
Operational data entered by agencies
To run a bail-bond operation, agencies enter information about the people they manage — which may include names, contact details, addresses, identifiers, employment and reference details, financial and payment information, collateral, bond and court information, and uploaded or camera-captured documents and media (including photographs of IDs, paperwork, and signatures). This information is access-controlled and isolated to the entering agency.
Location (check-ins)
When an agency enables the defendant check-in feature that captures location, the mobile app records the approximate or precise location associated with a check-in, on the agency's instruction, as part of that agency's supervision records. Location is used only for this purpose and is not used for advertising.
Technical information
Standard server logs (such as IP address, timestamps, and the request method and path) used to operate, secure, and debug the service. We do not log message bodies or sensitive query contents.
4. How we use information
- To provide, maintain, secure and improve the platform.
- To authenticate users and enforce role-based access and tenant isolation.
- To send transactional communications an agency configures — for example, court-date reminders to the people that agency manages (see Section 5).
- To maintain an audit trail of actions for security and accountability.
- To meet legal, regulatory and contractual obligations.
We do not sell personal information, and we do not use the operational data agencies enter for advertising or to build marketing profiles.
5. SMS & email communications — consent and opt-out
A core feature is reminding the people an agency manages about court dates and related events by email and text message. We treat this as strictly transactional and consent-based:
- Opt-in. A phone number receives text messages only when consent has been obtained and recorded against that contact. Where consent is not recorded, no SMS is sent.
- Identification. Every text identifies the sending agency so recipients know who is contacting them.
- Opt-out. Every text includes opt-out instructions ("Reply STOP to opt out"). Replying STOP immediately stops further messages and is recorded. Replying HELP returns help information. Message and data rates may apply, and message frequency varies.
- Transactional only. Messages are limited to notifications about a person's own bond — court-date reminders, missed-court alerts, and secure payment links. We do not send marketing or promotional texts, and we do not share or sell mobile numbers or consent to third parties for their own marketing.
- Email. Transactional email follows the same principle and includes the agency's identity. Recipients can ask the agency to stop non-essential email at any time.
6. Service providers & sub-processors
We use a small set of trusted providers to deliver the service. They process information only to perform services for us and under appropriate confidentiality and security obligations. These currently include, or are expected to include:
- Cloud hosting and database infrastructure.
- Object storage for uploaded documents and media.
- Messaging providers for email and SMS delivery.
- Payment processors, when an agency connects one to take card payments (the agency brings its own processor account). Card details are handled and tokenized by that processor; SymphonicBail does not store full card numbers, and retains only non-sensitive transaction records such as amount, status, and timestamps.
- E-signature and email providers, when an agency connects its own account.
We will publish a current list of sub-processors and keep it updated.
We may also disclose information when required by law or valid legal process, or to protect the rights, safety, and security of users, the public, or the service. If SymphonicBail is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy.
7. How we protect information
- Tenant isolation. Each agency's data is isolated at the database with row-level security, so one agency cannot access another's.
- Access control. Granular, role-based permissions and per-record scoping limit access to what a user needs.
- Encryption. Data is encrypted in transit; sensitive secrets and credentials are encrypted at rest.
- Audit trail. Meaningful changes are recorded in an immutable audit log.
- Append-only financial records. Money entries are immutable and never edited in place.
No system is perfectly secure, but we design for least privilege and defense in depth.
8. Data retention
We retain information for as long as an agency maintains its account and as needed to provide the service, and thereafter as required for legal, regulatory, tax, audit and recordkeeping obligations — which can be lengthy in the bail-bond industry. Agencies control the operational records they enter and can request export or deletion subject to those obligations.
9. Your choices & rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, or to object to or restrict certain processing. Agency users may exercise these by contacting us. If you are a defendant or indemnitor, the agency that manages your information is your primary point of contact; we will assist the agency in responding to verified requests.
10. Children
The platform is intended for use by licensed bail-bond professionals and is not directed to children. We do not knowingly collect information directly from children.
11. Changes
We will update this policy as the product and our practices evolve, and will revise the "last updated" date. Material changes will be communicated to account holders.
12. Contact
Questions about this policy or our data practices: SymphonicBail@tapcorpllc.com · TapCorp, LLC.