NTTheNextTap

Privacy

Privacy & advertising

This page explains how we handle privacy across our apps and website, with extra attention to advertising through Appodeal, measurement, and consent.

Who is TheNextTap?

I am Tommy Goossens, owner of TheNextTap and the data controller for this website and the apps listed here. I develop and maintain these products with a focus on clear UX, transparency, and respect for your privacy.info@thenexttap.com.

Postal address:Raam 501, 5403TM Uden, Netherlands
Chamber of commerce / VAT:Available on request via email.

What data may we process?

  • No directly identifying in-app account data (such as name or account profile), unless you provide it yourself by email.
  • Technical data such as device, app, and browser information.
  • Usage signals such as interactions in the app/website and ad events.
  • Advertising identifiers (such as IDFA on iOS) where applicable and permitted.
  • IP address or derived network data for delivery, security, and measurement.
  • Contact details you provide when you email us.

Why we process data (and on what legal basis)

  • Providing services and keeping them working: contract performance or legitimate interests.
  • Security, fraud prevention, and abuse detection: legitimate interests.
  • Advertising and measurement: consent where legally required, otherwise legitimate interests.
  • Legal obligations (e.g. tax or legal retention): legal obligation.
  • Support for questions or complaints: legitimate interests or contract performance.

Advertising, consent, and choices

Some apps may show ads through Appodeal, an ad mediation platform that may work with multiple advertising partners. For ad delivery, frequency capping, fraud prevention, and measurement, Appodeal and its partners may process advertising identifiers (such as IDFA), IP addresses, device and network information, and ad events (such as impressions and clicks).

Appodeal uses Stack Consent Manager (IAB TCF v2) to collect consent in regions where it is required, such as the EU/EEA. Depending on your region, we ask for consent before personalized ads and certain measurement. You can usually withdraw or adjust consent via in-app privacy settings. Non-personalized ads may still use contextual or technical data to deliver ads and prevent abuse.

On iOS, App Tracking Transparency (ATT) may apply. If tracking consent is not granted, ad requests are limited to the consent state and platform rules in effect. You can change your choices later in iOS settings and/or the app’s privacy options.

In regulated US states, users may access a Privacy Settings or “Do Not Sell or Share My Personal Information” option through Stack Consent Manager’s Privacy Entry Point when available in the app.

Read theAppodeal Privacy Policyfor more details on how Appodeal handles data.

Third parties and international transfers

We may share personal data with service providers (such as advertising partners) acting on our behalf. These parties may process data outside the EEA. Where required, we use appropriate safeguards such as Standard Contractual Clauses (SCCs) or other legally recognized mechanisms.

For apps that show ads, we rely on Appodeal for ad mediation, delivery, measurement, and consent management, and on Apple platform services (such as App Store distribution and iOS frameworks) for platform functionality. Appodeal may enable integrated ad networks, each with their own privacy practices.

Retention

We do not keep data longer than necessary for the purposes above, unless a longer retention period is legally required. The exact period depends on the type of data, context, and legal obligations.

Your rights (GDPR / UK GDPR)

  • Right of access, rectification, erasure, and restriction of processing.
  • Right to data portability.
  • Right to object to processing based on legitimate interests.
  • Right to withdraw consent without retroactive effect.
  • Right to lodge a complaint with your local supervisory authority.

You can send a request viainfo@thenexttap.com. We generally respond within 30 days unless the law allows a different period.

Additional rights in other regions

Depending on where you live, you may have additional rights under US privacy laws (e.g. CCPA/CPRA), including rights to access, delete, correct, and object to certain sharing or profiling. We do not sell personal data for money. For “do not sell/share” or similar requests, you can email us or use the in-app Privacy Settings where available.

Children

Our services are not intended to knowingly collect children’s personal data in violation of applicable law. If you believe a child has shared data inappropriately, please contact us so we can review and respond appropriately.

Processors and partners (overview)

Below is a concise overview of external parties we may use. We update this overview when our stack changes.

PartyPurposeProcessing regionDocumentation
AppodealAd mediation, delivery, measurement, and consent managementEU + possibly outside the EUAppodeal Privacy Policy
ApplePlatform distribution, App Store, iOS frameworks (incl. ATT / SKAdNetwork context)EU + possibly outside the EUApple Privacy Policy
RevenueCatSubscription status and purchase validation (apps with in-app purchases, such as OneThing Pro)EU + possibly outside the EURevenueCat Privacy Policy

Data matrix by category (summary)

CategoryExamplesPurposeLegal basisRetention
Technical identifiersIP, device ID, app versionSecurity, delivery, stabilityLegitimate interests90 days (server/technical logs), then deletion or aggregation
Ad dataAd events, ad ID, click/impressionAdvertising and measurementConsent / legitimate interestsUp to 24 months with ad partners via Appodeal, per partner settings
Contact detailsEmail address, message contentSupport and follow-upContract performance / legitimate interestsUp to 24 months after your request is completed

App-specific: TapBlox!

  • TapBlox! uses Appodeal for banner and rewarded ads.
  • TapBlox! uses Stack Consent Manager for consent choices and privacy options in the app.
  • TapBlox! may use advertising identifiers (such as IDFA) when permitted by consent and platform settings.
  • TapBlox! supports personalized and non-personalized ads, depending on region, consent status, and device settings.
  • TapBlox! stores progress and preferences locally on the device (such as high score, coins, skins/themes, and daily challenge status).
  • TapBlox! stores a local session state in an app file to resume a game.

App-specific: Bubble Quest

  • Bubble Quest uses Appodeal for banner and rewarded ads.
  • Bubble Quest uses Stack Consent Manager for consent choices and privacy options in the app.
  • Bubble Quest may use advertising identifiers when permitted by consent and platform settings.

App-specific: OneThing

  • OneThing does not show third-party ads and does not use analytics SDKs.
  • Tasks and preferences are stored locally on your device via SwiftData. Optional OneThing Pro iCloud sync uses Apple CloudKit in your private iCloud account — we do not have access to your iCloud data.
  • Streak data and app settings are stored locally (and in an App Group shared with the widget extension).
  • OneThing Pro subscriptions are processed through the Apple App Store. RevenueCat receives an anonymous app user ID and subscription status to unlock Pro features.
  • If you allow notifications, OneThing schedules gentle local reminders on your device only.
  • App lock (Pro) uses Apple’s LocalAuthentication framework. Biometric data never leaves your device.
  • App-specific support: thenexttap.com/onething/support

Apps without third-party ads

The following apps do not currently show third-party advertising:Activity Roulette, Brain Dump, TapRunner.

App Store Privacy Labels

App Store Connect privacy answers (such as data categories, tracking, and linkage to user/device) are aligned with the actual app implementation and this privacy policy. When SDKs or data flows change, we update both the labels and this page.

Contact and complaints

Questions about privacy or a request about your rights? Email us atinfo@thenexttap.com. You may also lodge a complaint with the competent data protection authority, such as the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the Belgian Data Protection Authority (GBA).

Last updated: July 10, 2026