TagLineID
← Back to TagLineID

Legal

Privacy Policy

Last updated: July 4, 2026

This explains what happens to the information you type into TagLineID, in plain terms. Most of this policy is short for one reason: there isn't much to explain, because there isn't much we actually do with your data.

The short version

You type information into a form. That information gets packed into the web address of the page you land on next, in the part after the # symbol. Browsers never send that part of an address to any server, by design, not when the link is created, and not when it's scanned later. We never receive it, never see it, and never store it. There is no database behind this tool.

What information is involved

Whatever you choose to enter: your name, age, blood type, allergies, medical conditions, medications, an emergency contact's name and phone number, and any notes you add. All of it is optional except your name and emergency contact, and all of it stays in the link, never on a server we operate. Age is asked for instead of a birth date on purpose, since a full birthday combined with a name is exactly the kind of pair used to verify identity elsewhere, and an age alone doesn't carry that risk.

Special category data (health information)

Allergies, medical conditions, and medications count as "special category" data under UK and EU data protection law, which normally requires extra safeguards because health information is sensitive by nature. In this case, the relevant safeguard is architectural: we never receive this data in the first place, so there's nothing on our end to secure, misuse, or lose. You are the one entering it and choosing to generate a link or a printed tag, in the same way you'd write it on a paper card yourself.

Cookies and tracking

None. This page doesn't set cookies, doesn't run analytics, and doesn't load anything from a third-party tracking service. The only external code involved is the QR code library, and it's built directly into the page rather than loaded from elsewhere, so no request for it ever leaves your browser either.

What a web host can see

Whatever service hosts these files (for example, a static hosting provider) will typically keep standard server access logs, the kind almost every website on the internet generates automatically: the visitor's IP address, which page was requested, and when. This is separate from us and happens at the infrastructure level, the same way it would for any website.

Importantly, those logs only ever see which page was requested, such as /index.html, never the part of the address after #. Your emergency information specifically does not appear in hosting logs, because browsers don't transmit it.

Exact log retention depends on the hosting provider in use. [Name the actual host once this is deployed, and add their retention period here if you want to be fully specific.]

GDPR and your rights

Under UK and EU GDPR, a website is normally a "data controller" or "data processor" for personal information it handles. For the emergency ID data itself, that relationship doesn't really apply here in the usual sense, since we never receive, process, or store a copy of it. There's nothing on our end to request access to, correct, or delete, because we don't have it.

For basic hosting access logs (IP addresses), the hosting provider may act in a limited processing capacity with a short, automatic retention window, standard for most infrastructure providers. If you'd like more detail on that once this is live, or have any other privacy question, you can reach us at jmakoffi@gmail.com.

Children

This tool isn't intended for children to fill in on their own. A parent or guardian should be the one entering a child's information, if it's ever used that way.

If this policy changes

If the way this tool works ever changes, for example if a future version adds accounts, syncing, or analytics, this page will be updated to reflect it honestly and the date at the top will change. As it stands today, the short version above is the accurate, complete picture.

One thing this policy can't protect you from: once a link or QR code exists, anyone who has it can read what's on it. That's covered in more detail on the main page, but it's worth repeating here, since it's the actual privacy trade-off of the whole tool, not a technicality.