Privacy Policy
1Preamble
This Privacy Policy describes how Ma Reputation En Ligne Producciones SL (the "Provider") collects, processes, and protects personal data of users of the iziqrcode service (the "Service").
By using the Service, the User acknowledges having read this Policy. Data processing complies with Regulation (EU) 2016/679 (GDPR) and the Spanish Organic Law 3/2018 (LOPDGDD).
21. Data controller
Ma Reputation En Ligne Producciones SL
C/ Pintor Joan Maragall, nº 60, piso 2º, 28020 Madrid, Spain
CIF: B88432935
Data protection contact: [email protected]
32. Data collected
The Provider collects the following categories of data:
Registration data: email, name (optional), password (hashed and salted).
Billing data (paying customers): name, company name, billing address, intra-EU VAT number, country. Banking details are never stored by the Provider — they are handled directly by Stripe.
Service usage data: created QR codes, destination URLs, customization parameters, creation/modification dates.
Technical data: IP address (anonymized after 7 days), browser type, device type, application error logs.
Scan data (your QR's visitors): we store no directly identifying data about the scanner — neither their IP address nor their User-Agent. What is recorded: the date and time of the scan, the country and approximate city derived from the IP address by the content delivery network, the device type (mobile / desktop / tablet), the operating system and the browser, plus a pseudonymous fingerprint of the IP address, computed with a salt that changes every day and destroyed after 7 days. That fingerprint is used only to count distinct visitors within a single day.
43. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Service delivery (QR creation, edit, tracking) | Contract performance (Art. 6.1.b GDPR) |
| Invoicing and accounting | Legal obligation (Art. 6.1.c) |
| Customer support | Contract performance (Art. 6.1.b) |
| Security, fraud prevention | Legitimate interest (Art. 6.1.f) |
| Website audience measurement (Google Analytics 4, anonymized IP, never on /p/*) | Consent (Art. 6.1.a), refusable in one click |
| Product communication (newsletter) | Explicit consent (Art. 6.1.a), withdrawable anytime |
54. Retention period
- Registration data: throughout account activity. Upon deletion, erasure within 30 days except for legal obligations (invoices kept for 6 years per Spanish tax law).
- Billing data: 6 years (Ley General Tributaria).
- Technical logs: 12 months maximum.
- IP addresses: 7 days in plain form, then irreversible anonymization.
- Anonymized scan data: retained indefinitely for aggregate statistical purposes (no possible link to an identifiable person).
65. Recipients and processors
The Provider uses the following processors, each bound by a sub-processing agreement compliant with GDPR Art. 28:
- Hetzner Online GmbH (Industriestraße 25, 91710 Gunzenhausen, Germany) — hosting of the Next.js application and the PostgreSQL database. Datacenter: Falkenstein (Germany, EU jurisdiction).
- Stripe Payments Europe Ltd (The One Building, 1 Lower Grand Canal Street, Dublin 2, Ireland) — payment processing, billing, VAT calculation (Stripe Tax). Full payment-card data never transits our servers. See https://stripe.com/privacy. Out-of-EU transfers are framed by Standard Contractual Clauses EU 2021/914.
- Cloudflare Inc. (101 Townsend St, San Francisco, CA 94107, USA) — three distinct processings:
– CDN + DNS: serving static assets, technical session cookie. No plain-text access to user data.
– R2 Storage (EU instance): hosting of user-uploaded logos, kept in Europe.
– Workers (qr-redirect): scan handling — IP address (anonymized after country extraction), geo-country, device type, user agent. No long-term storage on the Worker side.
See https://www.cloudflare.com/privacypolicy/. Out-of-EU transfers are framed by Standard Contractual Clauses EU 2021/914.
- Resend (Bird.com, Inc., 2261 Market Street #5039, San Francisco, CA, USA) — transactional emails (magic-link sign-in, invoices, notifications). See https://resend.com/legal/privacy-policy. Out-of-EU transfers are framed by Standard Contractual Clauses EU 2021/914.
- Anthropic PBC (548 Market Street, PMB 90375, San Francisco, CA 94104, USA) — AI-assisted translation and import of restaurant menus (dish names and descriptions, categories). Internal, authenticated feature limited to paid plans; no diner data is transmitted. Content processed via the Anthropic API (no training on data, limited retention). See https://www.anthropic.com/legal/privacy. Out-of-EU transfers are framed by Standard Contractual Clauses EU 2021/914.
- Google Ireland Ltd (Gordon House, Barrow Street, Dublin 4, Ireland) — marketing-site audience measurement via Google Analytics 4 and measurement of our campaigns via Google Ads, only after your consent. Anonymized IP, no ad targeting, never active on the public pages of your menus (`/p/*`). See https://policies.google.com/privacy. Out-of-EU transfers are framed by Standard Contractual Clauses EU 2021/914.
The Publisher also sends data to one recipient that does not act as a processor, but as an independent controller:
- OpenAI Ireland Ltd (1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland) — conversion measurement for advertising campaigns served inside ChatGPT, via the OpenAI Ads pixel, only after your consent, and never on the public pages of your menus (`/p/*`). Under OpenAI's conversion terms, OpenAI acts as an independent controller: it determines its own purposes and does not act on the Publisher's instructions. The Publisher's code sends it no identifier — no email address, no phone number, no account id. ⚠ The pixel does however carry an automatic matching feature that OpenAI alone controls, remotely, with no change to our code — and that is ACTIVE for our pixel. It scans the page's form fields and sends OpenAI, as a SHA-256 digest, the information it recognises there: email address, phone, name, city, region, country, postal code. The pixel sets an `__oppref` referral cookie, destroyed as soon as you withdraw consent. See https://openai.com/policies/privacy-policy and https://openai.com/policies/ad-tools-dpa. Transfers outside the EU are possible, governed by the OpenAI instruments named above.
An up-to-date register of processors is maintained pursuant to GDPR Art. 30 and is available on request at [email protected].
76. Transfers outside the EU
Data is hosted in Germany (Hetzner, Falkenstein). Some technical processors (Cloudflare, Stripe, Resend) may occasionally process data outside the EU. Such transfers are made under the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914) and, where applicable, under the EU-US Data Privacy Framework.
87. Your rights
Under GDPR Articles 15 to 22, you have the following rights:
- Access: obtain a copy of data concerning you;
- Rectification: correct inaccurate data;
- Erasure ("right to be forgotten"): delete your data, subject to legal obligations;
- Restriction of processing;
- Portability: receive your data in a structured format;
- Objection to processing based on legitimate interest;
- Withdrawal of consent at any time for consent-based processing.
To exercise these rights, write to [email protected] from the email address associated with your account. A response will be provided within 30 days.
You also have the right to lodge a complaint with the competent supervisory authority. In Spain: Agencia Española de Protección de Datos (AEPD), www.aepd.es. In your country of residence: see edpb.europa.eu.
98. Security
The Provider implements appropriate technical and organizational measures to protect your data: TLS 1.3 encryption for all communications, hashed passwords (argon2id), data access restricted to authorized personnel, encrypted daily backups, regular audits, least-privilege principle.
109. Cookies
The Service uses strictly necessary technical cookies (session, CSRF, language) and, with your consent only, an audience-measurement cookie (Google Analytics 4, anonymized IP, never on the public pages `/p/*`) together with an advertising-measurement cookie (Google Ads, to know which ads bring sign-ups). Both are provided by Google Ireland Ltd and ride on the same tag. Full details and consent management are set out in the Cookie Policy.