Draft — awaiting owner approval. This text describes how QRiva works today; it is not yet the final legal wording.
Privacy policy
Last updated: [date of approval]
What personal data QRiva handles, why, where it's kept and for how long — and the choices you have. QRiva is designed with GDPR's data-minimisation principle in mind.
1.Who is responsible
RH COMMODITIES, I.C. Bratianu 3, 077045 Chitila, Ilfov, Romania (“QRiva”, “we”), is the controller of the personal data of our customers and of people who contact us, as described in this policy.
When a business uses QRiva, that business is the controller of the data about its own visitors, leads and members, and we process that data on its behalf. If you scanned a code or filled in a form, the business that published it is your first point of contact.
2.Data about our customers
When you use QRiva we handle:
- Account details: your e-mail address, name if you add it, passkeys you register, and your preferences such as theme and Home layout.
- Workspace details: business name and details, members and their roles, and everything you create.
- Billing details: plan, billing address, VAT number and invoices. Card payments are handled by Stripe; we never see or store card numbers.
- Sign-in sessions: the device, browser and IP address of your signed-in sessions, recorded by our authentication provider so you can review and sign out devices.
- Support and sales conversations, including anything you attach.
- Security and error logs. Error logs are scrubbed of e-mail addresses, phone numbers and tokens; rate limits use a daily, salted hash of the network address that can't be reversed.
- E-mails we send you about your account, such as sign-in links, alerts and billing notices.
3.Data we process for our customers
When someone scans a code or visits a page, card or form published with QRiva, we process on the publishing business's behalf:
- Scan and visit events: the time, the code or page, country, approximate region and city, device type, browser, language and referrer. IP addresses are not stored.
- A first-party visitor cookie and a hash of it that changes every month, used to count unique visitors. Workspaces using strict privacy mode store neither city-level location nor this hash.
- What people choose to send: form answers, uploaded files, signatures, bookings and details shared from a business card, with a record of the consent wording shown.
- Leads the business creates or imports, with notes, tags, status and history.
- Payments in forms, which are processed by Stripe.
- Tags a business adds to its own pages, such as Google Analytics or Meta Pixel. These are controlled by that business.
Browsers and devices of the business's own team are recognised so their test scans aren't counted.
4.Visitors to our website
Our own website uses no advertising or analytics cookies. We use only what's needed for it to work, such as remembering that you're signed in.
If you contact sales or support, we use your name, e-mail, company and message to reply and to keep a record of the conversation.
5.Why we use data and our legal bases
We use personal data only for these purposes:
- To provide QRiva under our contract with you: accounts, workspaces, publishing, billing and support.
- For our legitimate interests in keeping QRiva safe and working: screening destinations, preventing abuse and fraud, security logs and fixing errors.
- To meet legal obligations, such as keeping invoices and answering lawful requests.
- With your consent where we ask for it, for example to contact you about an enquiry. You can withdraw consent at any time.
6.Service providers we use
We use carefully chosen providers who process data on our instructions:
- Supabase — database, authentication and file storage, in Frankfurt (EU).
- Vercel — hosting; the app's servers run in Frankfurt (EU), and static files are delivered through a global network.
- Stripe — payments, invoices and payment methods.
- Resend — sending e-mails such as sign-in links, alerts and notifications.
- Upstash — a short-lived cache that keeps printed codes working during outages, when enabled.
- Google Safe Browsing — receives the web addresses of destinations so they can be checked for threats. No personal data about visitors is sent.
- Anthropic — generates drafts and answers for the in-app assistant and AI form drafts, only when those features are enabled and used.
- Google and Microsoft — sign-in with those accounts, only if you choose to use it.
- Services you connect yourself, such as HubSpot, Google Sheets, Slack or webhooks, receive the data you choose to send them.
We don't sell personal data, and we don't share it with advertisers. [Owner: confirm the list of providers and their data processing agreements before publishing.]
7.Where data is stored
QRiva's database and file storage are in the EU, in Frankfurt, and the app's servers run in the same region.
Some providers may process data outside the European Economic Area, for example for payments, e-mail delivery or AI features. Where they do, we rely on an adequacy decision or the European Commission's standard contractual clauses. [Owner: confirm each provider's transfer mechanism.]
8.How long we keep data
We keep personal data only as long as we need it:
- Account and workspace data: while your account is open. After you close it, it is deleted within [30] days, except where we must keep it.
- Invoices and billing records: for as long as tax law requires, currently [number] years.
- Scan and visit events, and inactive leads: for the period each workspace chooses, after which they're deleted automatically every night.
- Items in the trash: 30 days, then deleted. Workspace export files: available to download for 7 days.
- Support conversations: [period] after the conversation is closed.
- Backups: kept by our database provider for [period], then overwritten.
9.How we protect data
Data is encrypted in transit, workspaces are isolated in the database and tested, and access follows each person's role. Our security page explains this in detail.
10.Your rights
You have the right to access your personal data, to have it corrected or deleted, to restrict or object to its use, to receive it in a portable format, and to withdraw consent at any time.
To use these rights, contact us at [Contact] or through Support. We'll reply within one month. If your data was collected by a business using QRiva, please contact that business first; we'll help them respond.
You can also complain to a data protection authority, in particular in the EU country where you live or work. Our lead authority is [supervisory authority].
11.Automated decisions
We don't make decisions about people that have legal or similarly significant effects based only on automated processing. Automated safety screening can block a destination; the owner is told why and can ask for a review.
12.Children
QRiva accounts are not intended for children under 16, and we don't knowingly collect their data for our own purposes.
13.Changes to this policy
If we change this policy in a way that matters, we'll tell customers by e-mail or in the app before the change applies.
14.Contact
Privacy questions: [Contact]. Data protection contact: [privacy contact].