This policy explains what personal data QRkontaq processes and why. QRkontaq is operated by sole proprietor (ФОП) Dmytro Kushpel, registered in Ukraine ("we", "us"). Contact: inowioss@gmail.com. We act as the data controller for the platform and as a processor for the menu data venues publish.
We process data to provide the service (contract), to secure and improve it (legitimate interest), and — for optional features like loyalty — based on your action of signing in (consent). We do not sell personal data and do not run third-party advertising or tracking.
We use only functional storage: session tokens to keep you signed in, and device storage for preferences such as language and liked dishes. No advertising cookies.
Account and venue data is kept while the account is active and deleted on account or venue deletion (backups expire within 30 days). Payment records are kept as long as financial regulations require. Anonymous statistics contain no personal identifiers.
Under the GDPR and Ukrainian data protection law you can request access, correction, deletion or export of your data, object to processing, and withdraw consent at any time by e-mailing inowioss@gmail.com. You can also lodge a complaint with your local supervisory authority.
All traffic is encrypted (TLS), passwords are stored hashed, access to production systems is restricted, and each venue's data is isolated per tenant.
The service is intended for business use and is not directed at children under 16.
We may update this policy; the current version with its effective date is always available at qrkontaq.com/privacy.