QR Catalog

Legal

Privacy policy

How QR Catalog handles account information, public catalogs, payments, and email preferences.

Effective from 17 September 2026

1. Who we are and what this covers

QR Catalog is operated by Saula, vl. Kristijan Dakovic, at Ulica Stanka Vraza 119, Slavonski Brod, Croatia, registration / OIB number 19097972932. Contact us about privacy at [email protected]. We are the controller for account administration, billing, service security, support, and our own marketing.

This policy covers visitors to our website and public catalogs, account holders, and people who contact us. Businesses decide which information to publish in their catalogs. Where we host personal data solely on a business’s instructions, that business is the controller and we act as its processor under a separate data processing agreement. This policy does not replace that agreement or the business’s own privacy notice.

2. Information we handle

Account information: your email address, optional name, password hash, verification status, account identifiers, membership permissions, and account timestamps. We also process session credentials and temporary verification and password-reset tokens.

Business and catalog information: business name, category, language, currency, contact email and phone if supplied, logos, photos, catalog text, product details, prices, and saved and published versions of your catalog.

Payment information: Stripe customer and subscription identifiers, subscription status, billing periods, and cancellation status. Stripe collects payment details through its hosted checkout and billing portal. Our application does not receive or store your full card number or card security code.

Technical and support information: requests to our servers can include an IP address, browser information, requested URL, and timestamps. We use hashed IP- and email-based identifiers to limit abusive requests. Our infrastructure providers may maintain access and error logs. If you contact us, we receive your message and contact details.

If you opt into marketing when that feature is available, we will record your email, preference, and evidence of your choice. Details will be provided at the point of subscription.

3. Why we use information

We use account, catalog, and subscription information to provide the service and perform our contract with you. An email address and password are needed to create an account; payment information is needed to purchase a subscription. Optional fields are identified in the interface.

For people acting on behalf of a business customer, account administration and support rely on our legitimate interest in serving that business. Security checks, abuse prevention, troubleshooting, and establishing or defending claims also rely on legitimate interests, balanced against your rights. Accounting and legally required disclosures rely on our legal obligations.

Promotional email will rely on your optional consent. We do not use a decision made solely by automated processing to produce legal or similarly significant effects about you.

4. Service emails and optional marketing

We send emails needed to operate your account, including address verification, password resets, and necessary security, billing, or service notices. These messages are separate from marketing and do not depend on marketing consent. They may continue while needed to provide the service or meet legal duties.

If you choose to subscribe when marketing is available, we may email you QR Catalog product news, tips, and offers. Signing up, paying, accepting terms, or verifying an email address does not by itself subscribe you. Declining marketing does not affect access or pricing.

Every marketing email will identify the sender and include a free, easy unsubscribe link. You will also be able to withdraw consent through email preferences or by contacting us. Withdrawal does not affect the lawfulness of earlier processing. A minimal suppression record may be retained to respect your choice.

5. Public catalogs

Publishing makes the published version of a catalog available to anyone with its link or QR code, including the business contact details and images included in that version. Other people may share, copy, or index it. Only publish personal information you are entitled to make public.

Saving changes to a draft does not update the published version until you publish again. Removing or changing content in the service cannot recall copies already saved by visitors or search engines. You do not need an account or email address to browse a public catalog.

6. Service providers and disclosures

We use Vercel to host the application and scheduled cleanup jobs, Railway to host our PostgreSQL database, Resend to deliver service emails, Stripe for subscriptions and payments, and Cloudflare R2 for uploaded images. Payment providers may also act as independent controllers for their own fraud prevention and legal duties.

Access is limited to people and providers who need it for their work. We may disclose relevant information to professional advisers, authorities where legally required, or parties to a business transfer with appropriate safeguards and notice. We do not sell personal information or give account email addresses to other businesses for their own marketing.

7. International transfers

Some providers may process data outside the European Economic Area. Where that happens, an applicable adequacy decision or appropriate safeguards, such as the European Commission’s standard contractual clauses with any necessary supplementary measures, cover the transfer. You can request information about the applicable safeguards and a copy by contacting us.

8. Cookies and browser storage

The qr_session cookie keeps you signed in for up to 30 days and is cleared when you log out. Language preferences may be stored in a NEXT_LOCALE cookie. Catalog favorites are stored in your browser’s local storage until you remove them or clear site data. Unfinished catalog setup may be kept in session storage for the browser tab’s session.

These features support sign-in and choices you make in the service. Blocking or clearing browser storage can reset those choices or sign you out. The current app does not include advertising pixels or a visitor analytics integration. Stripe’s hosted checkout and billing portal use their own technologies, explained by Stripe.

9. Retention and deletion

Account and catalog information is kept while needed to provide your account. You can delete your account in account settings. Businesses for which you are the only owner are deleted with it; a business with another owner remains under that owner’s control. Associated media is removed through our cleanup process.

Verification links expire after 24 hours, reset links after one hour, and sessions after up to 30 days. Expired tokens and stale rate-limit records are removed by scheduled cleanup. Expiry of a link is not the same as immediate deletion of the underlying record.

Some records may be kept longer for accounting, resolving disputes, security investigations, or honoring an unsubscribe request. Access to retained data is restricted. Backups may retain deleted information until their normal rotation ends.

10. Your choices and rights

Depending on the circumstances, you can request access, correction, deletion, restriction, or portability of your personal data, and object to processing based on legitimate interests. You can always object to direct marketing and withdraw marketing consent.

Send requests to [email protected]. We may ask for proportionate identity verification. We normally respond within one month; if a permitted extension is needed, we will explain it within that first month. Requests are generally free.

You can complain to Croatia’s Personal Data Protection Agency (AZOP, azop.hr), or the competent supervisory authority where you live or work or where an alleged infringement occurred. You do not need to contact us first. For information a business controls in its catalog, you can also contact that business; we will assist as appropriate.

11. Security, children, and changes

We use measures such as password hashing, restricted access, protected session cookies, and request limits. No service can guarantee absolute security. Please keep your credentials private and report suspected unauthorized access to [email protected].

Business accounts are intended for adults aged 18 or over acting for a business. The service is not directed at children. Contact us if you believe a child has supplied personal information inappropriately.

We will update this policy when our practices change and identify its effective date. We will give additional notice of material changes where appropriate, and obtain new consent where a new purpose requires it.