QrConnector

Draft: this legal text is currently under legal review and is not yet final.

Privacy Policy

Last updated: 4 October 2026

1. Controller

Toprak Özkale, Sole proprietorship (Türkiye), [address]. Email: support@qrconnector.com. Full provider details are in the Legal Notice.

EU representative (Art. 27 GDPR): [name and address of the EU representative]. We have not appointed a data protection officer; in our assessment there is no obligation to do so.

Roles: for account and contract data of restaurant operators we are the controller. For data of guests who open a menu, the restaurant is the controller and we act as processor (see the Data Processing Agreement).

2. What data we process and why

DataPurposeLegal basis
Name, email address, password (stored only as a hash) or Google account identifierCreate the account, sign in, contract communicationArt. 6(1)(b) GDPR
Menus, photos, tables, settingsProvide the serviceArt. 6(1)(b) GDPR
Support messages and email correspondenceAnswer requestsArt. 6(1)(b) and (f) GDPR
Technical logs (IP address, time, device/browser), error reportsSecurity, stability, troubleshootingArt. 6(1)(f) GDPR
Payment and invoice dataProcessing of paid plans by PaddleArt. 6(1)(b) and (c) GDPR
Email address and plan statusSubscription notices (cancellation, payment problem, plan end) and information about similar services of our ownArt. 6(1)(b) GDPR; for information about similar services § 7(3) UWG and Art. 6(1)(f) GDPR

3. Cookies and local storage

We do not use advertising, tracking or third-party analytics cookies. We store only technically necessary information:

Name / storagePurposeDuration
Sign-in cookies (Supabase Auth)Stay signed in, securitySession or until sign-out
NEXT_LOCALERemember the chosen languageup to one year
qc_oauth_localeKeep the language during Google sign-ina few minutes
localStorage / sessionStorage: active branch, interface, chosen menu languageOperating the dashboarduntil you delete it
localStorage in the guest menu: stories already viewedComfort feature; the information does not leave your deviceuntil you delete it

The legal basis for strictly necessary access is § 25(2) no. 2 TDDDG. Processing of any personal data that arises is based on Art. 6(1)(b) and (f) GDPR.

4. Audience measurement in the guest menu (cookie-free)

When guests open a menu, we count page views, search terms and clicks for the restaurant concerned. A guest is not recorded by name. The evaluation is carried out on behalf of the restaurant (see the Data Processing Agreement).

5. Recipients and processors

ProviderPurposeLocation of processing
SupabaseDatabase, sign-in, file storageRegion: [check Supabase region]
VercelHosting of the applicationUSA / global network
ResendSending emails (confirmation, password, notices, support)USA
SentryError monitoring (personal data is masked)EU region
Google (Gemini API, Google sign-in)Menu translation, optional sign-in with GoogleUSA
OpenRouterOptional AI image enhancementUSA (forwarding to model providers)
PaddlePayment processing as Merchant of Record (separate controller)United Kingdom / EU

For AI features, the menu text or photos you enter or upload are transmitted to the provider concerned. [clarify Gemini tier and use for model training]

6. Transfers to third countries

The service is operated from Türkiye. There is no adequacy decision of the EU Commission for Türkiye; we base access to data of customers from the EU on standard contractual clauses (Decision (EU) 2021/914). For providers in the USA we rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on standard contractual clauses.

7. Retention and deletion

  • Account data and content are kept until you delete your account. When you delete the account in the dashboard, the data is deleted immediately.
  • If you delete only a restaurant (branch), you can restore it for 30 days; after that, restoration is no longer possible.
  • Invoice and payment data are kept for as long as statutory retention duties require; they are not deleted earlier when the account is deleted.
  • Technical logs are kept only briefly.

8. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR). You can withdraw any consent at any time. Contact support@qrconnector.com for this. You can object at any time to information about similar services of our own by email, without any costs other than transmission costs at basic rates.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your residence or place of work.

9. Obligation to provide data, automated decisions

Name and email address are required to use an account; without them we cannot provide the service. No automated decision-making, including profiling, under Art. 22 GDPR takes place.