Privacy Policy
Last updated: 4 October 2026
1. Controller
Toprak Özkale, Sole proprietorship (Türkiye), [address]. Email: support@qrconnector.com. Full provider details are in the Legal Notice.
EU representative (Art. 27 GDPR): [name and address of the EU representative]. We have not appointed a data protection officer; in our assessment there is no obligation to do so.
Roles: for account and contract data of restaurant operators we are the controller. For data of guests who open a menu, the restaurant is the controller and we act as processor (see the Data Processing Agreement).
2. What data we process and why
| Data | Purpose | Legal basis |
|---|---|---|
| Name, email address, password (stored only as a hash) or Google account identifier | Create the account, sign in, contract communication | Art. 6(1)(b) GDPR |
| Menus, photos, tables, settings | Provide the service | Art. 6(1)(b) GDPR |
| Support messages and email correspondence | Answer requests | Art. 6(1)(b) and (f) GDPR |
| Technical logs (IP address, time, device/browser), error reports | Security, stability, troubleshooting | Art. 6(1)(f) GDPR |
| Payment and invoice data | Processing of paid plans by Paddle | Art. 6(1)(b) and (c) GDPR |
| Email address and plan status | Subscription notices (cancellation, payment problem, plan end) and information about similar services of our own | Art. 6(1)(b) GDPR; for information about similar services § 7(3) UWG and Art. 6(1)(f) GDPR |
3. Cookies and local storage
We do not use advertising, tracking or third-party analytics cookies. We store only technically necessary information:
| Name / storage | Purpose | Duration |
|---|---|---|
| Sign-in cookies (Supabase Auth) | Stay signed in, security | Session or until sign-out |
| NEXT_LOCALE | Remember the chosen language | up to one year |
| qc_oauth_locale | Keep the language during Google sign-in | a few minutes |
| localStorage / sessionStorage: active branch, interface, chosen menu language | Operating the dashboard | until you delete it |
| localStorage in the guest menu: stories already viewed | Comfort feature; the information does not leave your device | until you delete it |
The legal basis for strictly necessary access is § 25(2) no. 2 TDDDG. Processing of any personal data that arises is based on Art. 6(1)(b) and (f) GDPR.
4. Audience measurement in the guest menu (cookie-free)
When guests open a menu, we count page views, search terms and clicks for the restaurant concerned. A guest is not recorded by name. The evaluation is carried out on behalf of the restaurant (see the Data Processing Agreement).
5. Recipients and processors
| Provider | Purpose | Location of processing |
|---|---|---|
| Supabase | Database, sign-in, file storage | Region: [check Supabase region] |
| Vercel | Hosting of the application | USA / global network |
| Resend | Sending emails (confirmation, password, notices, support) | USA |
| Sentry | Error monitoring (personal data is masked) | EU region |
| Google (Gemini API, Google sign-in) | Menu translation, optional sign-in with Google | USA |
| OpenRouter | Optional AI image enhancement | USA (forwarding to model providers) |
| Paddle | Payment processing as Merchant of Record (separate controller) | United Kingdom / EU |
For AI features, the menu text or photos you enter or upload are transmitted to the provider concerned. [clarify Gemini tier and use for model training]
6. Transfers to third countries
The service is operated from Türkiye. There is no adequacy decision of the EU Commission for Türkiye; we base access to data of customers from the EU on standard contractual clauses (Decision (EU) 2021/914). For providers in the USA we rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on standard contractual clauses.
7. Retention and deletion
- Account data and content are kept until you delete your account. When you delete the account in the dashboard, the data is deleted immediately.
- If you delete only a restaurant (branch), you can restore it for 30 days; after that, restoration is no longer possible.
- Invoice and payment data are kept for as long as statutory retention duties require; they are not deleted earlier when the account is deleted.
- Technical logs are kept only briefly.
8. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR). You can withdraw any consent at any time. Contact support@qrconnector.com for this. You can object at any time to information about similar services of our own by email, without any costs other than transmission costs at basic rates.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your residence or place of work.
9. Obligation to provide data, automated decisions
Name and email address are required to use an account; without them we cannot provide the service. No automated decision-making, including profiling, under Art. 22 GDPR takes place.