← Back to Home

Privacy Policy

Last Updated: February 2026

Introduction and Identity of the Data Controller

EventQRCard ("we", "us", "our") is operated by an individual developer based in Romania. For the purposes of the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the developer is the Data Controller for Host account data. Event Hosts act as independent Data Controllers for the User Content (photos/videos) uploaded by their Guests. Contact for all privacy matters: [email protected]

1. Data Collection and Anonymization

Account Data: We store Host email addresses and hashed passwords for authentication and transactional communications (e.g., event notifications, material Terms change notices). Legal basis: GDPR Art. 6(1)(b) — necessary for the performance of the contract with the Host. Retention: Email addresses are retained for as long as the Host account is active, plus a maximum of 30 days after account deletion to allow for dispute resolution.

Guest Privacy: No accounts are required for Guests to upload media. Legal basis for processing Guest-uploaded content: GDPR Art. 6(1)(a) — consent provided by the Guest at the point of upload.

Consent of Depicted Persons: User Content uploaded to the Platform may contain images of individuals who are not the uploader. Under GDPR, the image of an identifiable living person constitutes personal data. The Platform processes such data solely on the basis that the uploader and the Host have represented that all depicted individuals have given their consent. The Platform does not independently verify this consent. If you are an individual whose image appears in an upload and you have not given consent, or you wish to withdraw previously given consent, you have the right to request deletion of that content. Please contact the event Host directly, or, if the Host is unresponsive, contact us at [email protected] and we will investigate and act accordingly.

IP Hashing: We collect IP addresses and browser strings for security purposes (rate limiting, abuse prevention, DDoS mitigation), but these are immediately and irreversibly hashed using a one-way cryptographic function before storage. We cannot re-identify individuals from hashed IP data. Legal basis: GDPR Art. 6(1)(f) — legitimate interests in maintaining platform security. Note: Under GDPR, hashed IP addresses may still be considered personal data under some legal interpretations; we treat them as personal data and apply all corresponding protections. Hashed logs are retained for up to 90 days for security auditing, then deleted.

Metadata Scrubbing: Our backend automatically removes all EXIF metadata (GPS, camera models, device serial numbers, timestamps) from photographs and videos.

Cookies and Local Storage: We use session cookies strictly necessary for Host authentication and CSRF protection tokens. We do not use tracking cookies, advertising cookies, or third-party analytics scripts. No cookie consent banner is required for strictly necessary cookies under ePrivacy rules; however, we disclose this use here for full transparency.

2. Use of Data and Security

  • Core Service: Data is used exclusively to operate the file-transfer conduit.
  • No Sale of Data: We do not sell data, run ads, or train AI models on your photos.
  • Infrastructure: Media is hosted on Cloudflare R2. The 60-day auto-deletion policy minimizes long-term risk. Passwords are hashed using a strong one-way algorithm (such as bcrypt); plain-text passwords are never stored or transmitted.

3. Deletion and Access

  • Auto-Deletion: All media is strictly scheduled for permanent deletion 60 days after upload. This data cannot be recovered once deleted.
  • Manual Deletion: Hosts may manually delete their entire event and all associated files at any time.
  • Asymmetric Access: Guests can only upload; they cannot view or download media uploaded by others. Hosts hold exclusive access to the dashboard.

4. Third-Party Processors

We use trusted providers including Cloudflare (DDoS protection and storage) and our Merchant of Record (payment processing). These providers are bound by strict data processing agreements. Cloudflare processes data under Standard Contractual Clauses (SCCs) for international transfers, ensuring GDPR-compliant data handling. Our Merchant of Record acts as an independent data controller for payment data; refer to their privacy policy for details.

International Data Transfers: Our infrastructure provider (Cloudflare) may store or process data in locations outside the European Economic Area (EEA). Cloudflare provides appropriate safeguards through Standard Contractual Clauses (SCCs) approved by the European Commission.

5. Your Rights (GDPR)

As a service provided from Romania, we comply with GDPR. You have the following rights, which you may exercise by contacting us at [email protected]:

  • Right of Access (Art. 15): Request a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16): Request correction of inaccurate personal data.
  • Right to Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten"). Users may request data deletion before the 60-day window via the Event Host or directly by contacting us.
  • Right to Restriction of Processing (Art. 18): Request that we restrict processing of your data.
  • Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
  • Right to Object (Art. 21): Object to processing based on legitimate interests.
  • Right to Withdraw Consent (Art. 7(3)): Where processing is based on consent, withdraw it at any time.

We will respond to all requests within 30 days.

6. Children's Privacy

The Platform is not directed at children under 16. Under Romanian law implementing GDPR Article 8, the minimum age for valid digital consent to data processing is 16. We do not knowingly collect personal data from individuals under 16, and Guests under 16 may not upload media under any circumstances. The Host is solely responsible for preventing under-16s from submitting uploads at their event. If you become aware that a minor under 16 has uploaded content, please notify us immediately at [email protected] and we will take prompt action to permanently delete the data.

7. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to registered Hosts via email at least 14 days before taking effect. The updated policy will be posted on the Platform with a revised "Last Updated" date.