Last Updated: February 2026
EventQRCard ("we", "us", "our") is operated by an individual developer based in Romania. For the purposes of the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the developer is the Data Controller for Host account data. Event Hosts act as independent Data Controllers for the User Content (photos/videos) uploaded by their Guests. Contact for all privacy matters: [email protected]
Account Data: We store Host email addresses and hashed passwords for authentication and transactional communications (e.g., event notifications, material Terms change notices). Legal basis: GDPR Art. 6(1)(b) — necessary for the performance of the contract with the Host. Retention: Email addresses are retained for as long as the Host account is active, plus a maximum of 30 days after account deletion to allow for dispute resolution.
Guest Privacy: No accounts are required for Guests to upload media. Legal basis for processing Guest-uploaded content: GDPR Art. 6(1)(a) — consent provided by the Guest at the point of upload.
Consent of Depicted Persons: User Content uploaded to the Platform may contain images of individuals who are not the uploader. Under GDPR, the image of an identifiable living person constitutes personal data. The Platform processes such data solely on the basis that the uploader and the Host have represented that all depicted individuals have given their consent. The Platform does not independently verify this consent. If you are an individual whose image appears in an upload and you have not given consent, or you wish to withdraw previously given consent, you have the right to request deletion of that content. Please contact the event Host directly, or, if the Host is unresponsive, contact us at [email protected] and we will investigate and act accordingly.
IP Hashing: We collect IP addresses and browser strings for security purposes (rate limiting, abuse prevention, DDoS mitigation), but these are immediately and irreversibly hashed using a one-way cryptographic function before storage. We cannot re-identify individuals from hashed IP data. Legal basis: GDPR Art. 6(1)(f) — legitimate interests in maintaining platform security. Note: Under GDPR, hashed IP addresses may still be considered personal data under some legal interpretations; we treat them as personal data and apply all corresponding protections. Hashed logs are retained for up to 90 days for security auditing, then deleted.
Metadata Scrubbing: Our backend automatically removes all EXIF metadata (GPS, camera models, device serial numbers, timestamps) from photographs and videos.
Cookies and Local Storage: We use session cookies strictly necessary for Host authentication and CSRF protection tokens. We do not use tracking cookies, advertising cookies, or third-party analytics scripts. No cookie consent banner is required for strictly necessary cookies under ePrivacy rules; however, we disclose this use here for full transparency.
We use trusted providers including Cloudflare (DDoS protection and storage) and our Merchant of Record (payment processing). These providers are bound by strict data processing agreements. Cloudflare processes data under Standard Contractual Clauses (SCCs) for international transfers, ensuring GDPR-compliant data handling. Our Merchant of Record acts as an independent data controller for payment data; refer to their privacy policy for details.
International Data Transfers: Our infrastructure provider (Cloudflare) may store or process data in locations outside the European Economic Area (EEA). Cloudflare provides appropriate safeguards through Standard Contractual Clauses (SCCs) approved by the European Commission.
As a service provided from Romania, we comply with GDPR. You have the following rights, which you may exercise by contacting us at [email protected]:
We will respond to all requests within 30 days.
The Platform is not directed at children under 16. Under Romanian law implementing GDPR Article 8, the minimum age for valid digital consent to data processing is 16. We do not knowingly collect personal data from individuals under 16, and Guests under 16 may not upload media under any circumstances. The Host is solely responsible for preventing under-16s from submitting uploads at their event. If you become aware that a minor under 16 has uploaded content, please notify us immediately at [email protected] and we will take prompt action to permanently delete the data.
We may update this Privacy Policy from time to time. Material changes will be communicated to registered Hosts via email at least 14 days before taking effect. The updated policy will be posted on the Platform with a revised "Last Updated" date.