Privacy Policy
Last Updated: July 2026
1. DATA CONTROLLER AND OPERATOR ANONYMITY
1.1. The platform payonqr.com (hereinafter referred to as the “Platform” or “Service”) is operated and maintained by an independent software developer and operator (hereinafter referred to as the “Operator”). 1.2. To protect proprietary software mechanics and reflecting the early-stage MVP/Beta status of the Platform, the Operator does not publicly disclose personal or corporate registry identifiers at this time. For any inquiries, data protection concerns, or legal notices regarding privacy, users may contact the Platform Administration directly at the following dedicated support email: [INSERT SUPPORT EMAIL, e.g., support@payonqr.com].
2. LEGAL STATUS AND SCOPE OF THE SERVICE (MVP / BETA PHASE)
2.1. The Service is provided strictly on an “as-is” and “as-available” basis for testing and voluntary deployment by independent Merchants who wish to connect their own infrastructure via Stripe Connect. 2.2. The Operator does not engage in direct commercial billing, does not issue direct tax invoices to users, and does not collect direct corporate revenue from individual transactions. All platform software commissions (application_fee) are executed, split, and collected automatically within the cloud architecture of the Stripe Connect ecosystem.
3. DATA PROCESSING ROLES
The Operator as a Data Controller: The Operator acts as a Data Controller solely for the personal data required to register, authenticate, and secure the operational profiles of Merchants and their authorized Staff.
The Operator as a Data Processor: Regarding transaction metadata flows (amounts, payment statuses, timestamps), the Operator acts strictly as a technical Data Processor on behalf of the Merchant. The Merchant retains the role of Data Controller for their business operations and is solely responsible for ensuring a lawful basis to track their Staff and process customer data via this software.
4. CATEGORIES OF DATA PROCESSED
4.1. Registered Users (Merchants & Staff):
Active operational email address used for system communication and login.
Business name, custom alias, or staff name (provided voluntarily for internal merchant dashboard statistics).
Cryptographically hashed password strings (plain text passwords are never stored).
Unique connected Stripe Account ID (e.g., acct_xxxxx), used to manage the automated API data bridge.
Technical security metadata: IP addresses, login attempts, session tokens, and functional cookies collected to protect against unauthorized system intrusions.
4.2. Transaction Metadata (Stored in Platform Database):
To facilitate accurate dynamic fee tier calculations and dashboard displays, the system logs:
Gross transaction value, currency Euro (€), date, exact timestamp, and final status (success, pending, failed, or refunded).
Third-party transaction reference tokens generated by Stripe: payment_intent_id and checkout_session_id.
Internal Staff Identifier indicating which sub-user generated the checkout link.
4.3. End-Customers (The Payers):
OUT OF PCI-DSS SCOPE NOTICE: The Platform does not collect, intercept, view, or store sensitive financial data such as credit/debit card numbers, cardholder names, expiration dates, or CVV security codes. When an end-customer scans a platform-generated QR code, the actual payment submission occurs entirely within an isolated, secure checkout window hosted on Stripe’s certified PCI-DSS Level 1 infrastructure. Our database only records automated cryptographic webhooks signaling transaction success or failure.
5. THIRD-PARTY ANALYTICS AND MARKETING TRACKING
5.1. The Platform integrates specialized digital tracking tools from external providers to evaluate system traffic, optimize user interface performance, and manage advertising campaigns. These scripts may collect online identifiers, browser fingerprints, and behavioral data:
Google Analytics & Google Ads: Used to analyze traffic volume, user navigation paths, and platform feature popularity.
Meta Pixel (Facebook/Instagram): Used to measure the conversion efficiency of digital advertisements and serve targeted remarketing messages on social networks. 5.2. These non-essential third-party tracking scripts are deployed strictly based on user opt-in consent via the interactive Cookie Banner on the website. Users can block or adjust their tracking preferences at any time.
6. INTERNATIONAL DATA TRANSFERS
As a globally accessible software interface, data collected by the Platform may be transferred to and maintained on cloud servers located outside the European Economic Area (EEA), primarily in the United States. We rely on certified cloud sub-processors (Stripe, Cloudflare, Google, Meta) that strictly utilize the European Commission’s Standard Contractual Clauses (SCCs) to ensure a legally equivalent level of data protection.
7. DATA RETENTION POLICY
Because the Operator does not issue corporate invoices or maintain traditional local accounting registries, personal data and transactional metadata are kept only for the lifespan of the active user profile. Upon receiving a verified account closure request, all related tables are permanently deleted or irreversibly anonymized within 30 days, except where data must be temporarily retained to resolve ongoing fraud reviews or chargeback disputes.
8. USER PRIVACY RIGHTS (GDPR / CCPA / GLOBAL)
Users worldwide retain the right to access their data, request corrections, or enforce the total erasure of their stored records (“Right to be Forgotten”). Given the MVP development state of the system, all profile deletions and data extraction requests are handled manually. To exercise your rights, you must send a clear request from your registered email address to our support contact: info @ payonqr.com