Skip to content

Privacy Policy

Last Updated: August 2026

1. DATA CONTROLLER AND OPERATOR IDENTITY

1.1. The platform payonqr.com (hereinafter referred to as the “Platform” or “Service”) is operated and maintained by Svetlozar Dobrev, an independent (self-employed) software developer registered in the Republic of Bulgaria under registration number (BULSTAT) 181244853, operating under the brand name INFOBGNET (hereinafter referred to as the “Operator”).

1.2. The Operator is the Data Controller for the purposes of the GDPR. For any inquiries, data protection concerns, exercise of data subject rights, or legal notices, users may contact the Operator by email at info@payonqr.com. This is the designated contact channel for all such matters.

2. LEGAL STATUS AND SCOPE OF THE SERVICE (MVP / BETA PHASE)

2.1. The Service is provided strictly on an “as-is” and “as-available” basis for testing and voluntary deployment by independent Merchants who wish to connect their own infrastructure via Stripe Connect. 2.2. The Operator does not engage in direct commercial billing, does not issue direct tax invoices to users, and does not collect direct corporate revenue from individual transactions. All platform software commissions (application_fee) are executed, split, and collected automatically within the cloud architecture of the Stripe Connect ecosystem.

3. DATA PROCESSING ROLES

The Operator as a Data Controller: The Operator acts as a Data Controller solely for the personal data required to register, authenticate, and secure the operational profiles of Merchants and their authorized Staff.

The Operator as a Data Processor: Regarding transaction metadata flows (amounts, payment statuses, timestamps), the Operator acts strictly as a technical Data Processor on behalf of the Merchant. The Merchant retains the role of Data Controller for their business operations and is solely responsible for ensuring a lawful basis to track their Staff and process customer data via this software.

4. CATEGORIES OF DATA PROCESSED
4.1. Registered Users (Merchants & Staff):

Active operational email address used for system communication and login.

Business name, custom alias, or staff name (provided voluntarily for internal merchant dashboard statistics).

Cryptographically hashed password strings (plain text passwords are never stored).

Unique connected Stripe Account ID (e.g., acct_xxxxx), used to manage the automated API data bridge.

Technical security metadata: IP addresses, login attempts, session tokens, and functional cookies collected to protect against unauthorized system intrusions.

4.2. Transaction Metadata (Stored in Platform Database):

To facilitate accurate dynamic fee tier calculations and dashboard displays, the system logs:

Gross transaction value, currency Euro (€), date, exact timestamp, and final status (success, pending, failed, or refunded).

Third-party transaction reference tokens generated by Stripe: payment_intent_id and checkout_session_id.

Internal Staff Identifier indicating which sub-user generated the checkout link.

4.3. End-Customers (The Payers):

OUT OF PCI-DSS SCOPE NOTICE: The Platform does not collect, intercept, view, or store sensitive financial data such as credit/debit card numbers, cardholder names, expiration dates, or CVV security codes. When an end-customer scans a platform-generated QR code, the actual payment submission occurs entirely within an isolated, secure checkout window hosted on Stripe’s certified PCI-DSS Level 1 infrastructure. Our database only records automated cryptographic webhooks signaling transaction success or failure.

5. THIRD-PARTY ANALYTICS AND MARKETING TRACKING

5.1. The Platform uses the following third-party tools. These collect online identifiers, and in some cases hashed contact identifiers, and are used to measure traffic, improve the site, and measure advertising performance:

Google Analytics 4 (Google LLC): Analyses traffic volume, user navigation paths, and feature popularity using pseudonymised identifiers.

Ahrefs Web Analytics (Ahrefs Pte. Ltd.): Measures page views and referral sources.

Meta Pixel (Meta Platforms, Inc.): Measures the conversion efficiency of advertising on Facebook and Instagram and enables remarketing.

Meta Conversions API (CAPI): Transmits conversion events server-to-server from our web server to Meta, in addition to the browser-side pixel. These events may include hashed identifiers (such as an email address or IP address) used to match an event to a Meta account.

5.2. These tools are not active by default. They are deployed strictly after the user gives explicit opt-in consent via the cookie banner, and this applies equally to browser-side and server-side (Conversions API) transmission. If consent is refused, no analytics or marketing identifiers are collected or transmitted. Consent can be changed or withdrawn at any time via the “Cookie settings” link in the site footer. The Platform additionally implements Google Consent Mode v2, which initialises Google’s tag in a denied state until consent is granted.

5.3. See the Cookie Policy for the full, current list of cookies and tracking technologies.

6. INTERNATIONAL DATA TRANSFERS

As a globally accessible software interface, data collected by the Platform may be transferred to and maintained on cloud servers located outside the European Economic Area (EEA), primarily in the United States. We rely on certified cloud sub-processors (Stripe, Cloudflare, Google, Meta) that strictly utilize the European Commission’s Standard Contractual Clauses (SCCs) to ensure a legally equivalent level of data protection.

7. DATA RETENTION POLICY

Because the Operator does not issue corporate invoices or maintain traditional local accounting registries, personal data and transactional metadata are kept only for the lifespan of the active user profile. Upon receiving a verified account closure request, all related tables are permanently deleted or irreversibly anonymized within 30 days, except where data must be temporarily retained to resolve ongoing fraud reviews or chargeback disputes.

8. USER PRIVACY RIGHTS (GDPR / CCPA / GLOBAL)

Users worldwide retain the right to access their data, request corrections, or enforce the total erasure of their stored records (“Right to be Forgotten”). Given the MVP development state of the system, all profile deletions and data extraction requests are handled manually. To exercise your rights, send a clear request from your registered email address to info@payonqr.com.