QR Relay

Privacy Policy

Incomplete policy — not final. Controller identity, retention periods or criteria, provider arrangements and international-transfer disclosures remain unconfirmed. Reviewed 8 October 2026.

Controller and contact

The Irish sole trader operating QR Relay is the controller of personal data processed to provide this service. The controller’s identity and contact details must be completed in the operator checklist. Send privacy requests to qrrelay@gmail.com.

Data and purposes

Legal bases

Account, room and purchased-access processing is necessary to perform the service contract you request (GDPR Article 6(1)(b)). Proportionate security, abuse prevention and troubleshooting rely on legitimate interests in keeping the service secure and reliable (Article 6(1)(f)), balanced against your rights. Records needed to meet applicable accounting or legal duties rely on legal obligation (Article 6(1)(c)). Any optional processing requiring consent must be explained and offered separately; camera permission alone is not a blanket GDPR consent.

Not yet confirmed: complete and approve the legitimate-interest assessment and identify the specific accounting/legal obligations and retention periods that apply to this operator.

Camera and content access

Camera frames are processed in your browser to detect QR codes. QR Relay does not upload camera video. Decoded QR content is transmitted to the service when published. Realtime messages distribute event metadata; protected payloads are returned through an authorized access request. This is access control, not end-to-end encryption. Authorized recipients can copy the content. Links you open lead to separate websites that may receive your IP address and other browser information.

Who receives data

Supabase provides authentication, database and realtime services. The configured project region is eu-west-1 (Ireland). Email/password signup and email verification are enabled; anonymous login, Google OAuth and other external login providers are disabled. Stripe provides Checkout, subscription billing and its Customer Portal. Sites hosting and its Cloudflare infrastructure deliver the application and process network requests. Google Fonts receives requests for the typefaces currently loaded by the application. Support email is handled using Gmail. Room participants receive the information needed for their room and authorized QR content; public discovery shows intentionally public room metadata.

Not yet confirmed: verify the contracting entities, processor agreements, support-email account arrangements, infrastructure subprocessors and enabled OAuth/email providers. The authentication email delivery provider and its processing arrangements require confirmation; the public authentication settings do not expose SMTP configuration.

Retention

Room expiry or host closure ends access but does not delete the room, its QR events or protected payloads. The current publishing function retains events; the history shown on screen is not a deletion policy. No scheduled database cleanup job or deployed Edge Function was found in the audit. The access ledger records lifetime free-open usage independently of event cleanup. Security attempt records older than one minute are removed when that account makes a subsequent relevant request; this is not a guaranteed one-minute retention limit. Account and billing records have no application-configured automatic deletion period.

Not yet confirmed: approve and implement a schedule for accounts, expired rooms, QR payloads/history, access ledgers, auth/security logs, billing records, support correspondence and backups, including deletion triggers and justified legal holds. No fixed deletion period is promised until verified.

International transfers

An Irish database region does not mean that all processing stays in the EEA. Supabase’s published DPA and transfer information describe international support/operations and Standard Contractual Clauses. Stripe acts as a processor for some activities and as a controller for others, including compliance and fraud prevention. OpenAI’s ChatGPT Sites DPA covers hosted personal data and provides for SCCs or adequacy decisions for relevant transfers. Not yet confirmed: confirm account-specific contracting/acceptance records, the email provider, backup/log retention, Gmail arrangements and any provider-specific transfer assessments. We do not claim all data stays in the EU.

Your rights

Depending on the circumstances, you can request access, correction, deletion, restriction, portability and object to processing based on legitimate interests. Where consent is the basis, you may withdraw it without affecting earlier lawful processing. Rights are subject to applicable legal conditions. We may request proportionate identity verification and will respond within the GDPR’s applicable time limits, normally one month, explaining any lawful extension.

Use our account/data deletion request instructions. You may complain to the Irish Data Protection Commission or your competent supervisory authority. The audited application code does not use QR content for advertising. Automatic entitlement and security checks control access. The operator must confirm the complete processing inventory and whether any automated processing has legal or similarly significant effects before this notice is final.

Provider information

Read the Supabase DPA and subprocessor list, Stripe DPA, and ChatGPT Sites DPA. Contact support to request further information about safeguards.

Storage technologies and updates

See the Cookies & Local Storage notice. Material changes to this policy will be identified with an updated date and communicated where appropriate.