This Privacy Policy explains how Rapkat Baudunov collects, uses, discloses, and protects your information when you use the QR Events mobile application and the public event web pages accessible via QR code (together, the "Service"). By creating an account or otherwise using the Service, you agree to the practices described in this Policy.
This Policy applies to two groups of people:
a) Account information. When you register we collect your email address, display name, and password. Passwords are handled and stored in hashed form by our authentication provider; we never store your password in plain text. We also store your account creation date.
b) Content you create. Information you provide when creating or managing events, including event name, type, dates, optional description, optional location text, cover images, and event privacy/moderation settings.
c) Photos and media. Photos and videos uploaded by you or by guests to an event, and any associated metadata contained in those files (which may include information such as capture time). Cover images may be stored with a publicly accessible URL so they can be displayed on the public event page.
d) Guest-contributed content. When a guest uploads photos to a public event, we collect and store those photos so they can be shown to the event owner and, where applicable, in the public event gallery.
e) Device permissions. With your consent, the app accesses your device camera and photo library solely to let you select or capture images to upload. We do not access these unless you initiate an action that requires them.
f) In-app purchases. The app offers paid features (event activation/credit packs). Payments are processed by the Apple App Store; we do not receive or store your payment card details. We receive a purchase confirmation (receipt) from Apple to activate the corresponding features in your account.
g) Push notifications. With your consent, we send push notifications (for example, reminders one month/week/day before event photos are automatically deleted). To deliver them we store a push device token provided by Apple (APNs) and Firebase Cloud Messaging. You can disable notifications at any time in your device settings.
h) Technical and log data. Basic technical information necessary to operate and secure the Service (such as error logs and request metadata generated by our hosting provider).
i) Analytics data. We use Google Firebase Analytics to understand how the app is used (for example, screen views and feature usage) and to improve the Service. Firebase assigns an app-instance identifier and may collect device and usage information. We do not send your email or name to the analytics provider, and we do not use third-party advertising or cross-app tracking SDKs.
j) Crash and diagnostic data. We use Sentry to detect and diagnose crashes and errors. When an error occurs, Sentry may collect diagnostic information such as device model, operating system, a stack trace, and a short replay of the app screens leading up to the error, which helps us reproduce and fix the problem.
Where the GDPR or UK GDPR applies, we process your information on the following bases: performance of a contract (to provide the Service), your consent (e.g. for camera/photo-library access, notifications, and optional features), our legitimate interests (to secure and improve the Service), and compliance with legal obligations.
When you mark an event as public, its event page becomes reachable by anyone who has the QR code or link. Photos approved for the public gallery (or, if moderation is turned off, all uploaded photos) can be viewed and downloaded by anyone with that link. Do not make an event public, and do not upload photos, if you do not want that content to be accessible to others with the link.
We do not sell your personal information. We share information only as follows:
Your information may be processed and stored on servers located outside your country of residence. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for such transfers.
We retain your account information and content for as long as your account is active or as needed to provide the Service. When you delete an event or your account, we delete or anonymize the associated data within a reasonable period, except where we must retain it to comply with legal obligations or resolve disputes.
We use industry-standard measures, including encryption in transit and access controls, to protect your information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
To exercise any of these rights, contact us at rapkat99@gmail.com. You may also delete your account directly in the app, which removes your profile and associated content as described in Section 8.
The Service is not directed to children under the age of 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
The Service relies on Supabase for backend infrastructure, Google Firebase for usage analytics and push notifications, Sentry for crash and error diagnostics, and the Apple App Store to process purchases. Your use of public event links may also involve your device's web browser. These providers process data under their own privacy policies. We are not responsible for the privacy practices of third parties that operate independently of the Service.
We may update this Policy from time to time. We will revise the "Last updated" date above and, where appropriate, notify you in the app. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
If you have questions about this Policy or our data practices, contact us at:
Rapkat Baudunov
Email: rapkat99@gmail.com