Privacy Policy

Last updated: June 14, 2026

1. Who we are

PoftaQR is a digital menu platform for restaurants, cafes and bars, operated by Ivan Zhantalay, Romania (hereinafter referred to as "the Administrator" or "the Data Controller"). This Privacy Policy explains how we collect, use and protect your personal data when you use our platform.

2. Data we collect

  • Account information: email address, name or company name, VAT number (for business accounts), country.
  • Usage data: pages visited, features used, timestamps.
  • Payment information: The service is currently completely free — we do not collect banking data. Payment functionality is temporarily disabled.
  • Cookies: technical cookies for authentication and performance analytics.

3. How we use your data

  • To provide and maintain the service (create menus, generate QR codes).
  • To send transactional emails (account confirmation, technical alerts).

4. Legal basis (GDPR)

We process your data on the basis of: (a) contract performance — to deliver the service you signed up for; (b) legitimate interest — to improve the platform; (c) your consent — for optional cookies and marketing communications.

5. Data retention

We retain your data for as long as your account is active. If you delete your account, all personal data is removed within 30 days, except where we are required to keep it for legal or tax purposes.

6. Your rights

  • Access: request a copy of your personal data.
  • Rectification: correct inaccurate data.
  • Erasure: request deletion of your account and all associated data.
  • Portability: receive your data in a machine-readable format.

7. Third-party services

We use Supabase (database and authentication) and Vercel (hosting). Each service has its own privacy policy and processes data in accordance with GDPR. Stripe integration is temporarily inactive and will become active upon the launch of paid plans.

8. Contact us

If you have questions about this policy or want to exercise your rights, contact us at: contact@poftaqr.ro