1. Who is responsible for your data?
İsmet Erdoğan is responsible for the personal data described in this notice.
- Legal entity
- İsmet Erdoğan
- Address
- PRE-LAUNCH - PUBLIC ACCESS DISABLED
2. Data we process
| Data group | Examples |
|---|---|
| Identity and contact | Name and email address |
| Account and security | Password hash, session-token hash, session and password-reset timestamps, and rate-limit records |
| Service content | Menus, items, prices, images, business profile, contact details, and opening hours |
| AI requests | Menu files or text, design instructions, and generated results when you choose an AI feature |
| Usage and analytics | Menu-open time, broad traffic source, device class, language, searches, and item or category visibility |
| Service records | Plan state, AI-credit movements, and publish or update timestamps |
We do not retain a visitor's raw IP address, referring URL, or full browser string in menu analytics. An IP address may be used momentarily for security rate limiting; only a SHA-256 digest is held in the short-lived security record. Device and traffic details are reduced to broad categories before storage.
3. Why we process data
- To create accounts, authenticate users, and provide the QR-menu service.
- To save, publish, back up, and maintain menus at the account owner's request.
- To prevent abuse, enforce rate limits, and protect the service and its users.
- To provide limited first-party menu analytics and improve the product.
- To meet legal obligations and respond to valid requests from public authorities.
Where applicable, we rely on performing our contract, complying with law, and legitimate interests such as service security and limited, identifier-free menu-open measurement. Optional interaction analytics that use a persistent random browser identifier run only after the visitor allows them. We do not ask you to upload sensitive personal data. Account owners must have the right to publish any personal data they add to menu content and must give any required notices.
4. How data is collected
Data comes from account and recovery forms, uploaded files, menu editing and publishing actions, support requests, server requests, first-party cookies, and browser storage. Collection may be automatic or partly automatic.
5. Service providers and international processing
- Hosting and infrastructure providers: to run the application, database, and backups.
- OpenAI: only when an account owner starts menu extraction, translation, theme, or product-image generation; the relevant input and output are processed.
- Resend: to deliver password-reset emails using the recipient address and message content.
- Public authorities: where disclosure is legally required.
Providers may process data outside your country. Where data-protection law requires safeguards for an international transfer, the operator must assess and put the appropriate safeguards in place before launch in that market.
6. Retention
- Account and menu records remain while the account is open and are removed from the active system when the account is deleted.
- Sessions last 24 hours by default or up to 30 days when “Remember me” is selected.
- Password-reset links expire after 30 minutes and can be used only once.
- AI result caches expire after 14 or 30 days, depending on the operation.
- After analytics is allowed, the anonymous visitor identifier remains in browser storage for up to 180 days; the server stores only its digest.
- Deleted records may remain for a limited period until the normal backup cycle completes.
Records may be retained longer only where law requires it or for a live legal claim, and only for that purpose.
7. Your choices and rights
Depending on where you live and which law applies, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, and to receive a portable copy. You may also have the right to complain to your local data-protection authority. These rights can be subject to legal exceptions.
People in the EEA can consult the official text of the General Data Protection Regulation.
8. Contact and requests
Send a request with enough information to verify your identity and understand the request to privacy@easyqrservice.com or to PRE-LAUNCH - PUBLIC ACCESS DISABLED. We will respond within the period required by the law that applies to your request.