Create

Privacy

Most of what Kverton does happens in your browser and never reaches our server at all. This document covers the rest — the little we do process, why, and for how long.

Who the controller is

The data controller is Michal Řepásek, company ID 43758967, registered at Dlouhá 162, 250 63 Mratín, Czech Republic; a sole trader entered in the Czech Trade Register, not registered for VAT.

Contact for data protection matters: podpora@kverton.cz, Czech data box ID 8xp7ikv.

Given the scale and nature of the processing, we have not appointed a data protection officer. There is no large-scale processing of special categories of data and no systematic monitoring.

What we do not process

The content of your codes

When you create a static QR code — a payment, Wi-Fi, contact card or link — everything is computed on your device. Your account number, Wi-Fi password and phone number are never sent to our server, because there is no reason to: the browser can encode a QR code on its own.

You do not have to take this on trust. Open your developer tools, the Network tab, and fill in the form. You will see no outgoing request while typing.

Images you read

In the reader, neither an uploaded image nor the camera feed leaves your device. Decoding runs in the browser, just like encoding.

The single exception is the "Check and open" button: when you click it on a decoded link, the address from the code is sent to our server and compared against blocklists and heuristics. This happens only on your explicit click, never on its own. From the check we keep daily counters (how many checks, how many findings) and, for problematic findings, only the domain and the reason — we never store the full address, and the record is not linked to you or your IP address.

Your IP address

We do not store your IP address. It is used only while a request is being handled — for rate limiting and to derive an approximate location (country, region, city) for traffic statistics — and then discarded. From the browser header we keep only a two-letter language tag (e.g. "en"). There is no column for it in our database. Address-to-location mapping uses the DB-IP database stored on our own server — the address never leaves it.

For rate limiting, a fingerprint is derived from the IP address using a one-way function with a salt that rotates daily. It cannot be reversed, and the next day it no longer even matches itself.

Tracking cookies

We use no advertising or cross-site tracking cookies. There is no Google Analytics, no Facebook Pixel, nothing of the sort. That is also why you will find no consent banner here — there is nothing to consent to.

What we do process

Website traffic

We measure traffic with Umami, running on our own server. It uses no cookies and collects nothing that would identify an individual visitor. It records the page visited, the country, the device type and the referring site.

DataPurposeLegal basisRetention
Page visitedUnderstanding what interests peopleLegitimate interestAggregates, indefinite
CountryDeciding which languages to addLegitimate interestAggregates, indefinite
Device typeDevelopment and testingLegitimate interestAggregates, indefinite
IP fingerprintRate limitingLegitimate interest24 hours at most

The legitimate interest under Article 6(1)(f) GDPR is operating and protecting the service and developing it further. Since no data identifying an individual is collected, the impact on your privacy is minimal.

Server logs

The web server records technical logs of requests. They serve only to detect errors and attacks and are deleted within 30 days.

When you write to us

If you contact us, we process the data you send us for as long as needed to handle your message, and afterwards for any period required by law.

Data in your browser

The application stores a few things on your device to save you work. This data never reaches us and is not our processing of personal data — it sits in your browser and is fully under your control.

You can remove all of it by clearing site data in your browser settings. Saved form details can also be cleared with the Forget link that appears below the form.

Payments and receipts

Subscriptions are paid by card via Stripe Payments Europe, Ltd. (Ireland). You enter card details on Stripe's page and we never receive them. Stripe receives from us the team owner's e-mail, team name, billing address and company IDs (if you fill them in) and an order reference; for every payment it returns its status and identifier. Stripe is an independent controller of that data for payment processing; its policy is at stripe.com/privacy.

We issue receipts with the billing details you entered. Receipts are accounting records kept for 10 years as required by law — deleting your account does not remove them. We e-mail the team owner about every payment operation.

Who we share data with

We do not sell it and do not pass it on for marketing. Only these parties have any access:

Analytics runs on our own server, so it goes to nobody. Fonts are self-hosted, so loading a page connects you to no third-party network.

We do not transfer data outside the European Economic Area.

Your rights

Under the GDPR you have the right of access, rectification, erasure, restriction of processing, data portability, and the right to object to processing based on legitimate interest.

For traffic statistics, exercising some of these rights is practically impossible — the data does not identify you, so we cannot match a request to it. That is not an excuse; it is a consequence of storing nothing identifiable about you.

Send requests to podpora@kverton.cz or to data box 8xp7ikv. We reply within one month.

You also have the right to lodge a complaint with the supervisory authority: the Czech Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, Czech Republic.

Changes

We may update this policy if the way we run the service changes. Material changes will be announced on this page and the date below will be updated.

Effective 1 September 2026.