Privacy
Most of what Kverton does happens in your browser and never reaches our server at all. This document covers the rest — the little we do process, why, and for how long.
Who the controller is
The data controller is Michal Řepásek, company ID 43758967, registered at Dlouhá 162, 250 63 Mratín, Czech Republic; a sole trader entered in the Czech Trade Register, not registered for VAT.
Contact for data protection matters:
podpora@kverton.cz,
Czech data box ID 8xp7ikv.
Given the scale and nature of the processing, we have not appointed a data protection officer. There is no large-scale processing of special categories of data and no systematic monitoring.
What we do not process
The content of your codes
When you create a static QR code — a payment, Wi-Fi, contact card or link — everything is computed on your device. Your account number, Wi-Fi password and phone number are never sent to our server, because there is no reason to: the browser can encode a QR code on its own.
Images you read
In the reader, neither an uploaded image nor the camera feed leaves your device. Decoding runs in the browser, just like encoding.
The single exception is the "Check and open" button: when you click it on a decoded link, the address from the code is sent to our server and compared against blocklists and heuristics. This happens only on your explicit click, never on its own. From the check we keep daily counters (how many checks, how many findings) and, for problematic findings, only the domain and the reason — we never store the full address, and the record is not linked to you or your IP address.
Your IP address
We do not store your IP address. It is used only while a request is being handled — for rate limiting and to derive an approximate location (country, region, city) for traffic statistics — and then discarded. From the browser header we keep only a two-letter language tag (e.g. "en"). There is no column for it in our database. Address-to-location mapping uses the DB-IP database stored on our own server — the address never leaves it.
For rate limiting, a fingerprint is derived from the IP address using a one-way function with a salt that rotates daily. It cannot be reversed, and the next day it no longer even matches itself.
Tracking cookies
We use no advertising or cross-site tracking cookies. There is no Google Analytics, no Facebook Pixel, nothing of the sort. That is also why you will find no consent banner here — there is nothing to consent to.
What we do process
Website traffic
We measure traffic with Umami, running on our own server. It uses no cookies and collects nothing that would identify an individual visitor. It records the page visited, the country, the device type and the referring site.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Page visited | Understanding what interests people | Legitimate interest | Aggregates, indefinite |
| Country | Deciding which languages to add | Legitimate interest | Aggregates, indefinite |
| Device type | Development and testing | Legitimate interest | Aggregates, indefinite |
| IP fingerprint | Rate limiting | Legitimate interest | 24 hours at most |
The legitimate interest under Article 6(1)(f) GDPR is operating and protecting the service and developing it further. Since no data identifying an individual is collected, the impact on your privacy is minimal.
Server logs
The web server records technical logs of requests. They serve only to detect errors and attacks and are deleted within 30 days.
When you write to us
If you contact us, we process the data you send us for as long as needed to handle your message, and afterwards for any period required by law.
Data in your browser
The application stores a few things on your device to save you work. This data never reaches us and is not our processing of personal data — it sits in your browser and is fully under your control.
- Details you filled in last time, for fields that do not change between uses, such as an account number. Passwords are never stored. Kept for 180 days.
- Work in progress, so that reloading the page does not wipe a filled-in form. Cleared when you close the browser tab.
- Favourite use cases you marked with a star.
You can remove all of it by clearing site data in your browser settings. Saved form details can also be cleared with the Forget link that appears below the form.
Payments and receipts
Subscriptions are paid by card via Stripe Payments Europe, Ltd. (Ireland). You enter card details on Stripe's page and we never receive them. Stripe receives from us the team owner's e-mail, team name, billing address and company IDs (if you fill them in) and an order reference; for every payment it returns its status and identifier. Stripe is an independent controller of that data for payment processing; its policy is at stripe.com/privacy.
We issue receipts with the billing details you entered. Receipts are accounting records kept for 10 years as required by law — deleting your account does not remove them. We e-mail the team owner about every payment operation.
Who we share data with
We do not sell it and do not pass it on for marketing. Only these parties have any access:
- the hosting provider running the server,
- the email provider, if you write to us.
Analytics runs on our own server, so it goes to nobody. Fonts are self-hosted, so loading a page connects you to no third-party network.
We do not transfer data outside the European Economic Area.
Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction of processing, data portability, and the right to object to processing based on legitimate interest.
Send requests to podpora@kverton.cz
or to data box 8xp7ikv. We reply within one month.
You also have the right to lodge a complaint with the supervisory authority: the Czech Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, Czech Republic.
Changes
We may update this policy if the way we run the service changes. Material changes will be announced on this page and the date below will be updated.