Privacy policy
Last updated: June 14, 2026
1. Data controller
Elsa Perez, publisher of the myQRvCard service, acts as the data controller for personal data collected via the Service. For any question, contact us via the contact form on the homepage.
2. Data collected
- Account: email, password (encrypted), unique identifier.
- vCard profile: name, contact details, organization, links, photos and other content you enter.
- Support: content of your messages when you contact us.
- Usage and technical: access logs, IP address, device and browser type, pages visited.
- Billing: payment data (card, billing address) is collected directly by Paddle, our official reseller — we do not have access to it.
3. Purposes and legal bases
- Create and manage your account — performance of the contract.
- Provide the Service (generating and hosting vCards) — performance of the contract.
- Ensure security, prevent fraud and abuse — legitimate interest.
- Improve the Service and produce anonymous statistics — legitimate interest.
- Provide support — performance of the contract.
- Send marketing communications — consent (you can unsubscribe at any time).
- Comply with our legal and accounting obligations — legal obligation.
4. Data recipients
We share personal data with:
- Our technical subprocessors (hosting, database, email delivery) acting on our instructions;
- Paddle, Merchant of Record, for sales, subscription management, payment, taxes and billing;
- Our professional advisors (accountants, lawyers) if necessary;
- Competent authorities when required by law.
5. International transfers
Some subprocessors may process data outside the European Union. In that case, we rely on the European Commission's standard contractual clauses or on an adequacy decision.
6. Retention period
Account data is retained as long as your account is active, then deleted or anonymized within a reasonable period after closure. Billing data is retained for the applicable legal period (up to 10 years). Technical logs are kept for a maximum of 12 months.
7. Your rights
Under GDPR, you have the rights of access, rectification, erasure, restriction, portability and objection regarding your personal data, as well as the right to withdraw your consent at any time. You can exercise these rights by contacting us; we respond within one month. You may also lodge a complaint with your local data protection authority.
8. Security
We implement appropriate technical and organizational measures to protect your data: encryption in transit (HTTPS), encryption at rest, access control, logging and regular backups.
9. Cookies
We use only essential cookies (session, authentication, preferences). No advertising or third-party tracking cookie is set without your consent.
10. Changes
This policy may be updated. The date of the last update appears at the top of this page.