Privacy Policy

Privacy Policy

← Home

Last updated: 31 August 2026

1. Who We Are

EvenQR ("we", "us") is a photo-sharing platform that lets event organizers collect photos and videos from their guests. The data controller responsible for your personal data is:

LAZAR RAUL-ANDREI P.F.A.
Authorised natural person (Persoană Fizică Autorizată) registered in Romania
Tax identification number (CUI): 54741496
Contact for privacy matters: contact@evenqr.com

This policy explains how we collect, use, and protect personal data in compliance with the EU General Data Protection Regulation (GDPR) and applicable Romanian law.

2. Data We Collect

Account data: Your name, email address, and a hashed version of your password (we never store passwords in plain text). If you sign in with Google, we receive your name, email address, and Google account identifier from Google instead of a password.

Event data: Event titles, subtitles, dates, unique links (slugs), gallery access settings, and any gallery password you set.

Photos & videos: Files uploaded by you or your guests, together with basic technical metadata (file type, size, upload timestamp). Guests can upload without creating an account and may optionally enter a display name; that name is shown only to the event organizer and is deleted together with the event.

Payment data: When you buy a plan or a boost, payment is processed by Stripe. We receive a transaction reference, amount, plan purchased, and payment status. We do not receive or store your full card number.

Support & contact messages: If you use the contact form, we store the name, email address, subject, and message you provide.

Newsletter / waitlist: If you sign up for updates, we store your email address and language preference until you unsubscribe.

Push notifications: If you enable browser notifications, we store the push subscription token issued by your browser so we can alert you when an event nears its storage limit.

Technical & log data: Like most web services, our infrastructure and our application logs automatically record data such as your IP address, browser user-agent, request timestamps, and pages or endpoints accessed. This is used for security, abuse prevention, rate limiting, and debugging.

3. How We Use Your Data

We use personal data to:
• Provide the service — create and run events, store and display photos, authenticate your account, process payments, and send transactional emails (email verification, password resets, receipts).
• Keep the platform secure — bot protection, rate limiting, fraud and abuse prevention, and audit logging.
• Communicate with you — respond to support requests and, if you subscribed, send occasional product updates. Every marketing email includes an unsubscribe link and you can opt out at any time.
• Comply with legal obligations, including tax and accounting rules for payments.

We do not sell your data and we do not use it for advertising or third-party marketing.

4. Legal Basis for Processing

We rely on the following GDPR legal bases:
Performance of a contract (Art. 6(1)(b)) — providing the service you signed up for, including storage and payment processing.
Legitimate interests (Art. 6(1)(f)) — platform security, abuse prevention, and basic operational logging.
Consent (Art. 6(1)(a)) — optional features such as the newsletter and browser push notifications; you can withdraw consent at any time.
Legal obligation (Art. 6(1)(c)) — retaining payment and invoicing records.

5. Cookies & Local Storage

We use only strictly necessary cookies — no analytics, advertising, or cross-site tracking:
Session cookie — keeps you signed in (expires after 7 days).
Language cookie — remembers your English/Romanian preference.
CSRF token cookie — protects forms against cross-site request forgery.
Gallery access cookie — remembers that you entered the correct password for a protected gallery.

Cloudflare, our hosting provider, may set its own strictly necessary cookie for security and bot management. We also use your browser's local storage to remember minor preferences (for example, a guest's uploader name and whether you have seen the onboarding guide). Cloudflare Turnstile and Google Sign-In may set cookies or storage on the pages where they are used.

6. Third-Party Service Providers

We share personal data with the following processors and providers, only as needed to run the service:
Cloudflare — hosting, application runtime, database (D1), file storage (R2), CDN, DNS, and bot protection (Turnstile).
Stripe — payment processing for plans and boosts.
Resend — delivery of transactional emails (verification, password reset, receipts).
Google — "Sign in with Google" authentication (optional), and Google Fonts. When your browser loads a page, it requests font files from Google's servers, which discloses your IP address to Google.
Your browser's push service (e.g. Google, Mozilla, Apple) — delivery of browser notifications if you enable them.

We do not use analytics, advertising, or social-media tracking services.

7. International Data Transfers

Some of our providers (including Cloudflare, Stripe, Resend, and Google) are based in or process data in the United States and other countries outside the European Economic Area. Where personal data is transferred outside the EEA, it is protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

8. Data Storage & Security

Data is stored on Cloudflare's infrastructure (Workers, D1 database, R2 object storage). Passwords are hashed with PBKDF2-HMAC-SHA-256. Session tokens are stored only as SHA-256 hashes. All connections use HTTPS. Access to production systems is restricted. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Data Retention

Account data — kept while your account is active; erased when you delete your account.
Events, photos, and videos — kept until you delete the event, until the retention countdown for the event expires, or until your account is deleted, whichever comes first. Deletion from storage is permanent.
Event history record — when an event is deleted, we keep a minimal audit record (event title, plan, dates, photo/storage totals, and the organizer's name and email) for up to 12 months for security, abuse, and accounting purposes. It contains no photos.
Payment records — retained for 10 years to meet tax and accounting obligations.
Contact messages — retained for up to 12 months.
Server and security logs — retained for up to 90 days.
Newsletter subscription — kept until you unsubscribe.

10. Your Rights

Under GDPR you have the right to:
Access your personal data
Rectify inaccurate data
Erase your data ("right to be forgotten")
Restrict or object to processing
Data portability — receive your data in a structured, machine-readable format
Withdraw consent at any time, without affecting prior processing

You can delete your account and its data directly from your profile. For any other request, contact us at contact@evenqr.com; we respond within one month. You also have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP, www.dataprotection.ro), or with the data protection authority in your EU country of residence.

11. Data Breach Notification

If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it and, where the risk is high, inform affected users without undue delay.

12. Children's Privacy

The service is not directed to children. You must be at least 18 years old to create an account. We do not knowingly collect personal data from children. Organizers are responsible for obtaining any consent required before uploading photos of minors.

13. Changes to This Policy

We may update this policy from time to time. We will post the updated version here with a new "last updated" date and, for significant changes, notify registered users by email or an on-platform notice.

14. Contact

For questions about this policy or your personal data, contact us at contact@evenqr.com. We have not appointed a Data Protection Officer, as we are not required to; privacy requests are handled at the address above.
🇷🇴 RO