Privacy Policy
Effective: 2 October 2026
In accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR), this notice explains what personal data we process when you use GenerateMyQRCodes (generatemyqrcodes.com), for what purpose, on what legal basis and for how long, as well as what rights you have.
1. The data controller
- Name: TourCierge s. r. o.
- Registered office: Karpatské námestie 10A, 831 06 Bratislava – mestská časť Rača, Slovenská republika
- Registration: IČO 57383898 · Obchodný register Mestského súdu Bratislava III, oddiel Sro, vložka č. 194953/B
- Email: help@testmyabilities.com
For data protection matters, you can reach us at help@testmyabilities.com.
2. In brief
- There is no registration and no password; each code is managed with its private management link, and subscribers can also sign in with a single-use code sent by email.
- We store no personal data about the people who scan your codes – only the number of scans per day.
- Payments are processed by Stripe; we do not see or store your card details.
- We do not use analytics, advertising or tracking cookies.
3. Creating and running a QR code
Data processed: the destination you enter (URL), the name of the code, its design settings (colours, pattern, label, uploaded logo), the code’s short identifier and private management token, the time it was created and the times it is active until, and the number of scans per day. The destination and the name only contain personal data if you enter such data (for example a link to a personal profile).
Purpose: providing the Service – forwarding visitors, the management page and the statistics. Legal basis: performance of a contract (Article 6(1)(b) GDPR).
Retention: until you delete the code; codes that were never activated for 30 days; paused codes for 12 months after they paused.
4. Preventing abuse
Data processed: the IP address of the device that creates a code, stored only as a salted, irreversible hash, together with the time of creation.
Purpose: limiting the mass, automated creation of codes (at most 20 per hour). Legal basis: our legitimate interest in the secure and stable operation of the Service (Article 6(1)(f) GDPR). Retention: together with the code.
5. Subscription and payment
If you subscribe, the data you enter on the payment form is processed by Stripe; what we receive is the data needed to keep a record of your subscriptions.
- Data processed: email address, the customer and subscription identifiers assigned by Stripe, the status and periods of each subscription and the code it belongs to, the amount and date of payments, the type of payment method (for example card, and its last 4 digits) and – if the payment form asks for them – the billing country and postal code.
- Purpose: creating and fulfilling subscriptions, collecting fees, invoicing and customer service.
- Legal basis: performance of a contract (Article 6(1)(b) GDPR); for keeping accounting records, a legal obligation (Article 6(1)(c) GDPR).
- Retention: for as long as the subscription exists; after it ends, we keep the accounting records for 10 years under section 35 of the Slovak Accounting Act (Act No. 431/2002 Coll.). We delete the other data at your request after the subscription ends.
Payments are processed by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland, which is an independent controller with regard to payment data and fraud prevention. You can find information about its data processing at https://stripe.com/privacy.
6. Signing in with an email code
If you have subscribed, you can sign in on the “My codes” page with a single-use code sent to you by email, and see the codes paid for with your email address on any device.
Data processed: the email address you enter, the sign-in code (stored only as a keyed hash), its expiry time and the number of failed attempts; after signing in, a signed session cookie that contains your email address. To find your codes, we look up the Stripe customers with this email address.
Purpose: giving subscribers access to their codes. Legal basis: performance of a contract (Article 6(1)(b) GDPR). Retention: the sign-in code for 10 minutes (it is deleted as soon as it is used); the session cookie for 180 days, or until you sign out.
We send a code only if the address belongs to a subscriber; the page shows the same message either way. Sign-in emails are sent by Resend, Inc., USA (https://resend.com) as a data processor.
7. Contacting us
If you write to us, we use your name, email address and the content of your message to answer you. Legal basis: our legitimate interest in handling enquiries (Article 6(1)(f) GDPR). Retention: for 1 year after the matter is closed.
8. Technical logs
When the site is served – as with any website – the hosting provider’s servers record technical data: IP address, time of the request, the requested address and the browser type. This also happens when a QR code is scanned. Purpose: the secure and uninterrupted operation of the Service, and the detection of errors and abuse. Legal basis: our legitimate interest (Article 6(1)(f) GDPR). Retention: for a short time, in accordance with the hosting provider’s data retention rules.
For sign-in and payment requests, the IP address is also kept in the server’s memory for up to 15 minutes, so that excessive use can be limited.
9. Cookies and local storage
- NEXT_LOCALE cookie: remembers the language you picked in the language switcher (1 year).
- gmqr_session cookie: keeps you signed in on the “My codes” page after you sign in with an email code; it is signed and cannot be read by scripts (180 days, or until you sign out).
- gmqr_login cookie: the sign-in in progress, between requesting and entering the code (10 minutes).
- Local storage (localStorage): the management links of the codes created or opened on this device, so that you find them on the “My codes” page. The “My codes” page uses them to look up the status of your codes; otherwise they stay in your browser, and you can delete them at any time in your browser settings.
- The payment form is provided by Stripe, which uses its own cookies to process the payment securely and to prevent fraud.
These are necessary for the Service to work, so they do not require consent. We do not use analytics or advertising cookies.
10. Data processors and data transfers
- Hosting and application server: Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA (https://vercel.com)
- Database: ChiselStrike, Inc. – Turso (https://turso.tech) – the data of the codes is stored on a server in the European Union (Ireland).
- Payments: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland – as an independent controller.
- Sending sign-in emails: Resend, Inc., USA (https://resend.com)
Some of these providers are headquartered in the United States of America, so data may also be transferred outside the European Economic Area. Such transfers take place with appropriate safeguards (the EU–US Data Privacy Framework and/or the standard contractual clauses adopted by the European Commission).
We do not share your data with any other third party, we do not sell it, and we do not use it for marketing, profiling or automated decision-making. We disclose data to authorities only where the law requires it.
11. Data security
All connections are encrypted (HTTPS). The management token is a 192-bit random value, IP addresses are stored only as salted hashes, and sign-in codes only as keyed hashes (they expire after 10 minutes and stop working after 5 wrong attempts). Sign-in cookies are signed and cannot be read by scripts, and only the Operator has access to the database.
12. Your rights
- right to information and access (Article 15 GDPR);
- right to rectification (Article 16);
- right to erasure (Article 17) – you can also delete a code yourself at any time on its management page;
- right to restriction of processing (Article 18);
- right to data portability (Article 20);
- right to object to processing based on legitimate interest (Article 21).
You can send your request to help@testmyabilities.com. To identify a code, include its short link. We respond within one month at the latest.
13. Remedies
If you feel that the processing of your personal data violates the law, you can lodge a complaint with the supervisory authority of the controller’s registered office, the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky, Hraničná 12, 820 07 Bratislava 27 (https://dataprotection.gov.sk)), or with the data protection authority of your place of residence or place of work – in Hungary, for example, the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH; 1055 Budapest, Falk Miksa utca 9–11.; https://naih.hu).
If your rights are violated, you can also go to court; you may bring the action before the courts of the member state of your place of residence.
14. Children
The Service is not intended for children under 16, and we do not knowingly process their data. Only adults can order a subscription.
15. Changes to this notice
We update this notice whenever the Service changes; the effective date is shown at the top of the document.