Privacy Policy
Този документ е достъпен само на английски език. Английската версия е правно обвързващата.
Last updated: September 1, 2026. This Privacy Policy describes how DominiQR, a product owned and operated by OblivionWare Ltd (“we,” “us,” or “our”), collects and processes your personal data when you use our service.
1. Data Controller
DominiQR is operated by OblivionWare Ltd (registered in Bulgaria as ОбливиънУеър ЕООД). For the purposes of the General Data Protection Regulation (GDPR), we are the data controller. You can contact us at support@dominiqr.com for any privacy-related inquiries.
2. Data We Collect
We collect the minimum data necessary to provide our services, categorized by how you interact with us:
A. Account Holders:- Account Data: Your email address for login, service communication, and account management.
- Destination Data: The URLs and content you link to your dynamic QR codes.
B. QR Code Scanners (End-Users):- Analytics Data: We track the scanner's device type, operating system, and browser type.
- Location Data: We temporarily process the scanner's IP address to determine geographical location (country/city). We do not log, store, or share the actual IP address. The IP is discarded immediately after the lookup is completed.
3. Third-Party Services & Infrastructure
We utilize trusted third-party processors to maintain our high-performance infrastructure:
- Render: Our core hosting and cloud infrastructure.
- Stripe: Payment processing. We do not store your credit card details; these are handled exclusively by Stripe.
- Mailgun: Delivery of transactional emails and service notifications.
- ipdata: Transient IP address lookups for scan location analytics.
- Google Analytics: Used on our website to understand user interaction. We do not use Google Analytics on the actual QR code scan redirects.
- Microsoft Clarity: Used on our website to understand how our pages are used, via aggregated heatmaps and session replays of interactions such as clicks, scrolls and mouse movement. Clarity is only loaded once you accept analytics cookies, and we do not use it on the actual QR code scan redirects.
4. Legal Basis for Processing
We process data under the following legal bases:
- Contractual Necessity: To provide the service to account holders, including resolving your dynamic QR codes and producing the scan analytics you subscribe to.
- Legitimate Interest: To prevent fraud and abuse, and to ensure the security and reliability of our infrastructure.
- Consent: For the website analytics cookies described in Section 7 (Google Analytics and Microsoft Clarity). These load only after you choose “Accept All” in our cookie banner. You can change or withdraw your consent at any time using the “Cookie preferences” link in the footer of any page, which re-opens the banner so you can choose again.
5. Data Retention
We retain customer account information for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are legally required to keep it for Bulgarian tax or accounting purposes.
6. Your Rights (GDPR)
As a user of a service operated from the EU, you have the right to:
- Access the personal data we hold about you.
- Request the deletion or rectification of your data.
- Object to processing or request data portability.
To exercise these rights, contact
support@dominiqr.com. You may also lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP).
7. Cookies
We use cookies on the DominiQR dashboard and marketing site to:
- Essential: Maintain your session and ensure security.
- Analytics: Allow Google Analytics and Microsoft Clarity to recognize return visits and measure how our pages are used. These are only set if you choose “Accept All” in our cookie banner; choosing “Necessary Only” prevents them from loading.
You can review or change these choices at any time using the “Cookie preferences” link in the footer of any page.
Note: We do not drop any cookies or tracking pixels on the devices of end-users scanning your QR codes.
8. Data Transfers outside the EEA
By using our third-party providers (Stripe, Render, Mailgun, Microsoft), your data may be processed in the United States. We ensure these providers comply with the EU-U.S. Data Privacy Framework or utilize Standard Contractual Clauses (SCCs) approved by the European Commission.