Privacy and data protection
What we store about you, why, for how long — and what we never store at all.
Last updated Aug. 18, 2026
Who is responsible
The company below decides what is collected and why, and is the one to write to about any of it.
DSO računarsko programiranje DIVERD, Rainci Gornji bb, 75260, Kalesija · privacy@diverd.dev
What we hold
Your name and email address, the codes and menus you create, and the record of what you have paid. Nothing is collected that you have not typed in or uploaded yourself.
- Your account: email address, name, interface language, and a password stored only as a hash.
- The codes you build: what they encode, the colours and shapes you chose, and any logo you uploaded.
- Hosted menus: the text, the prices and the pictures you publish on them, which are public by design.
- Your subscription payments: the amount, the currency, the date and which plan they bought. No card details — see below.
- Ordinary server logs, kept briefly to keep the service running and secure.
Cardholder data
We never receive your card number, expiry date, CVV or PIN, so there is nothing of the kind for us to store, retain or lose.
Card details are entered on a page hosted by Raiffeisen BANK dd Bosna i Hercegovina and are handled by the bank alone, under the card schemes' own security rules. Our application is not part of that exchange.
What comes back to us is the outcome and nothing else: whether the payment succeeded, the amount, the currency, the date and a reference we can quote to the bank if you ever query it.
How this works in detail is set out in Payment security.
What a scan records
A hosted menu counts how often it is opened, so the venue can tell whether the code on the table is being used. That count is the whole of it.
- How often a menu was opened, and when.
- No name, address or account — a guest who scans a code has no account here and is never asked for one.
- No advertising or analytics scripts of any kind, and nothing that follows a guest to another site.
A downloaded code is an image file and reports nothing at all. Once it is printed on a poster it is out of our hands: scanning it takes the phone straight to whatever the code encodes, without passing through us.
Why
To provide the service you signed up for — building your codes, keeping them, and publishing the menus you make. That is the contract between us; we do not process your data for anything else.
- To provide the service you signed up for — an account cannot exist without an address to sign in with.
- To meet accounting and tax obligations, which set their own minimum retention periods.
- To keep the service running and secure — logs that let us find a fault or stop an attack.
How long
For as long as your account exists. Payment records are kept because tax rules require it. Close your account and we delete the rest.
- Account data: for as long as the account exists. Delete the account and it goes with it.
- Codes and menus: for as long as the account exists. Delete one and it is gone; delete the account and all of them go with it. A code already downloaded is a file you hold, and deleting it here cannot recall it.
- Payment records: kept for as long as accounting and tax law requires, even after an account is closed. They are the record of a transaction and cannot simply be erased.
Who else sees it
Nobody, beyond the three processors below. Your data is not sold, shared or sent to advertisers. A menu you publish is public because publishing it is the point; nothing else about your account is.
- Raiffeisen BANK dd Bosna i Hercegovina, which processes card payments and is the only party that ever handles your card details.
- Our hosting provider, which runs the servers the application and its database sit on.
- Our email provider, which delivers the messages the service sends — password links, and notices about your subscription.
We do not sell your data, rent it, or hand it to anyone for advertising. We disclose it otherwise only where the law obliges us to.
Cookies
Three: a session cookie that signs you in, a security token that blocks cross-site request forgery, and a language cookie written only when you switch language. All three are necessary for the site to work.
Your rights
Under the GDPR you can ask for a copy of your data, correct it, have it deleted, take it elsewhere, or object to how it is handled. Ask and we act within one month.
- Tell you what we hold about you.
- Correct anything that is wrong.
- Delete your account and its data, subject to the retention periods above.
- Give you a copy of what you have made — every code you have generated can be downloaded again from your account.
Write to us at privacy@diverd.dev