Service publisher and contact
The myQR.re service is operated by WinzUp, a SAS (simplified joint-stock company), registered with the Trade and Companies Register of Saint-Denis under number 101963593.
Registered office: 7 rue Henri Cornu, Immeuble Rodrigues 2, 97490 Sainte-Clotilde, Reunion, France
SIRET: 10196359300013
Intra-community VAT: FR30101963593
Legal representatives: PERRIN Florent (Chairman) and SAUTRON Loic (Managing Director)
Publication director: SAUTRON Loic
Support and data protection contact: myqr.re@gmail.com
Scope of the policy
This policy applies to the processing carried out from the myQR.re public site, the public business pages hosted by myQR.re, the business dashboard and the associated technical services.
- Public site: presentation pages, information pages, browsing and contact requests.
- Public business pages: myQR page, /go/ links, QR Codes, public modules linked to the menu, loyalty, events and special offers.
- Business dashboard: page configuration and customization, opening hours, buttons, statistics, contacts, email and SMS campaigns, digital menu, loyalty card, events, special offers, bookings, artificial intelligence assistance features, subscriptions, wallet and credits.
Categories of data processed
Depending on the features used, myQR.re may process the following categories of data.
- Business account data: business name, slug, logo, description, main color, opening hours, button configuration, enabled modules and page settings.
- Browsing and statistics data: page visits, clicks, QR Codes used, technical events, performance indicators and service consultation information.
- Contact data: last name, first name, email, phone, date of birth, title or gender, postal code, marketing consents, tags (including public tags selectable by the end customer), unsubscription statuses, deliverability statuses and information submitted through public forms.
- Marketing data: email or SMS drafts and campaigns, prepared content, senders, timestamps, tag-based targeting, sending statistics and unsubscription management.
- Functional data: digital menu content, loyalty program, events, special offers, bookings (services, resources, slots, contact details of the end customer making the booking), responses and data associated with these modules.
- Data generated by artificial intelligence: briefs, instructions, menu content, product sheets, offers, events or campaigns prepared or reworked using the AI assistance features, as well as the exchanges associated with the myQR Copilote assistant.
- Advertising measurement data (Meta): when the visitor has given their consent, technical Meta Pixel identifiers (_fbp, _fbc cookies), browsing and conversion events, and data sent to Meta's Conversions API in hashed form (email, phone, name), IP address and user agent.
- Payment and subscription data: Stripe customer, subscription, item, price, invoice and payment method identifiers, non-sensitive card summary, billing statuses, top-ups, ledger, wallet, credits, quotas and synchronization events.
- Google data: place ID, name, address, review or directions URL and, where a Google Business Profile connection is authorized, listing and review data strictly necessary for the requested feature.
When a business collects its own customers' data through a public myQR.re page, it may act as data controller for its commercial purposes. myQR.re then acts as a technical platform or processor depending on the operations carried out.
Processing purposes and legal bases
The data is processed to provide, administer, secure and improve the service. The main legal bases are performance of the contract, consent, legitimate interest and compliance with legal obligations.
- create, administer and secure business accounts;
- publish and update myQR pages, /go/ links and QR Codes;
- manage the digital menu, loyalty, events and special offers;
- centralize contacts, tags, forms and consents;
- prepare, send or schedule email and SMS campaigns;
- produce usage and performance statistics;
- process payments, subscriptions, saved cards, credit top-ups and billing synchronizations;
- provide the Google integrations requested by the business;
- prevent fraud, abusive use, incidents and non-payment;
- comply with the applicable accounting, tax, legal and regulatory obligations.
Data recipients
The data is accessible, as needed, to WinzUp's authorized teams and to the technical processors necessary for the performance of the service.
- Google Firebase / Google Cloud for hosting, the database, authentication, storage, certain backend functions and the Google APIs (Google policy).
- Stripe for subscriptions, credit top-ups, payment methods, saved cards, invoices and payment webhooks (Stripe policy).
- Mailjet for sending emails when this feature is used (Mailjet policy).
- ALL MY SMS for sending SMS when this feature is used (ALL MY SMS policy).
- Google Places and Google APIs for review and directions links and authorized Google integrations (Google policy).
- Meta Platforms (Facebook / Instagram) for advertising audience measurement via the Meta Pixel and the Conversions API, when the visitor has consented (see the dedicated section) (Meta policy).
- OpenAI for artificial intelligence assistance and generation features (menu, products, offers, events, campaigns, myQR Copilote assistant), when these features are used (OpenAI policy).
The data is not resold. It is shared only to the extent necessary for the provision of the service, maintenance, security, support, billing or compliance with legal obligations.
Transfers outside the European Union. Certain processors (notably Meta Platforms, OpenAI and some Google services) may process data outside the European Union, in particular in the United States. These transfers are governed by the appropriate safeguards provided for by the regulation, such as the European Commission's standard contractual clauses or the applicable adequacy mechanisms.
Main host: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Contact: Google Cloud / Firebase support or legal-notices@google.com for legal notifications.
Retention periods
- Contacts: during the commercial relationship, then for up to 3 years after the end of the relationship or the last contact from the data subject.
- Email and SMS campaigns: 3 years from their creation or last activity, unless a longer legal obligation or need for evidence applies.
- Invoices and accounting documents: 10 years.
- Connected Google data: for the period necessary to provide the service, then deletion or anonymization within a reasonable time after disconnecting the Google account.
- Technical, security and audit logs: for the period necessary for security, maintenance and the defense of the platform's rights.
Google Business Profile and Google services
myQR.re may allow a business to connect a Google account in order to use certain features linked to its Google presence. This access is granted only with the user's explicit authorization through the Google authorization mechanism.
- Google data is used solely to provide the features requested in the dashboard.
- When a Google Business Profile connection is enabled, myQR.re may access listing information, certain configuration data and, depending on the active modules, information useful for displaying or managing reviews.
- This data is neither resold nor used for unsolicited advertising purposes.
- The user can withdraw this access by disconnecting their Google account from the service settings or from their Google account when this option is available.
Payments, subscriptions and payment methods
Payments related to subscriptions, credit top-ups and certain saved payment methods are processed by Stripe.
- myQR.re is not intended to store full bank card numbers.
- myQR.re may retain non-sensitive data necessary for the proper operation of the service, such as the Stripe customer identifier, the card type, the last 4 digits, the expiry date, subscription identifiers, invoice identifiers and payment statuses.
- Saved cards may be reused for uses authorized by the customer and compatible with the configuration of the associated Stripe account.
- Technical payment events may be synchronized via webhooks in order to correctly apply rights, quotas, downgrades, top-ups and billing statuses.
Email, SMS, contacts and unsubscriptions
myQR.re allows businesses to centralize contacts and run email or SMS campaigns. Businesses are responsible for the lawfulness of the data they import or collect and for the compliance of their communications.
- Tags, segments, deliverability statuses, unsubscriptions, invalid numbers, invalid emails and exclusion lists are retained to avoid unwanted or non-compliant sends.
- Campaigns may consume wallet credits or included quotas depending on the active plan.
- On the PRO plan, a quota of 5000 monthly emails may apply depending on the service configuration.
- Custom senders, drafts and context elements may be retained to make it easier for the business to resume its work.
Meta Pixel and Conversions API (advertising measurement)
The myQR.re public site and public business pages may use the Meta Pixel and Meta Platforms' Conversions API (CAPI) in order to measure audience, evaluate the performance of advertising campaigns and improve the relevance of the content served.
- The Pixel is only loaded after the visitor's explicit consent, collected via a cookie banner. In the absence of consent, or in the event of refusal, no advertising pixel is activated.
- The visitor's choice is stored in the browser (local storage and the myqr_cookie_consent cookie) in order to respect their decision, and can be changed at any time.
- After consent, Meta cookies (_fbp, _fbc) may be placed and browsing or conversion events may be sent to Meta.
- Some events may also be sent server-to-server via the Conversions API. Personal data (email, phone, name) is then hashed (SHA-256) before transmission; the IP address and user agent may be transmitted for event matching.
- For the collection and transmission of data via the Pixel and the Conversions API, myQR.re (and the business concerned) and Meta act as joint controllers. Meta then acts as an independent controller for its own purposes. The processing is based on the visitor's consent. To find out more, see Meta's privacy policy.
Artificial intelligence
myQR.re offers artificial intelligence assistance and content generation features (for example: writing offers and events, importing and structuring a menu, generating email or SMS campaigns, myQR Copilote assistant). These features rely on the provider OpenAI.
- The content, briefs and instructions provided to these features may be transmitted to OpenAI only to the extent necessary for the requested generation.
- It is recommended not to include sensitive data or unnecessary personal data.
- The generated content is offered as an aid; the user business remains responsible for its verification, accuracy and compliance before publication or sending.
Security
WinzUp implements reasonable technical and organizational measures to protect the data against destruction, loss, alteration, disclosure or unauthorized access.
- access control and authentication;
- logical segmentation of data;
- logging, audit and technical monitoring;
- synchronization of critical statuses via backend and webhooks;
- use of recognized providers for hosting, payment and message sending.
No security measure guarantees zero risk. In the event of an incident affecting personal data, the applicable legal obligations are implemented.
Your rights
In accordance with the applicable regulation, you may have a right of access, rectification, erasure, restriction, objection and, where applicable, portability of your personal data.
- Requests can be sent to myqr.re@gmail.com.
- Identity verification may be requested if necessary.
- If, after contacting us, you believe that your rights are not being respected, you may lodge a complaint with the CNIL (the French data protection authority).
Policy updates
This policy may be updated to reflect legal, technical, contractual or functional changes to the service. The version online at the time of consultation is the applicable version.