Privacy Notice
Last updated: July 31, 2026
This notice explains which personal data is processed when you use OCB QR Visit, for what purpose, and what rights you have.
Controller
OCB ConsultingInhaber: Orkun BayramGrabenstraße 2245964 GladbeckDeutschlandPhone: +49 (0) 163 1695159Email: datenschutz@ocb-consulting.comWhat data we process
Account data: when you create an account we process your email address, an optional display name, and a user id issued by Firebase. If you sign in with Google we additionally receive the profile data Google shares (name, email address, profile picture).
Content: the QR codes you create are stored together with their content — depending on the type that may be URLs, text, contact details (vCard), WiFi credentials, events or coordinates. Uploaded logos are downscaled and stored as image data alongside the QR code. You decide this content yourself; please do not enter third-party data without their knowledge.
Dynamic QR codes: we additionally store the target address, a scan counter and the time of the last scan. We deliberately do not record IP addresses, location or device data, and we build no profiles of the people scanning.
Server logs: when the site is accessed, our hosting provider processes technically necessary access data such as IP address, time, requested address and browser identifier. These serve secure operation and are deleted after a short period.
Legal bases
Providing your account and managing your QR codes is performance of the usage contract (Art. 6(1)(b) GDPR).
Server logs, security measures and scan counting rest on our legitimate interest in a secure and functioning service (Art. 6(1)(f) GDPR).
Optional statistics cookies are used solely on the basis of your consent (Art. 6(1)(a) GDPR). You may withdraw consent at any time with effect for the future.
Recipients and third-country transfers
Authentication and database: Google Ireland Limited / Google LLC (Firebase Authentication, Cloud Firestore), acting as processor; standard contractual clauses are in place for transfers to the United States.
Hosting and delivery: Vercel Inc. Standard contractual clauses also apply here for third-country transfers.
We do not sell data, operate no advertising networks, and do not share your data for advertising purposes.
Retention
Saved and dynamic QR codes are kept until you delete them or close your account. Deleting a code under “My QR codes” or “Dynamic QR codes” takes effect immediately.
Server logs are retained only briefly by the hosting provider. Your cookie choice is stored in your browser for twelve months.
Please note: if you delete a dynamic QR code, codes already printed or distributed will stop working.
Data security
All transmission is encrypted via TLS. Access to stored QR codes is restricted to your own account by database rules.
The target address of a dynamic QR code is technically publicly readable so that the redirect works when scanned. Do not put confidential content there.
No automated decision-making
No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place.
Changes to this notice
We update this notice when the service or the legal situation changes. The version published on this page always applies; the date above indicates the current status.
Cookies and local storage
We set only the following entries. Statistics entries are created only after your consent.
| Name | Purpose | Duration | Category |
|---|---|---|---|
NEXT_LOCALE | Remembers the selected language (TR/DE/EN). | 1 year | Necessary · cookie |
firebase:authUser:* | Keeps you signed in. | Until sign-out | Necessary · local storage |
ocb-cookie-consent | Stores your choice from this banner. | 12 months | Necessary · local storage |
_ga, _ga_* | Anonymous usage statistics (Firebase/Google Analytics). Not loaded without consent. | Up to 2 years | Optional · consent only |
Your rights
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
To exercise your rights, a message to the email address above is sufficient.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority — in particular in the member state of your residence, place of work, or the place of the alleged infringement.