Legal

Privacy Policy

The short version: Pivento collects the minimum needed to run your QR workspace, never sells data, and never adds tracking you didn’t ask for. The details follow.

Last updated: pending launch.

This policy explains what Pivento collects through the Pivento mobile apps and this website (pivento.app), why we collect it, and what we will never do with it. It applies whether you create codes, scan them, or are simply reading this page. Pivento is operated by [COMPANY LEGAL ENTITY] (“Pivento”, “we”, “us”). You are reading the pre-launch draft; the final policy will be published before the app is released.

1. What we collect

We collect what the service needs to work — and little else.

Account data

When you create an account, we store your email address, display name, and the identifier your sign-in method (email, Google, or Apple) gives us. Accounts are handled by Firebase Authentication. If you start with an anonymous account, we create a random identifier so your codes sync to your device — no personal details are required until you choose to add them.

QR content you create

The destinations and payloads you encode — links, Wi-Fi credentials, contact cards, event details — along with titles, notes, folders, and settings. This lives in Cloud Firestore. We store the encoded data, not the rendered QR images; codes are regenerated on demand.

Scan telemetry

When someone scans a dynamic code, the request is resolved at Cloudflare’s edge. We record an anonymous scan event — timestamp, approximate country or city, device type, and referring app — to power your analytics. These events contain no name, no account identifier, and no way to identify the person who scanned. We never learn who they are, and we don’t try. Static codes never touch our servers at all: their destination is encoded directly in the printed code.

Device and diagnostic data

Device model, operating system version, app version, and language; crash reports through Crashlytics; aggregate usage events through Firebase Analytics; and, if you enable notifications, a push token for Firebase Cloud Messaging. App settings and experiments are delivered through Remote Config.

2. How we use your data

  • To operate the service: create and sync your codes, resolve scans at the edge, and keep free codes alive.
  • To show you how your codes perform, in aggregate.
  • To find and fix problems, using crash reports and diagnostics.
  • To keep the service safe: detect abuse and enforce our Terms of Service.
  • To communicate with you: service messages about your account. Marketing email is opt-in only.
  • To comply with the law where we’re required to.

3. What we never do

These are commitments, not aspirations:

  • We never sell your data. To anyone. Ever.
  • We never run third-party advertising in the app or on scanned pages, and we embed no advertising trackers or SDKs.
  • We never track the people who scan your codes. Scan events are anonymous; we don’t profile scanners or follow anyone across sites.
  • We never deactivate your codes because you stopped paying. Free codes don’t expire — the only way a code stops working is if you delete it.

4. Service providers (processors)

We don’t do this alone. These providers process data on our behalf:

Google — Firebase & Google Cloud
Firebase Authentication, Cloud Firestore, Cloud Functions, Cloud Storage, Firebase Analytics, Crashlytics, Firebase Cloud Messaging, and Remote Config.
Role: runs the app’s backend — accounts, QR metadata, diagnostics and crash reports, push notifications, and feature configuration.
Cloudflare
Workers, KV, R2, and Analytics Engine on the QR network; cookieless Cloudflare Web Analytics on this website.
Role: edge infrastructure — resolves scans to destinations, stores code mappings and public assets, and records anonymous scan telemetry.
RevenueCat
Subscription infrastructure.
Role: validates in-app purchases made through Google Play Billing and the Apple App Store, and keeps your entitlement status in sync.
Google Play & the Apple App Store
App distribution and billing platforms.
Role: process your payments and subscriptions. Your payment details go to the store, not to us — we never see your card.

We share only what each provider needs to do its job. Our agreements require them to process personal data only on our instructions; their own privacy policies describe their services in full.

5. Data retention

Account data is kept while your account is active and deleted when you delete your account. QR content is kept until you delete it. Scan events are retained only long enough to power your analytics, then reduced to aggregates. Crash logs and diagnostics are kept for a limited troubleshooting window under our providers’ default settings; we will publish the exact windows in the final version of this policy.

After you delete something, copies may persist briefly in encrypted backups before they are fully purged.

6. Your rights and choices

Depending on where you live, you have rights over your personal data — including under the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), as amended:

  • Access and export — get a copy of your data, in a portable format.
  • Correction — fix anything inaccurate.
  • Deletion — delete your account and its data.
  • Restriction and objection — limit or object to certain processing.
  • Withdraw consent — where processing is based on consent, at any time.

You can export your data and delete your account directly from the app’s settings, or make a request by emailing hello@pivento.app. We respond within the timeframes the law requires (generally 30 days under the GDPR) and may ask you to verify your identity first. We do not sell or share personal information as those terms are defined under the CCPA, so there is nothing to opt out of. If you’re unhappy with how we handled a request, you can complain to your local data protection authority.

7. Children’s privacy

Pivento is not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and we don’t knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.

8. International data transfers

Our providers operate globally: Google Cloud and Cloudflare run data centers in many countries, and RevenueCat operates from the United States. That means your data may be processed outside your own. Where the GDPR applies, those transfers are protected by the safeguards in our providers’ data processing agreements, including the EU Standard Contractual Clauses. We will document the specific regions used before launch.

9. Changes to this policy

If we change this policy, we’ll update this page and the “last updated” line at the top. For material changes, we’ll also tell you in the app or on this site before the new version takes effect.

10. Contact us

Questions, requests, or complaints: email hello@pivento.app or use the contact page. Postal address: [COMPANY LEGAL ENTITY], [COMPANY POSTAL ADDRESS].