Privacy Policy
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of the member states as well as other data protection provisions is:
thinkrs — Digital-Agentur für zukunftsfähige Marken
Robin Steppat
Kochsdorfer Weg 38
03130 Spremberg
Germany
Email: hello@thinkrs.digital
Mobile: +49 173.7425801
2. General Information on Data Processing
We only collect and process personal data to the extent necessary to provide a functioning website as well as our content and services. The processing of personal data is generally only carried out with the user's consent. An exception applies in cases where prior consent cannot be obtained for factual reasons and the processing of the data is permitted by legal provisions.
The legal bases for data processing arise from the GDPR, in particular Art. 6(1)(a) (consent), (b) (performance of a contract), (c) (legal obligation) and (f) (legitimate interest).
3. Server Log Files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- IP address of the accessing device
- Date and time of access
- Name and URL of the file accessed
- Referrer URL (the previously visited page)
- Browser and operating system used
This data is stored for technical reasons to ensure the smooth operation of the website and to investigate misuse. This data is not merged with other data sources.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the technical security and stability of the website).
Storage period: Server log files are stored for a maximum of 7 days and then automatically deleted.
4. Contact Form and Contacting Us
If you contact us by email or via a contact form, the data you provide (name, email address, phone number, message text) will be stored in order to process your inquiry.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures / performance of a contract) or Art. 6(1)(f) GDPR (legitimate interest in processing your inquiry).
Storage period: Your data will be deleted once your inquiry has been fully processed, unless statutory retention obligations apply.
5. Cookies and Similar Technologies
This website uses only technically necessary cookies required for the operation of the website (e.g. session cookies for login). No tracking or marketing cookies are used.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the technically flawless operation of the website).
Storage period: Session cookies are automatically deleted when the browser is closed.
In the menuQR app (app.menuqr.codes), additional cookies are set by PostHog (EU region) to improve app quality and log errors. These cookies apply exclusively to logged-in app users. For more information, see Section 7.
6. Analytics Tools
This website uses Google Analytics 4 (Google Ireland Limited) to analyze website usage. Google Analytics sets cookies on your device and processes usage data (e.g. pages visited, time spent, approximate location) for statistical purposes. It is used exclusively with your consent given via the cookie consent banner.
Legal basis: Art. 6(1)(a) GDPR (consent).
Storage period: Analytics data is stored for a maximum of 14 months.
Withdrawal: You can withdraw your consent at any time via the "Privacy Settings" link in the footer.
7. Product Analytics and Error Tracking (App)
The menuQR app at app.menuqr.codes uses PostHog (Posthog, Inc., 965 Mission St, San Francisco, CA 94103, USA — EU region: eu.i.posthog.com) for product analytics and error tracking. PostHog captures only actions of logged-in app users (e.g. page views, feature usage, error events). Processing takes place on servers within the European Union.
Categories of data collected: User ID (pseudonymised), email address (pseudonymised), page views within the app, features used (e.g. menu upload, QR download), error and exception logs, device information (browser, operating system).
PostHog uses cookies and similar technologies to provide its functionality. These cookies are set exclusively in the context of the app (app.menuqr.codes), not on this website.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving app quality and diagnosing errors).
Objection: You can object to the processing by email to support@menuqr.codes.
PostHog privacy information: posthog.com/privacy
8. Map Services
This website does not use Google Maps or any other external map services.
9. Fonts
This website does not use externally loaded Google Fonts. All fonts are provided locally via system fonts. No IP addresses are transmitted to Google or other third parties.
10. Hosting
This website is hosted by the following provider:
Hetzner Online GmbH
Industriestraße 25, 91710 Gunzenhausen, Germany
A data processing agreement pursuant to Art. 28 GDPR is in place with the hosting provider. The server locations are in Germany.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure and efficient provision of the website).
11. External Links
Our website contains links to external third-party websites over whose content we have no influence. Therefore, we cannot assume any liability for this external content. The respective provider or operator of the linked pages is always responsible for their content. The linked pages were checked for possible legal violations at the time of linking. Illegal content was not identifiable at the time of linking.
We recommend that you read the privacy policies of the respective external websites before entering any personal data there.
12. Applicant Data
No job applications are currently accepted via this website. No applicant data is processed.
13. Your Rights as a Data Subject
Under the GDPR, you have the following rights, which you can assert at any time using the contact details provided in Section 1:
- Right of access (Art. 15 GDPR): You can request information about the data stored about you.
- Right to rectification (Art. 16 GDPR): You can request the correction of inaccurate data.
- Right to erasure (Art. 17 GDPR): You can request the deletion of your data, provided no statutory retention obligations apply.
- Right to restriction of processing (Art. 18 GDPR): You can request the restriction of processing.
- Right to data portability (Art. 20 GDPR): You can receive your data in a structured, commonly used format.
- Right to object (Art. 21 GDPR): You can object to the processing of your data.
- Right to lodge a complaint with the supervisory authority (Art. 77 GDPR): You can lodge a complaint with a data protection supervisory authority. The authority responsible for us is: Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg, Stahnsdorfer Damm 77, 14532 Kleinmachnow.
14. Data Security
We employ technical and organizational security measures (TOMs) to protect your personal data against accidental or intentional manipulation, loss, destruction, or access by unauthorized persons. These include:
- SSL/TLS encryption of all data transmissions
- Firewalls and access controls
- Regular security updates
- Backup strategy for emergency recovery
Our security measures are continuously improved in line with technological developments.
15. Automated Decision-Making
Automated decision-making, including profiling, within the meaning of Art. 22 GDPR does not take place.
15. Sharing of Data with Third Parties
Your personal data will not be transferred to third parties for purposes other than those listed below. We only pass on your personal data to third parties if:
- you have given your explicit consent to do so (Art. 6(1)(a) GDPR)
- the disclosure is necessary to fulfil contractual obligations (Art. 6(1)(b) GDPR)
- there is a legal obligation to do so (Art. 6(1)(c) GDPR)
The following act as processors within the meaning of Art. 28 GDPR:
- Hetzner Online GmbH (hosting)
- Stripe, Inc. (payment processing — only for active subscriptions)
- PostHog, Inc. (product analytics and error tracking — app only, EU region)
Personal data is only transferred to countries outside the EU/EEA if an adequacy decision by the EU Commission exists or appropriate safeguards (e.g. standard contractual clauses) are in place.
16. Changes to This Privacy Policy
We reserve the right to amend this privacy policy as needed to ensure it always complies with current legal requirements, or to implement changes to our services in the privacy policy. The new privacy policy will then apply to your next visit.
Status: October 2026