Privacy Policy

Last updated: 18 August 2026 · Operated by DINAMIK d.o.o. · OIB 66166833677

This Privacy Policy explains how DINAMIK d.o.o. processes personal data when you use QStatus, our live order-status board and self-serve ordering service for food stalls ("QStatus" or the "Service"). It covers the dashboard used by stall owners and staff, the public order board, and the ordering, card payment, fiscal receipt, and notification features that go with it. We process personal data in accordance with the EU General Data Protection Regulation (GDPR, Reg. (EU) 2016/679) and applicable Croatian law.

1. Who we are (data controller)

The controller responsible for your personal data is:

  • DINAMIK d.o.o. (limited liability company)
  • OIB (personal identification number): 66166833677
  • Registered address: Šušnjevec 49, 10000 Zagreb, Hrvatska
  • Director: Jura Milković
  • Contact for privacy matters: info@dinamik.dev

For any question about this policy or to exercise your rights, contact us at info@dinamik.dev. We have not appointed a Data Protection Officer, as we are not legally required to.

We are the controller for stall owner and staff data. For the data of customers who order from a stall, the stall itself is the controller and we act as its processor — see the next section.

2. Who this policy applies to, and in which role

QStatus has two very different kinds of user, and we hold a different legal role for each.

  • Stall owners and staff who create an account and use the dashboard. For their account, stall, and billing data we are the controller — we decide why and how it is processed, and this policy governs it.
  • Customers who scan a stall's QR code. Where a customer places an order, we handle their data as a processor on behalf of the stall: the stall decides to sell, issues the receipt in its own name, and is the controller of that order. We process it only to run the ordering, payment, and receipt features the stall has switched on.

If you only watch the board, nothing changes for you: the public board shows anonymous order numbers and their status, and we collect no name, email, or contact details from you. We set no tracking or advertising cookies on any device, and run no analytics product at all.

If you place an order, you do give us data — at minimum the items you chose, and, if the stall takes card payments, an email address so the fiscal receipt can be sent to you. Section 3 lists exactly what, and section 11 explains how to exercise your rights over it.

3. What personal data we collect

From stall owners and staff who register:

  • Account data: your name, email address, and password (stored only as a salted hash, never in plain text), plus whether your email has been verified.
  • Stall data: the stall name, its town or city, an automatically generated stall code, your menu, and the order numbers and timestamps that run the board.
  • Staff PIN: if you set a PIN to lock a till device into board and kitchen view, we store only a cryptographic hash of it (scrypt) and its salt — never the digits.
  • Billing data: subscription status, plan, billing period, your monthly order count (used to calculate the per-order fee), and the identifiers linking your account to your payment. Card details are handled by Stripe and are never stored on our systems.
  • Technical and security data: your IP address and request metadata, used transiently to operate the Service and to rate-limit sign-in and sign-up against abuse, plus a strictly necessary session cookie (see Cookies).

From stall owners who connect payments or fiscalization, we additionally store, encrypted at rest: your OIB and registered business name, your business premise and device marks, your FINA application certificate and its passphrase, and your Teya credentials. These identify your business to the Tax Administration and to your payment provider; we use them for nothing else.

From customers who place an order (as processor for the stall):

  • Your order: the items and quantities you chose, the total, and the language you were browsing in (so the receipt reaches you in that language).
  • Your email address — optional, and only requested where the stall takes card payment, because Croatian law requires the fiscal receipt to be delivered to you. If you pay at the counter we do not ask for it and do not store one.
  • Your note to the kitchen — optional and free-text. It is shown to the stall's staff and repeated on your receipt. Please do not write anything into it you would not want the stall to read; in particular, avoid health details. If you need to tell the stall about an allergy, we would rather you told them in person.
  • A push notification address — only if you tap to be told when your order is ready. This is a handle for your browser, not for you, and it is deleted once the order is done.
  • Your IP address, held briefly in memory to rate-limit ordering against abuse. It is not written to our database.

We do not intentionally collect special categories of personal data, and we ask you not to enter such data into order numbers, stall names, menu items, or order notes.

4. Why we process your data and our legal bases

  • To provide the Service — create and manage your account, run your order boards, menus, kitchen display, and analytics (legal basis: performance of a contract, Art. 6(1)(b) GDPR).
  • To take payment and manage subscriptions — including calculating the per-order usage fee, via our payment provider (Art. 6(1)(b) GDPR).
  • To process customer orders and take payment for them — on the stall's behalf and on its instructions (Art. 6(1)(b) GDPR between the customer and the stall; Art. 6(1)(f) for us as its processor).
  • To issue fiscal receipts — submitting each card-paid receipt to the Croatian Tax Administration and delivering the receipt to the customer is a legal obligation of the stall, which we discharge on its behalf (Art. 6(1)(c) GDPR).
  • To meet our own legal obligations — issuing and keeping invoices and accounting records (Art. 6(1)(c) GDPR).
  • To keep the Service secure — authentication, abuse prevention, and rate limiting (Art. 6(1)(f) GDPR; our legitimate interest in protecting the Service and its users).
  • To send service emails — such as account verification and password reset (Art. 6(1)(b) GDPR).
  • To send order-ready push notifications — only where you have asked for them (consent, Art. 6(1)(a) GDPR). You can withdraw consent at any time by revoking the notification permission in your browser.
  • To measure and improve our own advertising — only on our public marketing pages (home, pricing, and sign-up), never on the dashboard or the public order board, and only if you accept the advertising cookie in the cookie notice (consent, Art. 6(1)(a) GDPR). See Cookies for what this involves and how to withdraw consent.

5. Cookies and storage on your device

The dashboard and the public order board use only strictly necessary and functional cookies there — no tracking, advertising, or analytics cookies. Our marketing pages (home, pricing, and sign-up) additionally offer one advertising cookie, but only with your consent — see below.

  • appwrite-session (strictly necessary) — keeps you signed in to the dashboard. It is HttpOnly (not readable by JavaScript), Secure, and SameSite=strict, and lasts for the duration of your session (up to ~30 days). Without it you could not stay logged in. Set for stall owners and staff only.
  • qstatus-staff-mode (strictly necessary) — records that a device has been unlocked into staff mode, so a till tablet stays confined to the board and kitchen views. It is HttpOnly and Secure, holds no more than a marker value, and lasts up to 90 days. Set for stall owners and staff only.
  • NEXT_LOCALE (functional) — remembers your language choice (English or Croatian) so the site loads in your preferred language. It holds only a two-letter language code, contains no identifying information, and is set on all pages, including the public order board.
  • _fbp, and _fbc where you arrived via an ad click (advertising, consent-based) — set by Meta's Pixel on our marketing pages only, to measure whether an ad led to a visit or sign-up and to help us run better ads. Never set on the dashboard or the public order board. Declining the advertising cookie still lets you use every part of the Service.

Because the necessary and functional cookies above are needed to deliver a service you have requested or to remember a preference you have set, they are exempt from the consent requirement under the ePrivacy rules and Croatian electronic communications law. The advertising cookie is different — it is not necessary to deliver the Service — so the cookie notice asks for your consent the first time you visit a marketing page, with an "Accept" or "Necessary only" choice. You can change your mind at any time with the "Cookie preferences" link below.

Two things are also stored in your browser's local storage rather than as cookies. Neither is sent to us automatically, and you can clear both by clearing site data.

  • qstatus.my-orders.v1 — the order numbers you placed at a stall, so your own numbers can be highlighted on the board and you can be alerted when one is ready. It is kept on your device only, expires after six hours, and holds at most the last 20 orders per stall.
  • qstatus-consent — records your cookie-notice choice (including whether you accepted the advertising cookie), so it is not shown again until you change your mind.

If you ask to be notified when your order is ready, your browser also installs a small service worker script that receives the notification. It stores nothing. If you install QStatus to your home screen, your browser keeps the application files locally, as it would for any installed web app.

Subscribing redirects you to Stripe's own checkout page (on stripe.com), where Stripe sets its own cookies. That redirect happens only when a stall owner clicks to subscribe — never on an ordinary page view, and never on the public board.

If you accept the advertising cookie and later create an account, we also send Meta a matching sign-up event from our own server (Conversions API), so ad measurement stays reliable even when a browser blocks cookies. That server-side message carries a one-way cryptographic hash (SHA-256) of your email address plus technical values like your IP address and browser — never your name, password, or a readable copy of your email — and is sent only for accounts created from a marketing-page visit where you had accepted the cookie. See Recipients for more on Meta specifically.

6. Who we share data with (processors)

We do not sell personal data. We share it only with service providers that help us run QStatus, under contracts that require them to protect it and to process it only on our instructions:

  • Appwrite — our backend platform for authentication, database, real-time updates, and account emails (verification and password reset). Hosted in the European Union (Frankfurt, Germany).
  • Hetzner Online GmbH — our cloud hosting provider (Germany, EU), which runs the servers the QStatus application operates on. It processes technical data such as the IP addresses in server logs.
  • Stripe — our payment processor for the stall owner's own subscription. QStatus is the seller of record for your subscription and issues your invoice; Stripe processes your payment details and calculates applicable VAT/tax on our behalf. It also receives the monthly order count per account, because usage is billed per order.
  • Teya — the card payment provider for customer orders, used only at stalls that have connected their own Teya account. The order amount, currency, and item lines are sent to Teya to open a payment session, and the customer enters card details on Teya's own hosted page. QStatus never sees or stores card data.
  • Resend — our email provider for customer receipts. Where a customer supplies an email address, Resend processes that address and the receipt content (items, totals, VAT, the fiscal identifiers, and any note the customer wrote). Resend is based in the United States.
  • Browser push services — where a customer opts in to a notification, the delivery is handled by whichever service their browser uses: Google (Chrome, Edge, Opera), Mozilla (Firefox), Apple (Safari), or Microsoft. They receive the device's push address and an encrypted message containing the stall name and the order number, both of which are already public on the board. Some of these providers are based in the United States.

We may also disclose data where required by law or to establish, exercise, or defend legal claims. Stall owners: this same list forms the agreed subprocessor list in the data-processing terms in our Terms of Use, and we will tell you before it changes.

One more recipient, kept separate from the list above because it is not a processor acting only on our instructions: if you visit our marketing pages and accept the advertising cookie, we send Meta Platforms Ireland Limited a record of that visit and, if you sign up for a trial, the hashed sign-up event described in Cookies. This is solely to measure and improve our own advertising on Meta's platforms; Meta also uses this data under its own terms, not only ours, which is why it isn't listed as an ordinary subprocessor. It never touches the public order board, the dashboard, or customer-order data, and only happens where you have consented.

7. Reporting to the Croatian Tax Administration

Where a stall sells online through QStatus, Croatian law requires each receipt to be reported to the Tax Administration's Central Information System (CIS) before it is handed to the customer. We do this on the stall's behalf, signing with the stall's own FINA certificate. The Tax Administration is not our processor: it receives the data as an authority in its own right, and we transmit it to satisfy a legal obligation (Art. 6(1)(c) GDPR).

What is sent is the receipt, not the customer: the stall's OIB and business premise and device marks, the receipt number and time, the total and its VAT breakdown, the payment method, and the security codes required by law. No customer name, email address, order note, or item description is ever sent to the Tax Administration. What comes back is the receipt's unique identifier, which is printed on your receipt so you can verify it.

Orders paid at the stall's own counter are not reported by us at all — the stall's own cash register issues that receipt.

8. What is publicly visible

Some information in QStatus is public by design, and you should assume anyone with the link can read it:

  • The order board. Order numbers and their status are readable by anyone who has a stall's code, because that is what lets a customer's phone update live without logging in. Board numbers identify an order, not a person, and carry no name, email, or amount.
  • The menu, including item names, descriptions, and prices.
  • The stall directory. A stall's name, town or city, and code are listed on our public directory page by default. An owner can remove a stall from the directory at any time in Settings; doing so does not hide the board itself, which stays reachable by its code.

9. International data transfers

Our database, authentication, and hosting are all within the EU/EEA. Two things reach providers outside it: customer receipt emails, sent through Resend, and push notifications, delivered by the customer's own browser vendor. Both are based in the United States. A third, consent-based flow also leaves the EU/EEA: where a marketing-page visitor accepts the advertising cookie, our contracting entity Meta Platforms Ireland Limited (based in the EU) may transfer the data described in Cookies and Recipients to Meta Platforms, Inc. in the United States.

Those transfers are protected by an adequacy decision or by the European Commission's Standard Contractual Clauses together with appropriate safeguards. You can ask us for a copy of the safeguards at any time.

10. How long we keep your data

  • Account and stall data: kept while your account is active, and deleted when you delete your account (see Your rights).
  • Customer orders and receipts: an order record, including any email address and note given at checkout, is a financial and fiscal record. We keep it for as long as the stall's account exists and Croatian tax and accounting law requires it (currently 11 years), and it is not deleted automatically when the order is finished. Abandoned orders that were never paid for are marked expired rather than deleted, for the same reason.
  • Our own invoices and accounting records: retained for the period required by Croatian tax and accounting law (currently 11 years), even after account deletion.
  • Push notification addresses: deleted as soon as the order is done, and in any case swept automatically within a few hours of the order expiring.
  • Order history on your own device: expires by itself after six hours.
  • Security and technical logs: kept only for a short period as needed for security and troubleshooting. Rate-limiting data lives in memory only and is discarded when the server restarts.

11. Your rights

Under the GDPR you have the right to: access your data; rectify inaccurate data; erase your data; restrict or object to processing; and data portability. You can exercise most of these directly in the app or by emailing us.

  • Erasure (right to be forgotten): you can delete your account yourself at any time from your Profile page. This permanently removes your account, stalls, menus, orders, and customer and subscription records from our systems, destroys your stored Teya credentials and FINA certificate, and cancels any active subscription immediately. Records we are required by law to keep — such as statutory invoices and fiscal receipts — are retained as described above.
  • Other requests: email info@dinamik.dev and we will respond within one month.

If you are a customer who ordered from a stall, the stall is the controller of your order, so a request about it is best sent to the stall directly. You can also write to us and we will either pass the request on or act on it for the stall, as our contract with it requires. We will always help you reach the right party rather than turn you away.

12. Right to lodge a complaint

If you believe we have processed your personal data unlawfully, you have the right to lodge a complaint with the Croatian supervisory authority:

  • Agencija za zaštitu osobnih podataka (AZOP)
  • Selska cesta 136, 10000 Zagreb, Hrvatska
  • https://azop.hr

13. Automated decision-making

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.

14. How we protect your data

We use encryption in transit (HTTPS), store passwords only as salted hashes, route every data change through server-side checks that verify who you are and what you own, restrict access to authorised personnel, and apply the principle of least privilege.

The most sensitive material gets specific protection: FINA certificates, their passphrases, and Teya credentials are encrypted at rest with AES-256-GCM; staff PINs are stored as scrypt hashes and compared in constant time; push notifications can only be sent to an allowlist of known browser vendors; and the browser is never given permission to write to our database directly. No system is perfectly secure, but we work to protect your data appropriately.

15. Children

QStatus is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 16.

16. Changes to this policy

We may update this policy from time to time. We will post the updated version here and change the 'Last updated' date. Material changes will be communicated where appropriate.

Company details

DINAMIK d.o.o.
Šušnjevec 49, 10000 Zagreb, Hrvatska
Registered at
Trgovački sud u Zagrebu
Court register no. (MBS)
080014746
OIB
66166833677
VAT ID
HR66166833677
Share capital
2.654,00 EUR (paid in full)
Sole founder & director
Jura Milković
Bank
Raiffeisenbank Austria d.d.
IBAN
HR3824840081106801578
SWIFT/BIC
RZBHHR2XXXX
Email
info@dinamik.dev