Privacy Policy
Last updated: 18 August 2026 · Operated by DINAMIK d.o.o. · OIB 66166833677
This Privacy Policy explains how DINAMIK d.o.o. processes personal data when you use QStatus, our live order-status board and self-serve ordering service for food stalls ("QStatus" or the "Service"). It covers the dashboard used by stall owners and staff, the public order board, and the ordering, card payment, fiscal receipt, and notification features that go with it. We process personal data in accordance with the EU General Data Protection Regulation (GDPR, Reg. (EU) 2016/679) and applicable Croatian law.
1. Who we are (data controller)
The controller responsible for your personal data is:
- DINAMIK d.o.o. (limited liability company)
- OIB (personal identification number): 66166833677
- Registered address: Šušnjevec 49, 10000 Zagreb, Hrvatska
- Director: Jura Milković
- Contact for privacy matters: info@dinamik.dev
For any question about this policy or to exercise your rights, contact us at info@dinamik.dev. We have not appointed a Data Protection Officer, as we are not legally required to.
We are the controller for stall owner and staff data. For the data of customers who order from a stall, the stall itself is the controller and we act as its processor — see the next section.
2. Who this policy applies to, and in which role
QStatus has two very different kinds of user, and we hold a different legal role for each.
- Stall owners and staff who create an account and use the dashboard. For their account, stall, and billing data we are the controller — we decide why and how it is processed, and this policy governs it.
- Customers who scan a stall's QR code. Where a customer places an order, we handle their data as a processor on behalf of the stall: the stall decides to sell, issues the receipt in its own name, and is the controller of that order. We process it only to run the ordering, payment, and receipt features the stall has switched on.
If you only watch the board, nothing changes for you: the public board shows anonymous order numbers and their status, and we collect no name, email, or contact details from you. We set no tracking or advertising cookies on any device, and run no analytics product at all.
If you place an order, you do give us data — at minimum the items you chose, and, if the stall takes card payments, an email address so the fiscal receipt can be sent to you. Section 3 lists exactly what, and section 11 explains how to exercise your rights over it.
3. What personal data we collect
From stall owners and staff who register:
- Account data: your name, email address, and password (stored only as a salted hash, never in plain text), plus whether your email has been verified.
- Stall data: the stall name, its town or city, an automatically generated stall code, your menu, and the order numbers and timestamps that run the board.
- Staff PIN: if you set a PIN to lock a till device into board and kitchen view, we store only a cryptographic hash of it (scrypt) and its salt — never the digits.
- Billing data: subscription status, plan, billing period, your monthly order count (used to calculate the per-order fee), and the identifiers linking your account to your payment. Card details are handled by Stripe and are never stored on our systems.
- Technical and security data: your IP address and request metadata, used transiently to operate the Service and to rate-limit sign-in and sign-up against abuse, plus a strictly necessary session cookie (see Cookies).
From stall owners who connect payments or fiscalization, we additionally store, encrypted at rest: your OIB and registered business name, your business premise and device marks, your FINA application certificate and its passphrase, and your Teya credentials. These identify your business to the Tax Administration and to your payment provider; we use them for nothing else.
From customers who place an order (as processor for the stall):
- Your order: the items and quantities you chose, the total, and the language you were browsing in (so the receipt reaches you in that language).
- Your email address — optional, and only requested where the stall takes card payment, because Croatian law requires the fiscal receipt to be delivered to you. If you pay at the counter we do not ask for it and do not store one.
- Your note to the kitchen — optional and free-text. It is shown to the stall's staff and repeated on your receipt. Please do not write anything into it you would not want the stall to read; in particular, avoid health details. If you need to tell the stall about an allergy, we would rather you told them in person.
- A push notification address — only if you tap to be told when your order is ready. This is a handle for your browser, not for you, and it is deleted once the order is done.
- Your IP address, held briefly in memory to rate-limit ordering against abuse. It is not written to our database.
We do not intentionally collect special categories of personal data, and we ask you not to enter such data into order numbers, stall names, menu items, or order notes.
4. Why we process your data and our legal bases
- To provide the Service — create and manage your account, run your order boards, menus, kitchen display, and analytics (legal basis: performance of a contract, Art. 6(1)(b) GDPR).
- To take payment and manage subscriptions — including calculating the per-order usage fee, via our payment provider (Art. 6(1)(b) GDPR).
- To process customer orders and take payment for them — on the stall's behalf and on its instructions (Art. 6(1)(b) GDPR between the customer and the stall; Art. 6(1)(f) for us as its processor).
- To issue fiscal receipts — submitting each card-paid receipt to the Croatian Tax Administration and delivering the receipt to the customer is a legal obligation of the stall, which we discharge on its behalf (Art. 6(1)(c) GDPR).
- To meet our own legal obligations — issuing and keeping invoices and accounting records (Art. 6(1)(c) GDPR).
- To keep the Service secure — authentication, abuse prevention, and rate limiting (Art. 6(1)(f) GDPR; our legitimate interest in protecting the Service and its users).
- To send service emails — such as account verification and password reset (Art. 6(1)(b) GDPR).
- To send order-ready push notifications — only where you have asked for them (consent, Art. 6(1)(a) GDPR). You can withdraw consent at any time by revoking the notification permission in your browser.
- To measure and improve our own advertising — only on our public marketing pages (home, pricing, and sign-up), never on the dashboard or the public order board, and only if you accept the advertising cookie in the cookie notice (consent, Art. 6(1)(a) GDPR). See Cookies for what this involves and how to withdraw consent.
6. Who we share data with (processors)
We do not sell personal data. We share it only with service providers that help us run QStatus, under contracts that require them to protect it and to process it only on our instructions:
- Appwrite — our backend platform for authentication, database, real-time updates, and account emails (verification and password reset). Hosted in the European Union (Frankfurt, Germany).
- Hetzner Online GmbH — our cloud hosting provider (Germany, EU), which runs the servers the QStatus application operates on. It processes technical data such as the IP addresses in server logs.
- Stripe — our payment processor for the stall owner's own subscription. QStatus is the seller of record for your subscription and issues your invoice; Stripe processes your payment details and calculates applicable VAT/tax on our behalf. It also receives the monthly order count per account, because usage is billed per order.
- Teya — the card payment provider for customer orders, used only at stalls that have connected their own Teya account. The order amount, currency, and item lines are sent to Teya to open a payment session, and the customer enters card details on Teya's own hosted page. QStatus never sees or stores card data.
- Resend — our email provider for customer receipts. Where a customer supplies an email address, Resend processes that address and the receipt content (items, totals, VAT, the fiscal identifiers, and any note the customer wrote). Resend is based in the United States.
- Browser push services — where a customer opts in to a notification, the delivery is handled by whichever service their browser uses: Google (Chrome, Edge, Opera), Mozilla (Firefox), Apple (Safari), or Microsoft. They receive the device's push address and an encrypted message containing the stall name and the order number, both of which are already public on the board. Some of these providers are based in the United States.
We may also disclose data where required by law or to establish, exercise, or defend legal claims. Stall owners: this same list forms the agreed subprocessor list in the data-processing terms in our Terms of Use, and we will tell you before it changes.
One more recipient, kept separate from the list above because it is not a processor acting only on our instructions: if you visit our marketing pages and accept the advertising cookie, we send Meta Platforms Ireland Limited a record of that visit and, if you sign up for a trial, the hashed sign-up event described in Cookies. This is solely to measure and improve our own advertising on Meta's platforms; Meta also uses this data under its own terms, not only ours, which is why it isn't listed as an ordinary subprocessor. It never touches the public order board, the dashboard, or customer-order data, and only happens where you have consented.
8. What is publicly visible
Some information in QStatus is public by design, and you should assume anyone with the link can read it:
- The order board. Order numbers and their status are readable by anyone who has a stall's code, because that is what lets a customer's phone update live without logging in. Board numbers identify an order, not a person, and carry no name, email, or amount.
- The menu, including item names, descriptions, and prices.
- The stall directory. A stall's name, town or city, and code are listed on our public directory page by default. An owner can remove a stall from the directory at any time in Settings; doing so does not hide the board itself, which stays reachable by its code.
9. International data transfers
Our database, authentication, and hosting are all within the EU/EEA. Two things reach providers outside it: customer receipt emails, sent through Resend, and push notifications, delivered by the customer's own browser vendor. Both are based in the United States. A third, consent-based flow also leaves the EU/EEA: where a marketing-page visitor accepts the advertising cookie, our contracting entity Meta Platforms Ireland Limited (based in the EU) may transfer the data described in Cookies and Recipients to Meta Platforms, Inc. in the United States.
Those transfers are protected by an adequacy decision or by the European Commission's Standard Contractual Clauses together with appropriate safeguards. You can ask us for a copy of the safeguards at any time.
10. How long we keep your data
- Account and stall data: kept while your account is active, and deleted when you delete your account (see Your rights).
- Customer orders and receipts: an order record, including any email address and note given at checkout, is a financial and fiscal record. We keep it for as long as the stall's account exists and Croatian tax and accounting law requires it (currently 11 years), and it is not deleted automatically when the order is finished. Abandoned orders that were never paid for are marked expired rather than deleted, for the same reason.
- Our own invoices and accounting records: retained for the period required by Croatian tax and accounting law (currently 11 years), even after account deletion.
- Push notification addresses: deleted as soon as the order is done, and in any case swept automatically within a few hours of the order expiring.
- Order history on your own device: expires by itself after six hours.
- Security and technical logs: kept only for a short period as needed for security and troubleshooting. Rate-limiting data lives in memory only and is discarded when the server restarts.
11. Your rights
Under the GDPR you have the right to: access your data; rectify inaccurate data; erase your data; restrict or object to processing; and data portability. You can exercise most of these directly in the app or by emailing us.
- Erasure (right to be forgotten): you can delete your account yourself at any time from your Profile page. This permanently removes your account, stalls, menus, orders, and customer and subscription records from our systems, destroys your stored Teya credentials and FINA certificate, and cancels any active subscription immediately. Records we are required by law to keep — such as statutory invoices and fiscal receipts — are retained as described above.
- Other requests: email info@dinamik.dev and we will respond within one month.
If you are a customer who ordered from a stall, the stall is the controller of your order, so a request about it is best sent to the stall directly. You can also write to us and we will either pass the request on or act on it for the stall, as our contract with it requires. We will always help you reach the right party rather than turn you away.
12. Right to lodge a complaint
If you believe we have processed your personal data unlawfully, you have the right to lodge a complaint with the Croatian supervisory authority:
- Agencija za zaštitu osobnih podataka (AZOP)
- Selska cesta 136, 10000 Zagreb, Hrvatska
- https://azop.hr
13. Automated decision-making
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.
14. How we protect your data
We use encryption in transit (HTTPS), store passwords only as salted hashes, route every data change through server-side checks that verify who you are and what you own, restrict access to authorised personnel, and apply the principle of least privilege.
The most sensitive material gets specific protection: FINA certificates, their passphrases, and Teya credentials are encrypted at rest with AES-256-GCM; staff PINs are stored as scrypt hashes and compared in constant time; push notifications can only be sent to an allowlist of known browser vendors; and the browser is never given permission to write to our database directly. No system is perfectly secure, but we work to protect your data appropriately.
15. Children
QStatus is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 16.
16. Changes to this policy
We may update this policy from time to time. We will post the updated version here and change the 'Last updated' date. Material changes will be communicated where appropriate.
Company details
- DINAMIK d.o.o.
- Šušnjevec 49, 10000 Zagreb, Hrvatska
- Registered at
- Trgovački sud u Zagrebu
- Court register no. (MBS)
- 080014746
- OIB
- 66166833677
- VAT ID
- HR66166833677
- Share capital
- 2.654,00 EUR (paid in full)
- Sole founder & director
- Jura Milković
- Bank
- Raiffeisenbank Austria d.d.
- IBAN
- HR3824840081106801578
- SWIFT/BIC
- RZBHHR2XXXX
- info@dinamik.dev