1. Introduction
This Privacy Policy explains how Chaos Technologies ("we", "us") collects, uses and protects personal data when you use https://chaos-qr-dynamics.website/ and our QR code generator.
We comply with Regulation (EU) 2016/679 (GDPR) and applicable national law.
2. Data Controller
Chaos Technologies is the data controller for the website and tool operation.
Contact: the.tech.of.chaos@gmail.com.
For payments, Lemon Squeezy acts as Merchant of Record (MoR) and independent controller/processor for payment data per the Lemon Squeezy Privacy Policy.
3. Merchant of Record — Lemon Squeezy
Paid downloads (€0.50 discount / €1.00 instant) are processed via Lemon Squeezy. Sold through Link, LLC f/k/a Lemon Squeezy LLC is the official Merchant of Record.
Lemon Squeezy handles payment processing, sales tax where required, PCI compliance, refunds and chargebacks per MoR documentation.
Chaos Technologies delivers digital files (SVG + Live HTML) and does not store card details.
4. Data We Collect
User input in browser: URL, optional logo (processed locally), generated QR files.
Technical data: IP, browser, device, hosting logs (Netlify) for security and operation.
sessionStorage: checkout return tokens (e.g. pendingDiscountReviewToken).
Payment data: email, name, billing address if required — collected by Lemon Squeezy at checkout.
5. Purposes & Legal Bases
Service provision / contract (Art. 6(1)(b)): QR generation, downloads, purchase completion.
Legitimate interests (Art. 6(1)(f)): security, abuse prevention, service improvement.
Legal obligation (Art. 6(1)(c)): tax/accounting via MoR where applicable.
Consent (Art. 6(1)(a)): optional social sharing, non-essential cookies if added.
6. Cookies & Local Storage
We use sessionStorage for checkout/download flows. No advertising cookies are placed by us.
CDN scripts may log technical data per their providers.
You may clear sessionStorage in browser settings.
7. Sharing with Third Parties
Lemon Squeezy — payments, MoR, refunds (DPA).
Netlify/hosting — static site hosting.
Google (optional) — review link you choose to open.
We do not sell personal data.
8. International Transfers
Providers may process data outside the EEA with appropriate safeguards (SCCs etc.) per their policies.
9. Retention
sessionStorage: cleared when tab/browser closes or after flow completion.
Hosting logs: limited security retention.
Payment records: retained by Lemon Squeezy per law and their policy.
10. Your GDPR Rights
Access, rectification, erasure, restriction, portability, objection and withdrawal of consent.
Requests via the.tech.of.chaos@gmail.com. We respond within 30 days.
You may lodge a complaint with your supervisory authority.
For payment data, you may also exercise rights with Lemon Squeezy directly.
11. Security & Minors
We apply technical/organisational measures (HTTPS, minimal collection, local logo processing).
Not intended for users under 16.
12. Changes
We may update this policy. Continued use after changes constitutes acceptance.