Terms of ServicePrivacy Policy
Privacy Policy
This policy explains what personal data Shiffra collects, why, who else handles it, how long it is kept, and the rights you have over it. It applies to the Shiffra website and application.
The short version: the QR codes you make, the links inside them and the logos you add are processed on your own device and never sent to us. We collect only what an account needs, we do not sell your data, and we do not use advertising or analytics trackers.
1. Who is responsible for your data
Shiffra is operated by Zayd Bentalha, an individual based in Morocco, who is the controller of your personal data (the “data controller” under Moroccan Law No. 09-08 and, where it applies, the EU General Data Protection Regulation).
For any question or request about your data, write to zeedrxx@gmail.com.
2. What we collect
When you create and use an account, we collect:
- your first and last name;
- your email address;
- your password, stored only as a salted hash: nobody, including us, can read it;
- the country you choose at sign-up, and the language of the interface when you signed up;
- if you choose to add them: a phone number, which we do not verify, and a profile photo, which your browser reduces to a small square before sending it;
- if you sign up with Google: the name, email address and profile photo your Google account shares with us;
- the date and version of the Terms of Service and Privacy Policy you accepted.
When you use the service, our server and our hosting provider necessarily process technical data such as your IP address and browser information, to keep you signed in and to protect the service against abuse. We do not store your IP address with your account or your sessions. To limit repeated attempts, such as guessing a password, we keep a one-way hash of the address for at most a day; it cannot be turned back into the address.
When you sign up, our server checks whether the domain of your email address can receive mail and whether it belongs to a disposable-email service. The address is not stored by this check.
3. What we do not collect
- The content of the QR codes you create, including the links in them: codes are generated in your browser.
- The logos and images you add to a code: they are read and drawn on your device and are not uploaded.
- The results of the scan test: it runs entirely on your device.
- Advertising identifiers, analytics or tracking data: we use no such tools.
If we later offer features that require us to store codes or measure their scans (for example, codes whose destination can be changed after printing), this policy will be updated before those features are released, and you will choose whether to use them.
4. Why we use it, and on what basis
- To create and run your account, sign you in and let you manage your profile: this is necessary to provide the service you asked for (performance of a contract).
- To keep the service secure, prevent fraud, abuse and automated sign-ups: our legitimate interest in protecting the service and its users.
- To produce aggregated, anonymous statistics about the countries and languages of our users, so we can decide which translations and features to build: our legitimate interest. These statistics never identify you.
- To answer you when you contact us, and to tell you about important changes to the service or to these documents.
- To comply with our legal obligations.
We do not sell your personal data, we do not rent it, and we do not use it for advertising.
5. Who else handles your data
We rely on a small number of service providers, who process your data only on our instructions and only to provide their service to us:
- Google LLC (United States), through Gmail: delivery of the emails we send you, such as sign-up and password-reset codes.
- Neon (database hosted in Frankfurt, Germany, European Union): storage of your account record.
- Our hosting provider, which serves the website and runs its server functions.
- Google, if you choose to sign in with Google: Google confirms who you are and shares your name, email address and profile photo with us, under Google’s own privacy policy.
We may also disclose data where the law requires it, or to protect the rights and safety of Shiffra, its users or the public.
6. Transfers outside Morocco
Because our providers are located in the European Union and the United States, your data is transferred outside Morocco. We carry out these transfers in accordance with Law No. 09-08 and the requirements of the Moroccan data protection authority (CNDP), and we rely on providers that apply recognised safeguards, such as the European Commission’s standard contractual clauses, for the data they handle.
7. How long we keep it
- Account data is kept for as long as your account exists.
- When you delete your account, your account record, and any organisation you were the only member of, are removed from our database without delay, and from our providers’ systems within their deletion periods, usually within 30 days.
- Security and technical logs held by our providers are kept for their limited retention periods.
- We may keep a record of your acceptance of these documents for as long as we may need to prove it.
8. Your rights
Under Moroccan Law No. 09-08 you have the right to be informed, the right to access your data, the right to have it corrected or deleted, and the right to object, for legitimate reasons, to its processing. If you are in the European Union, you also have the rights to restrict processing and to data portability.
You can change your name, photo, password and phone number, and delete your account, yourself in Settings. For anything else, including receiving a copy of your data, write to zeedrxx@gmail.com. We answer within 30 days.
If you believe your data is not being handled correctly, you can complain to the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP, www.cndp.ma) or, in the European Union, to your local data protection authority.
9. Security
Connections to Shiffra are encrypted. Passwords are stored only as salted hashes and are checked against known data breaches when you choose one; only a partial fingerprint of the password is sent for that check, never the password. Changing your password or deleting your account asks you to confirm it is you, with your password or a code sent to your email. No system is perfectly secure; if a breach affecting your data occurs, we will notify you and the authorities where the law requires.
10. Minimum age
You must be at least 16 years old to create an account. We do not knowingly collect data from anyone younger. If you believe a child has created an account, write to zeedrxx@gmail.com and we will delete it.
12. Changes to this policy
If we change this policy in a way that matters, we will tell you by email or in the application before the change takes effect. The date of the current version is shown at the top of this page.
13. Contact
Zayd Bentalha, Morocco. Email: zeedrxx@gmail.com.