Legal
Privacy Policy
We believe in radical transparency. Here's exactly what data we collect, why, and how you can control it.
What We Collect
How We Use It
Cookies
Your Rights
Contact
shield
We never sell your data
Your personal information stays with us — always.
cookie
One session cookie
Just rb_sid to keep you logged in. No trackers.
delete_forever
Delete anytime
Request full account & data deletion at any time.
§1 Who We Are
We provide a link management and QR code platform for creators.
§2 Data We Collect
Account: Name, email, username, password (bcrypt). Content: Links, descriptions, QR configs. Analytics: Device type, country, referrer, timestamp. Technical: Session cookie, access logs (30 days). OAuth: Name, email, profile picture if you use social login.
§3 Legal Basis (GDPR)
Contract performance (Art. 6(1)(b)) for core features. Legitimate interests (Art. 6(1)(f)) for security. Consent (Art. 6(1)(a)) where requested. Legal obligation (Art. 6(1)(c)) where required.
§4 How We Use Data
Account management & authentication. Link routing and QR generation. Analytics dashboard. Transactional emails. Security monitoring. We never sell or share your data for marketing.
§5 Cookies & Storage
One first-party session cookie (rb_sid) — HttpOnly, SameSite=Lax, Secure on HTTPS. No third-party ad or tracking cookies.
§6 Data Sharing
Hosting provider for infrastructure. Google/Apple OAuth only if you use social login. QR rendering is fully local in the browser — no external requests.
§7 Retention
Account data: active account lifetime. Analytics: 90 days raw. Logs: 30 days. Post-deletion: all personal data removed within 30 days.
§8 Your Rights
Access (Art. 15), Rectification (Art. 16), Erasure (Art. 17), Restriction (Art. 18), Portability (Art. 20), Objection (Art. 21). We respond within 30 days.
§9 Security
HTTPS/TLS, bcrypt password hashing, CSRF protection, session isolation, regular security reviews.
§10 Children
returnbob is not for persons under 16. Contact us to remove any accidentally collected child data.
§11 Changes
Material changes announced by email or in-app notice at least 14 days before taking effect.
§12 Contact
Privacy inquiries: privacy@returnbob.com
DPO: