returnbob

Legal

Privacy Policy

We believe in radical transparency. Here's exactly what data we collect, why, and how you can control it.

What We Collect How We Use It Cookies Your Rights Contact
shield
We never sell your data

Your personal information stays with us — always.

cookie
One session cookie

Just rb_sid to keep you logged in. No trackers.

delete_forever
Delete anytime

Request full account & data deletion at any time.

§1 Who We Are

We provide a link management and QR code platform for creators.

§2 Data We Collect

Account: Name, email, username, password (bcrypt). Content: Links, descriptions, QR configs. Analytics: Device type, country, referrer, timestamp. Technical: Session cookie, access logs (30 days). OAuth: Name, email, profile picture if you use social login.

§3 Legal Basis (GDPR)

Contract performance (Art. 6(1)(b)) for core features. Legitimate interests (Art. 6(1)(f)) for security. Consent (Art. 6(1)(a)) where requested. Legal obligation (Art. 6(1)(c)) where required.

§4 How We Use Data

Account management & authentication. Link routing and QR generation. Analytics dashboard. Transactional emails. Security monitoring. We never sell or share your data for marketing.

§5 Cookies & Storage

One first-party session cookie (rb_sid) — HttpOnly, SameSite=Lax, Secure on HTTPS. No third-party ad or tracking cookies.

§6 Data Sharing

Hosting provider for infrastructure. Google/Apple OAuth only if you use social login. QR rendering is fully local in the browser — no external requests.

§7 Retention

Account data: active account lifetime. Analytics: 90 days raw. Logs: 30 days. Post-deletion: all personal data removed within 30 days.

§8 Your Rights

Access (Art. 15), Rectification (Art. 16), Erasure (Art. 17), Restriction (Art. 18), Portability (Art. 20), Objection (Art. 21). We respond within 30 days.

§9 Security

HTTPS/TLS, bcrypt password hashing, CSRF protection, session isolation, regular security reviews.

§10 Children

returnbob is not for persons under 16. Contact us to remove any accidentally collected child data.

§11 Changes

Material changes announced by email or in-app notice at least 14 days before taking effect.

§12 Contact

Privacy inquiries: privacy@returnbob.com
DPO: