Privacy Policy
Last updated: 22 August 2026
1. Controller
ViBuCard S.L.Avinguda de Joan Miró 13807015 Palma de MallorcaSpain- Tax number
- ESB44672178
- Represented by
- Pasquale D'Ambrosio
- [email protected]
- Phone
- +34 971 86 37 29
Data protection officer: we have not appointed a data protection officer, as the statutory conditions for doing so are not met.
Competent supervisory authority: Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, Spain. You may also contact the supervisory authority where you habitually reside.
2. Whose data we process
Prospects and website visitors: people who visit veridaro.com or contact us.
Customers: businesses and people with a Veridaro subscription, and their contacts.
Guests of our customers: people who scan a Veridaro QR code. For that data our customer is normally the controller. We process it as a processor on their instructions.
Partners in the referral programme.
3. What data we process and why
Master data (name, email, company, address, telephone) is processed to perform the contract, to run the customer account and for support. The legal basis is Article 6 (1) (b) GDPR. We store this data for the term of the contract plus the statutory retention periods.
Payment data is processed through our payment service provider in order to process the payment. The legal basis is Article 6 (1) (b) GDPR.
Invoice-related data (invoices, payment records and the data needed to produce them) is kept for six years on the basis of statutory retention obligations (Article 30 of the Spanish Código de Comercio). The legal basis is Article 6 (1) (c) GDPR.
Usage data of the software (logins, scans, forwardings triggered, statistics) is processed in order to provide the software, to produce the statistics shown in the customer account, to improve the software and to detect misuse. The legal bases are Article 6 (1) (b) and (f) GDPR. This data is the basis of the statistics view and therefore remains stored for the term of the contract. After the contract ends we delete it within the periods named in section 14 of our terms and conditions.
Access logs: the application server itself keeps no access log. The router in front of it (Traefik) does log every request with the time, the path requested, the response code and the address the request reaches it from. Because our content delivery network sits in front, that is as a rule its address and not yours; if the website is addressed directly in exceptional cases, your IP address appears there. We additionally use your IP address transiently in memory in order to limit the number of requests per minute; it is not stored in the process. The legal basis is Article 6 (1) (f) GDPR; our legitimate interest lies in secure and undisturbed operation.
Email addresses for system messages are processed in order to send confirmations, invoices and cancellation and withdrawal confirmations. The legal basis is Article 6 (1) (b) GDPR. Storage period: for the term of the contract.
Cancellation and withdrawal statements that you submit using the “Cancel contracts here” or “Withdraw from contract” buttons are stored with the details you provide and with the date and time of receipt. We need that record because the law obliges us to confirm receipt of your statement to you and to be able to prove it. The legal bases are Article 6 (1) (c) GDPR (sections 312k and 355 of the German Civil Code) and Article 6 (1) (b) GDPR. We keep these statements for three years from the end of the year in which they were received and delete them after that.
Email addresses for the newsletter are processed on the basis of your consent under Article 6 (1) (a) GDPR. You can withdraw your consent at any time, for example using the unsubscribe link in every email.
Cookies that are not necessary to run the website are only set with your consent. On this website that applies exclusively to the referral programme (section 4.4). The legal bases are section 25 (1) TDDDG and Article 6 (1) (a) GDPR.
Guest data on a QR scan: we store the time of the scan, the QR code scanned and the location linked to it, the rating chosen, whether the guest was forwarded to the review platform, and the browser identifier (user agent) in order to detect automated access. The guest’s IP address is not stored, and no cookies are set in the guest journey. If a guest submits internal feedback, we store their text, the rating and, where they provide it voluntarily, their email address so the business can reply. For this processing the respective business is the controller; we act as a processor under Article 28 GDPR on their instructions. We delete this data when the business's contract ends, within the periods set out in section 14 of our terms and conditions; earlier if the business instructs us to.
4. Recipients and processors
We only pass data to service providers who support us in delivering our service. We have concluded a data processing agreement under Article 28 GDPR with all of them, to the extent that they process on our behalf.
4.1 Supabase, database
Provider: Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513, Singapore.
Supabase runs the database that holds our customers’ data and the data processed through Veridaro. The account and session data for logging in is also held there; the login process itself runs in our own application. Processed is all data arising from the use of Veridaro, in particular account data, our customers’ business data and the data recorded in connection with QR scans.
Server location: our Supabase instance runs in the region eu-central-1, Frankfurt am Main, Germany. Supabase undertakes contractually to store data in the chosen region and to process it there primarily.
Third country transfer: Supabase is based in Singapore and uses sub-processors outside the European Economic Area. For those transfers Supabase relies on the European Commission’s standard contractual clauses under Article 46 (2) (c) GDPR.
Legal basis: Article 6 (1) (b) GDPR.
Supabase data processing agreement and list of sub-processors
4.2 Stripe, payment processing
Provider for customers in the European Economic Area: Stripe Payments Europe, Limited, One Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland (Companies Registration Office no. 513174).
Processed are name, email address, billing address, payment data such as card details or IBAN, transaction data and technical data for fraud prevention. We neither collect nor store full card details; they are transmitted directly to Stripe.
In relation to us, Stripe is partly an independent controller, in particular for fraud prevention and regulatory obligations, and partly a processor. For transfers to the United States, Stripe relies on the European Commission’s standard contractual clauses.
Legal basis: Article 6 (1) (b) GDPR.
4.3 Resend, sending emails
Provider: Resend, 2261 Market Street #5039, San Francisco, CA 94114, United States.
We use Resend to send system messages such as registration confirmations, invoices and cancellation and withdrawal confirmations. Processed are the recipient address, the subject and content of the message and delivery logs such as delivery and bounces.
Third country transfer: Resend stores account data, email metadata, logs and API records in the United States. Choosing a sending region within the European Union only controls where emails are sent from, not where the data is stored. Resend is certified under the EU-U.S. Data Privacy Framework; the European Commission’s adequacy decision forms the basis of the transfer under Article 45 GDPR. The standard contractual clauses apply in addition.
Legal basis: Article 6 (1) (b) GDPR for system messages, Article 6 (1) (a) GDPR for the newsletter.
4.4 Rewardful, referral and partner programme
Provider: Rewardful Inc., Suite 3810 Bankers Hall West, 888 3rd Street SW, Calgary, Alberta T2P 5C5, Canada.
Rewardful attributes new customers to the partner who referred them and calculates the commission. To do that, Rewardful sets a cookie for visitors who arrive on our website through a partner link. Processed are the referral identifier, the time of the visit, conversion events and, where a contract comes about, the link to the payment.
Rewardful runs its application on Heroku, a service of the Salesforce group whose infrastructure is provided by Amazon Web Services.
Third country transfer: Rewardful is based in Canada. For transfers to companies subject to the Canadian data protection act PIPEDA there is an adequacy decision of the European Commission under Article 45 GDPR. Where data is passed on to the United States in the course of hosting through Heroku and Amazon Web Services, that transfer relies on the European Commission’s standard contractual clauses under Article 46 (2) (c) GDPR.
Legal basis: your consent under section 25 (1) TDDDG in conjunction with Article 6 (1) (a) GDPR. The Rewardful script is only loaded after you have given consent in the cookie notice.
4.5 Hosting and content delivery network
Our website runs in a dedicated container on a server operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server location is Nuremberg, Germany. The content of this website is therefore processed within the European Union. Hetzner is our processor under Article 28 GDPR.
Upstream we use Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, United States, as a content delivery network and for protection against attacks. Cloudflare processes the IP address and technical metadata of the request before it is forwarded to our server. For transfers to the United States, Cloudflare relies on the European Commission’s standard contractual clauses and on the EU-U.S. Data Privacy Framework.
Legal basis: Article 6 (1) (f) GDPR, our legitimate interest in providing the website securely, quickly and reliably.
4.6 Google services
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. For transfers to the United States: Google LLC, certified under the EU-U.S. Data Privacy Framework; the standard contractual clauses apply in addition.
Sign in with Google: customers can choose to sign in to their customer account with their Google account. If you choose that route, Google transmits your name, your email address and confirmation that the address has been verified. Without that click no connection to Google takes place; signing in through a link sent by email always remains available as an alternative. The legal basis is Article 6 (1) (b) GDPR.
Google Fonts are embedded locally from our own server. No connection to Google servers takes place in the process.
We do not use Google Analytics, Google Maps or the Google Places interface on this website. The reviews shown on the website are verbatim quotations stored in the site; they are not fetched from Google on each visit.
4.7 Other services
Chat assistant and translations: The chat assistant on this website is powered by a language model from Anthropic, which we also use to translate our customers' offerings. The contracting party within the European Economic Area is Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland; processing may also take place at Anthropic PBC, 548 Market St, PMB 90375, San Francisco, CA 94104, United States, based on the European Commission's standard contractual clauses. The most recent messages of the ongoing conversation are transmitted so the answer fits the context. Before a message leaves our site, a check replaces recognisable personal details such as email addresses and phone numbers with placeholders. We do not store the conversation on our servers. According to Anthropic, content sent through the interface is not used to train its models. Please still avoid entering sensitive data in the chat. The legal basis is Art. 6(1)(f) GDPR, our legitimate interest in answering questions about our offering directly.
Umami, reach measurement: to see which pages are viewed how often we use Umami from the provider Umami Software, Inc., San Francisco, California, United States. According to the provider, Umami sets no cookies and collects no personal data; what is recorded are page views, the referring address, browser, operating system, device type and country of origin in aggregated form. Because nothing is stored on or read from your device, no consent under section 25 TDDDG is required for this. The provider’s servers are located in the United States and in the European Union; the European Commission’s standard contractual clauses apply to transfers to the United States. The legal basis is Article 6 (1) (f) GDPR, our legitimate interest in an understandable measure of reach without tracking individuals.
5. Transfers to third countries
Some of the service providers named process data outside the European Union, in particular in the United States, in Canada and in Singapore. We base those transfers on the European Commission’s adequacy decisions under Article 45 GDPR, to the extent that the provider or the destination country is covered by them, and otherwise on the European Commission’s standard contractual clauses under Article 46 (2) (c) GDPR.
We point out that in third countries a level of data protection fully comparable to that of the European Union cannot be guaranteed and that authorities in the United States in particular may access data under certain conditions.
6. Cookies and similar technologies
We use technically necessary cookies that are required to run the website, to log in and to store your cookie decision. The legal basis is section 25 (2) no. 2 TDDDG.
All other cookies are only set with your consent. You can change or withdraw your consent at any time with effect for the future using the cookie settings in the footer of every page.
| Name | Provider | Purpose | Lifetime | Category |
|---|---|---|---|---|
__Secure-authjs.session-token | Veridaro | signing in to the customer account | 30 days | Technically necessary |
__Secure-authjs.callback-url, __Host-authjs.csrf-token | Veridaro | running and securing the sign-in process | session | Technically necessary |
veridaro_dash_locale | Veridaro | language chosen in the customer account | 1 year | Technically necessary |
veridaro_consent | Veridaro | stores your decision in the cookie notice | 6 months | Technically necessary |
__stripe_mid | Stripe | fraud prevention during payment | 1 year | Technically necessary |
__stripe_sid | Stripe | fraud prevention during payment | 30 minutes | Technically necessary |
rewardful.referral | Rewardful | attributing new customers to the referring partner | up to 60 days | Consent required |
The Stripe cookies are only set once you begin a payment. The sign-in cookies only come into being when you log in.
7. Your rights
You have the right of access under Article 15 GDPR, to rectification under Article 16 GDPR, to erasure under Article 17 GDPR, to restriction of processing under Article 18 GDPR, to data portability under Article 20 GDPR and the right to object to processing based on legitimate interests under Article 21 GDPR.
You can withdraw consent you have given at any time with effect for the future. The lawfulness of processing carried out until the withdrawal is unaffected.
You can reach us for all requests at [email protected]. We reply within one month.
You also have the right to lodge a complaint with a data protection supervisory authority, with the Spanish AEPD or with the authority where you habitually reside.
8. Data security
We use technical and organisational measures to protect your data appropriately against loss, misuse and unauthorised access.
Encryption: your data is transmitted exclusively TLS-encrypted. Our database provider Supabase encrypts stored data to the AES-256 standard.
Backups: Supabase creates automated daily backups.
Certifications of our processors: Supabase is SOC 2 Type II certified. Stripe is certified as a PCI DSS Level 1 service provider, the highest security standard for processing payment card data.
Access restriction: access to customer data is limited to those employees who need it to perform their tasks.
9. Changes to this privacy policy
We adapt this privacy policy when our services or the legal situation change. The version published on this page applies.