Privacy Policy

Responsible for data processing:

Robert Clemens
Monvou
Moltkestr. 13
50859 Köln

Email: info@monvou.com

General use of the Monvou platform

When you access, scan, create, edit or view a Monvou card, we process the data technically required for the respective function. This includes, in particular, the QR/card code, the selected card type, creation, editing and access timestamps, and the content entered by users. Processing is carried out to provide the requested digital card or digital service, prevent abuse and ensure technical operation. The legal bases are in particular Art. 6(1)(b) GDPR where processing is required to provide the Monvou function, and Art. 6(1)(f) GDPR for security, error analysis and stability.

Server logs

Each time our pages are accessed, technically necessary information may be processed in server logs. This includes in particular IP address, date and time of access, requested URL, amount of data transferred, status codes, referrer and user agent. These data are not used for advertising purposes. Processing serves website delivery, error analysis, IT security and protection against abuse. The legal basis is Art. 6(1)(f) GDPR. Server logs are deleted regularly, usually no later than after 90 days, unless longer storage is required to investigate security incidents.

Digital cards, media and QR codes

For classic digital cards, video cards, link cards, AI cards and similar Monvou experiences, we store depending on use the QR code, card type, texts, layout and design selection, effects, uploaded images, audio or video files, file paths, preview data, optional PIN settings, timestamps and technical counters such as design or view counters. These data are required so the QR code can continue to display the desired digital experience. Content remains stored until the card is reset, deleted or cleaned up after longer inactivity, unless legal retention obligations require otherwise.

Group card / shared entries

For the group card, we process the associated QR code, a group code, optional recipient name, participant entries, display names, message texts, optionally uploaded images or image paths and creation timestamps. In addition, a technically necessary device cookie is set to limit entries to one per device. To allow later editing or deletion of a participant’s own entry, a local editing token is stored in that person’s browser (localStorage), consisting of group reference, entry ID and token. The token is used only to recognize the participant’s own entry; it is not analytics or marketing tracking. The data are used to provide the group card, display entries and enable editing/deletion functions.

Gift function / gift card

For the gift function, depending on use, we process the QR code, recipient name, intro text, gift type (text, code or file), gift title, gift text, gift code, description, file path, original file name, MIME type, file size, optional password hint, a password hash and creation, editing and opening timestamps. A gift password is not stored in plain text but as a hash. Unlock attempts may be logged to limit abuse. For this, we store the code, whether the attempt was successful and the time. The unlock status itself is stored as technically necessary data in the browser session.

PIN protection, CSRF protection and security functions

For protected cards and editing areas we use technically necessary session data. This includes in particular CSRF tokens to protect against unwanted form submissions, PIN unlock status, temporary locks after failed attempts, nonces for paid actions and session markers for editing rights. These data are generally used only for the respective session or security purpose.

Optional AI functions

If you actively use AI functions, the prompts you enter, selected parameters and generated text, images or voice files may be technically processed and transmitted to the respective AI provider for generation. OpenAI API functions are currently used for this purpose. Processing takes place only when you deliberately trigger such an AI function. Please avoid entering sensitive personal data in prompts. Generated results may be stored temporarily as a preview and permanently assigned to your card after saving. The legal basis is Art. 6(1)(b) GDPR for the requested generation and Art. 6(1)(f) GDPR for security, error analysis and abuse prevention.

Credit purchases via monvou.com & webhook

You can purchase credits through our shop at vision.monvou.com. The shop privacy policy applies to the purchase. After a successful purchase, the shop sends technically necessary information to our servers via webhook so that your balance can be assigned to the correct code. We process, in particular, a pseudonymous code ID (monvou_code), product/quantity details, order/transaction ID and timestamps. Payment data such as card or bank details and personal billing data are not transmitted to us.

Purpose: Crediting and managing your credits, support, abuse prevention
Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR
Recipients: Our hosting provider (see “Server location & hosting”). Shop and Monvou app are operated by the same Monvou provider; data is transferred between the technically separate shop and app systems.
Storage period: Technical logs up to 90 days; booking/transaction records in accordance with commercial and tax retention obligations for up to 10 years.
Third-country transfers: Do not occur or only on the basis of the safeguards under Art. 46 GDPR where applicable.

Cookies, session and local browser storage

Monvou currently uses only technically necessary cookies and local storage. This includes in particular the PHP session cookie for language, CSRF protection, PIN/gift unlocks and editing rights, the group device cookie mv_grp_done_... to limit entries to one per device, localStorage entries such as monvou_group_entry_... for editing a participant’s own group entry and individual sessionStorage entries for stable browser navigation. These storage mechanisms are necessary to provide explicitly requested functions. No analytics, marketing or retargeting cookies are used.

Reusability and access via saved links

Monvou cards and QR codes are generally reusable. If a card is passed on, gifted or redesigned, persons who saved an earlier link may in some cases continue to access content until the card has been reset, deleted or reconfigured. Confidential content should therefore be protected with a suitable PIN or password or reset before the card is passed on.

Storage period and deletion options

Server location & hosting

This app is operated with a hosting provider in Germany. The hosting provider processes technical access data and stored content only in connection with providing, maintaining and securing the platform. Where required, a data processing agreement under Art. 28 GDPR is used with the hosting provider.

Recipients and service providers

Recipients of personal data may be technical service providers required for hosting, operation, security, payment/credit processing or optional AI functions. Data are not shared for advertising purposes. Where service providers outside the EU/EEA are used, this is done only on the basis of appropriate safeguards, in particular Standard Contractual Clauses, where required.

Rights of data subjects

Subject to the GDPR, you have the right of access, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interests. Where processing is based on consent, you may withdraw that consent with effect for the future. You also have the right to lodge a complaint with a data protection supervisory authority.

Users are generally responsible for the cards, group entries, gift content, uploaded files and messages they create or submit. Monvou provides the technical platform and removes unlawful or abusive content where we become aware of it.