In this document
- 1. Controller and scope
- 2. Website and Smart Page visits
- 3. Browser storage, NFC and QR
- 4. Business accounts, authentication and teams
- 5. Business content and uploads
- 6. Bookings and feedback
- 7. Loyalty programmes and Wallet
- 8. AI-assisted menus and reach
- 9. Subscriptions and hardware
- 10. Support, messages and security
- 11. Device permissions
- 12. Recipients and international transfers
- 13. Retention and deletion
- 14. Your rights
- 15. Automated decisions and updates
- Our providers’ privacy notices
- Contact by email
1. Controller and scope
The controller for NFCeez’s own processing purposes is Farres Nagaa, trading as NFCeez (sole proprietorship, not entered in the commercial register), Wittbräucker Straße 4, 44287 Dortmund, Germany. Contact: privacy@nfceez.de. No data protection officer is appointed; there is no obligation to appoint one (Art. 37 GDPR, § 38 BDSG).
This policy covers the NFCeez Business app, public Smart Pages and these information pages. The respective merchant is generally responsible for its offers, bookings, customer programmes and the processing purposes it determines. Its contact details and supplementary privacy information are available from the merchant. Where we process data on its behalf, we assist it with your rights.
For bookings, loyalty programmes, feedback and Smart Page statistics the respective business is responsible; NFCeez processes this data on its behalf (/avv). NFCeez operates the cross-business guest sign-in by email code under its own responsibility (section 7). There is no joint controllership under Art. 26 GDPR. Membership with one merchant does not give other merchants general access to your data.
2. Website and Smart Page visits
Cloudflare delivers the pages. For transmission, the requested address, your IP address and technically transmitted browser and connection information are processed to provide the pages and prevent abuse (Art. 6(1)(f) GDPR; our interest is a working and secure service). Cloudflare logs connections under its own notices (/recht/dienstleister).
The legal pages contain no analytics, advertising or consent scripts.
Smart Pages count views and link clicks for the respective business: page, time, source (NFC, QR code or direct), for direct visits the platform the visit came from (such as Instagram, Google or WhatsApp), the kind of device (iPhone or iPad, Android or computer), the clicked link and, where applicable, the NFC card identifier. The nfceez.de server derives the platform and the kind of device from what your browser sends with the request anyway: the requested address (including a channel tag such as ?via=instagram that the business may add to its links), the referring page and the browser identifier. Only one word for each is stored; the statistics do not store the referring address, the browser identifier or your IP address. Smart Pages set no cookies for this and neither store nor read information on your device; that is why Smart Pages have no cookie banner. On a Smart Page's menu, NFCeez also counts for the business which dishes guests open and what they search for. Stored are the opened dish or the search word in lower case, whether the search found anything, the time and the random identifier of the page view. Search words that look like an e-mail address, a link or a phone number are not stored. The business only sees a search word once at least three different visits have searched for it. These entries are deleted after 90 days. The business is responsible for these statistics; NFCeez processes them on its behalf (/avv). The legal basis is the business's legitimate interest in knowing the reach of its page (Art. 6(1)(f) GDPR). The data is deleted when the business deletes its location.
3. Browser storage, NFC and QR
Smart Pages store nothing on your device for statistics. Only what you request yourself is stored: the access key of your loyalty card (nfceez.loyalty.<business-id>, valid for 180 days) and your language choice (tapkarte.lang). Both are strictly necessary for the function you requested (§ 25(2) no. 2 TDDDG). Details: /recht/technologien.
An NFC tap or QR scan opens an address. The request may transmit the source NFC, QR or direct link and the card identifier. NFCeez does not gain access to other content on your phone. The QR code of your loyalty card identifies your card and should not be shared publicly.
4. Business accounts, authentication and teams
We process names, email addresses, authentication and session data, business details, roles, preferences and, where relevant, phone numbers and profile pictures. Supabase provides authentication, database and storage. The app stores session tokens in Keychain. Sign in with Apple supplies the identity information Apple provides for authentication, which may include a relay email address.
Purposes are account creation, authentication, permissions, contract performance and account security. Article 6(1)(b) GDPR applies to individuals who are contracting parties; Article 6(1)(f) may apply to customer contacts and employees for contract administration and access security. Where a merchant supplies team-member information, it is the source. Required fields are indicated in the form; an account or permission cannot be established without necessary information.
Data is retained for necessary account use and afterwards only for specifically required settlement, evidence and legal obligations. After the account is deleted, account, profile and team data is deleted; records of purchases and subscriptions are kept for up to ten years (§ 257 HGB, § 147 AO). Account deletion, branch deletion and cancellation of an Apple subscription are separate actions.
App lock: for owners and managers, the NFCeez Business app is locked with Face ID, Touch ID or the iPhone passcode; for other roles the lock is optional. The check is performed solely by your device’s operating system (Apple LocalAuthentication). NFCeez receives no biometric data, only whether the check succeeded; NFCeez therefore does not process biometric data within the meaning of Article 9 GDPR. Whether the lock is set up and after how long it applies is stored only locally on the device. Important actions such as deleting a location or the account, team invitations and role changes are additionally confirmed on the device. The purpose is protecting account, guest and business data (Article 32 GDPR); the legal basis is Article 6(1)(b) and (f) GDPR.
Business verification: owners can have their business verified in the app to show the "Verified business" badge on their Smart Pages. For this, the business name they enter is searched in the German commercial register (Handelsregister) via OpenRegister (see /recht/dienstleister). For the selected business we store the company name, legal form, register court and number, registered address and whether the entry is active. Register data may include names of owners, managing directors or partners; these come from the public commercial register (Article 14 GDPR). The owner also uploads proof, such as a register extract, a trade registration or a letter from the tax office. Proof documents are kept in private storage at Supabase that only our servers and NFCeez's review can access, and are deleted 30 days after the decision. A person at NFCeez always decides on the verification; there is no solely automated decision within the meaning of Article 22 GDPR. We keep the result, the type of proof, the dates and the review steps for the life of the account and three years afterwards to resolve disputes. The purposes are the check, provided for in the contract, that NFCeez is used by businesses, and protecting guests from impersonation. The legal basis is Article 6(1)(b) and (f) GDPR. The Smart Page shows only the badge, never details from the proof. Verification is voluntary; without it the Smart Page remains usable without the badge.
5. Business content and uploads
Merchants supply names, addresses, opening hours, logos, photos, links, menus and other content. Published material is accessible to visitors and search services. Unpublished original files and drafts are processed under the intended access separation. Providers include Supabase and Cloudflare. Purposes are editing, storage and publication on the merchant’s instructions; section 4 applies to our own account administration.
Upload only necessary content for which you have the required rights. File metadata, people in images or screenshots may contain additional personal data. A selected upload function cannot run without its required upload. Original files, drafts and published media have different retention needs; see /recht/loeschung.
6. Bookings and feedback
For bookings, the merchant uses NFCeez to process names, email and/or phone details, requested service, time, possible party size, assigned staff, status and voluntary notes. Feedback may contain a rating, message and optional contact information. Recipients are the merchant, its authorised staff and storage or messaging providers Supabase and, where applicable, Resend.
The purpose is handling your enquiry, booking or feedback. The merchant may rely on Article 6(1)(b) GDPR for pre-contractual or contractual requests and Article 6(1)(f) for other feedback. NFCeez processes within the agreed instructions. Without required form information, a booking may not be identifiable or confirmable. Free text is optional; do not include health data unless necessity and a separate basis have been established.
Bookings and feedback are kept until the business deletes them, at most until 30 days after the location is deleted. You receive confirmations and reminders for your booking by email via Resend; the business sees your details in the NFCeez Business app.
7. Loyalty programmes and Wallet
When you take part, first name, last name, verified email address, memberships, stamps, rewards, confirmed transactions and times are processed. The business sets its programme rules and is responsible for its programme's data; NFCeez processes it on the business's behalf (/avv). The legal basis is the performance of the programme (Art. 6(1)(b) GDPR).
The sign-in by email verification code, with which you open and manage your cards at different businesses, is operated by NFCeez under its own responsibility, so you do not need a separate account for each business (Art. 6(1)(b) GDPR). Programme statuses of different businesses are not merged, and no business sees data from other businesses' programmes. The verification code is sent via Resend.
You only receive news from a business if you have separately agreed to it; the wording and time of your consent are stored. You can withdraw it at any time on your card.
If you save your card to Apple Wallet or Google Wallet, the card content, member and QR identifier and programme status are sent to Apple or Google; device-related identifiers are processed for updates. Apple and Google act under their own notices and their own responsibility.
Cards not used for 24 months are deleted automatically. You can delete your card yourself at any time.
8. AI-assisted menus and reach
When a merchant uses AI, selected menu photos, PDF content or text, target languages and processing instructions are transmitted to OpenAI for extraction, translation or enrichment. Results are stored as editable drafts. Supabase stores files, drafts and technical processing and usage records. Merchants review prices, ingredients, allergens and dietary statements before publication.
Personal-data processing on instructions requires an appropriate basis at the merchant and a suitable processing chain. Our own operational usage and security records require a separate basis. AI processing cannot run without sending the selected content to the AI provider.
The contracting party is OpenAI Ireland Ltd. in Dublin. Requests are sent with the setting that OpenAI does not store them for later retrieval (store: false); OpenAI may keep requests for a limited time for abuse detection under its data processing agreement. Transfers to affiliates outside the EEA are based on the EU standard contractual clauses. No guest data is transferred. Do not submit unnecessary personal or sensitive data. Original menus have a scheduled cleanup mechanism; this does not establish the same retention period for drafts or processing logs.
Reach summary: so that the app can explain in one plain sentence where the visits of a Smart Page come from, NFCeez sends only totals to OpenAI, for example how many visits in this and the previous period came via Instagram, Google or an NFC stand. No information about individual guests is sent for this. Every number in the result is checked against the numbers sent; NFCeez keeps the sentence for up to 7 days and then deletes it. In the same way, the app explains in plain words in the loyalty card statistics how often members come back; only totals of the loyalty card are sent for this, for example members, stamped visits, repeat visits and redeemed rewards, no names, e-mail addresses or details about individual members.
9. Subscriptions and hardware
Apple processes in-app payments under its own responsibility and applicable terms. NFCeez processes transaction and product identifiers, account associations, periods, entitlements and refund or revocation status for contract administration and abuse prevention. The inspected NFCeez data model did not show full payment-card details. Depending on purpose, Article 6(1)(b), (c) or (f) GDPR applies. Reliance on point (c) requires an actual applicable legal obligation.
Confirmed hardware orders may require name, contact, delivery address, product, quantity and order status. Hardware is currently not sold online; order details are processed only when NFCeez provides products to a business directly. Historical Stripe fields do not establish current Stripe processing; Stripe is not listed as a confirmed active recipient.
10. Support, messages and security
Support involves your contact information, message, account association and voluntarily attached files. Issue reports may include app/OS versions and a screenshot you select. Purposes are assistance, troubleshooting and security, based on Article 6(1)(b) or (f) as appropriate. Supabase stores requests; Resend may deliver operational emails. Missing necessary details may prevent handling. Support requests are kept until the account is deleted; the email delivery log is deleted 30 days after sending.
Consent-based advertising requires a separate voluntary choice. A marketing-consent field alone does not establish an active newsletter service.
Business app notifications: if you allow notifications, we store with your account the device token issued by Apple, the environment (test or live version of the app) and the language setting. The title and short text of an account notification, for example about bookings, the loyalty programme, your subscription or a question from NFCeez, are delivered to your device via the Apple Push Notification service; tapping opens the notification in the app. The legal basis is Article 6(1)(b) GDPR. You can turn notifications off at any time in iOS Settings. The device token is deleted when you sign out of the app, delete your account or Apple reports it as invalid; notifications that cannot be delivered within 24 hours are discarded. Push notifications contain no advertising. We do not use SMS marketing or an external crash-reporting system.
11. Device permissions
Camera access may support hardware and loyalty QR scanning and document scanning. Photo selection lets you choose images to use or upload. NFC access supports compatible NFC products. An optional location function may suggest a telephone country code; manual selection is intended. The coordinates are only passed to Apple's map service to determine the country; they are neither sent to NFCeez nor stored.
Face ID or Touch ID is used for the app lock (section 4); permission for notifications is used to deliver account notifications (section 10). Permissions can be changed in system settings. Denial may limit the associated function. An operating-system permission does not automatically replace legally required data-protection consent.
12. Recipients and international transfers
NFCeez uses Supabase (database, stored in Ireland), Cloudflare (page delivery), Resend (email sending), OpenAI (menus only, no guest data) and Hostinger (email mailbox) as service providers. Apple and Google act under their own responsibility for sign-in, purchases and Wallet. Apple delivers Business app notifications via the Apple Push Notification service. Contracting companies, locations and transfer bases: /recht/dienstleister.
Transfers to third countries take place only under the conditions of Articles 44 et seq. GDPR: for Cloudflare and Resend based on the EU-US Data Privacy Framework and the EU standard contractual clauses, for access by Supabase and transfers by OpenAI based on the EU standard contractual clauses. You can request a copy of the safeguards at privacy@nfceez.de.
External links such as WhatsApp, social networks, map or review services are opened by you; processing there follows the respective provider's notices.
13. Retention and deletion
Data is kept only as long as the purpose or a statutory retention obligation requires. In detail: loyalty cards are deleted automatically 24 months after last use; verification codes and expired sign-in sessions after one day; original menu files 30 days after upload; the email delivery log 30 days after sending; notification device tokens when you sign out of the app, with the account, or as soon as Apple reports them invalid; undeliverable notifications after 24 hours. A deleted location can be restored for 30 days; after that its content, bookings, feedback and statistics are permanently deleted.
When an account is deleted, the account and its locations are deleted. Records of purchases and subscriptions are kept as far as commercial and tax law requires (§ 257 HGB, § 147 AO: up to ten years). Details: /recht/loeschung.
14. Your rights
Subject to statutory conditions, you have rights of access, rectification, erasure, restriction and portability. Where processing relies on Article 6(1)(e) or (f), you may object on grounds relating to your particular situation; you may object to direct marketing at any time. Consent may be withdrawn prospectively without affecting earlier lawful processing.
Contact the privacy address above. For processing on behalf of a merchant, you may also contact that merchant directly. Identity checks will be limited to what is necessary. You may complain to a supervisory authority, particularly in your habitual residence, workplace or the place of an alleged infringement. For the Dortmund establishment, the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia is a competent contact: https://www.ldi.nrw.de/kontakt. Your right to complain to other legally competent authorities remains.
15. Automated decisions and updates
The audit does not establish solely automated decisions with legal or similarly significant effects. AI menu drafts are produced for human review. There are no solely automated decisions within the meaning of Art. 22 GDPR and no profiling for advertising.
This policy will be updated for material changes. New purposes or necessary consents are not legitimised merely by changing this text. Version: 5 October 2026, v1 – draft.
Our providers’ privacy notices
Official privacy notices for Supabase, Cloudflare, Resend, OpenAI, Apple, Google and Hostinger are linked at /recht/dienstleister. Which providers receive data depends on the features actually used.
Contact by email
When you contact us by email, Hostinger, our mailbox provider, processes your sender address, message, attachments and technical delivery data. privacy@nfceez.de, legal@nfceez.de and support@nfceez.de are topic-specific aliases delivering to the operator mailbox farres@nfceez.de. Depending on the request, processing serves contract administration (GDPR Article 6(1)(b)), compliance with legal duties including data subject requests (Article 6(1)(c)), or handling other enquiries based on our legitimate interest in communication (Article 6(1)(f)). Messages to NFCeez are kept in the email mailbox at Hostinger (/recht/dienstleister), which only the owner can access. They are deleted once your request has been dealt with; requests about your rights are kept for three years as evidence.