Skip to content
bebber

Last updated: 18 August 2026. This policy describes bebber as it actually works. If you find a statement here that does not match what the service does, tell us — we treat that as a bug.

1. Who is responsible

The controller for the processing described below is:

BLANX effects interactive GmbH
Bismarckstr. 17
50672 Cologne, Germany
Phone: +49 221 3317620
Email: contact@blanx.de

For anything about your data, write to info@bebber.com and put "privacy" in the subject line. We have not appointed a data protection officer, because we are below the thresholds of Art. 37 GDPR and § 38 BDSG.

2. What this policy covers

bebber lets you attach content to a QR code and change that content later without reprinting the code. Three groups of people meet the service, and each one meets a different slice of it:

  • Creators — people who make a bebber, with or without an account.
  • Visitors — people who scan a code and land on a viewer page at /v/….
  • Site visitors — people who read our marketing pages, contact us, or report abuse.

This policy covers all three. It does not cover the content a creator puts inside their own bebber: there we act on the creator's instructions, and section 7 explains what that means for you.

3. When you create a bebber

Creating a bebber without an account requires one thing from you: an email address. We use it to send the edit link, because that link is the only way back into content you made without an account. Your address is stored encrypted, and a keyed hash of it lets us find your codes without ever reading the address itself.

We also store the IP address you created from, encrypted, alongside the code. That record exists for abuse handling and takedown requests — a QR sticker in the physical world can point at anything, and we need a way to answer a complaint.

Alongside that we keep what you actually made: your uploaded files (images, video, audio, PDF), your text, page titles, branding, QR design, and any settings such as password protection or an expiry date. Passwords you set on a bebber are stored as a bcrypt hash, never in readable form.

If you create a bebber without being logged in and without a prior verified address, we send a verification code first. An unverified code and everything attached to it is deleted automatically after 72 hours.

Legal basis

Art. 6 (1) (b) GDPR — providing the service you asked for — for the content, your email address and the edit link. Art. 6 (1) (f) GDPR — our legitimate interest in a service that is not a haven for illegal content — for the stored creator IP and for abuse handling.

4. When someone scans a bebber

Scans are counted, and this is the part most privacy policies get wrong, so here is the exact shape of it. We record the time of the scan, the browser's user-agent string, the language your browser asked for, the language we served, and a coarse location: country, region, city. That is the whole record.

No visitor IP address is stored in scan analytics. The analytics table has no column for one. The IP is used in memory to look up the coarse location and is then dropped.

That location lookup happens entirely on our own server, against a local MaxMind GeoLite2 database file. Your IP address is never sent to a geolocation provider, or to anyone else, for this purpose. The only thing that leaves our server is our own periodic download of the database itself.

To count unique visitors rather than repeat scans, we store a one-way hash derived from the IP address and user-agent for a short deduplication window. Those rows are deleted after one hour.

Viewer pages also send an engagement beacon: how long the page was open, how far it was scrolled, whether a block was played or tapped. The beacon carries no personal data and no IP address, and it goes to our own server only — there are no third-party scripts, pixels, or analytics services on any viewer page. How we count visits to our own marketing pages — never to viewer pages — is section 9.

Creators can see these statistics for their own codes and, on paid tiers, export them. The export contains the same derived fields you have just read about, never a raw IP.

Legal basis

Art. 6 (1) (f) GDPR. Our legitimate interest, and the creator's, is knowing whether a printed code is being scanned at all — measured with the coarsest data that answers the question. There is no cross-site tracking, no advertising profile, and no identifier that follows you to another website.

5. Accounts

An account is optional. It unlocks a dashboard, webhooks, password protection, and the paid tiers. Signing in is passwordless: you enter your email, we send a magic link, and the link expires after 15 minutes and works exactly once.

We store your email address encrypted. The directory your account lives in is named after a keyed hash of the address, so without our encryption key the storage layer says nothing about who you are. Your session cookie contains that opaque account identifier and the time of your last login — never your email address.

If you subscribe, our payment provider handles the payment and sends us back a subscription record: status, tier, billing cadence, period end, and the provider's customer and subscription identifiers. That record is stored encrypted with your account. We never see or store your card details.

Legal basis

Art. 6 (1) (b) GDPR for the account itself and for the subscription record we hold, which is what tells the service which tier you are entitled to. The statutory duty to issue and retain invoices under German commercial and tax law falls on polar.sh as merchant of record, not on us — Art. 6 (1) (c) GDPR applies to them for that record, and their own privacy notice governs it.

6. Emails we send

Every email bebber sends is transactional. Edit links, verification codes, magic links, contact-form notifications, abuse notices, scan notifications — that is the complete list. We run no newsletter and no marketing mail, so there is nothing to unsubscribe from.

Scan notifications are the one recurring message, they are opt-in per code, and every one of them carries a one-click opt-out link. Following that link switches notifications off for that code without asking you to log in.

7. Data your visitors give to a creator

Creators can add a contact form, an email gate, or a form builder to their page. When you fill one in, the data belongs to the creator: they decide why they collect it, so they are the controller and we are their processor. We store it encrypted on their behalf, show it to them in their dashboard, and let them export it.

Creators can also configure a webhook. If they do, submissions from their page are forwarded to a URL they chose, on their infrastructure or a third party's. We sign each delivery, but what happens at the far end is the creator's responsibility, not ours. Ask the creator whose page you filled in about their own privacy notice.

If you want data you submitted to a creator's page erased and the creator does not respond, write to info@bebber.com. We will act on it as processor and pass it to the controller.

Creators who need a data processing agreement under Art. 28 GDPR for their use of forms, lead capture, or the contact block can request one at info@bebber.com.

Legal basis

The creator's, not ours. Typically Art. 6 (1) (a) GDPR — the consent you give by submitting the form.

8. Our own contact and abuse forms

The contact form on this site emails your name, address and message to our mailbox. It is not written to our database; it lives in the mailbox until we clear it out. Abuse reports are stored, because we need a queue to work through: the reporter's email address is encrypted, and, when your email is verified, the reporter's IP is kept as a keyed hash so repeated reports about the same code can be counted without keeping the address.

Legal basis

Art. 6 (1) (f) GDPR for handling your enquiry and for keeping the service clean.

9. How we measure visits to our own pages

On our own marketing pages — the homepage, pricing, the create wizard and similar — we count visits with a self-hosted Matomo instance. It runs on infrastructure we operate, and the numbers never leave it. The measurement is deliberately blunt: no cookie is set, nothing is stored in your browser, your IP address is anonymized before anything is written, and the events we record are a closed list — a page was viewed, a code was created, the contact form was sent — with no identifier that could name you in any of them. When a subscription is completed, our server additionally records an anonymous order: the plan and its price, with no identifier that could name the buyer.

Because nothing is stored on your device and no personal profile is built, this measurement needs no consent banner: § 25 TDDDG is not triggered, and the processing rests on Art. 6 (1) (f) GDPR — our legitimate interest in knowing whether our own pages work. You can object at any time (Art. 21), and if your browser sends the Do Not Track signal, the instance discards the request entirely.

Pages that show creator content — everything under /v/, and the editor — are excluded from this measurement altogether. What happens when someone scans a bebber is section 4, and nothing in this section applies to it.

10. Cookies

bebber sets no advertising, analytics, or tracking cookies. Every cookie below is strictly necessary to deliver a function you requested, which is why you see no consent banner: § 25 (2) TTDSG covers exactly this case.

bebber_session
Your signed login session. HTTP-only, 30 days, set only after you log in.
bebber_logged_in
A flag holding the value 1, readable by the page so the header can show "Dashboard" instead of "Log in". Contains nothing else.
bebber_access_{code}
Proof that you entered the correct password for one password-protected bebber, so you are not asked again on every block.
bebber_lead_{code}
Proof that you passed one creator's email gate, for that code only.
bebber_lang_{code}
The language you picked in the switcher on a multilingual bebber. Scoped to that code's page, one year.
bebber_tz
Your browser's time zone name, read automatically when you open your own dashboard or edit page. Without it, the statistics you came to that page for would be drawn in UTC and "today" would end at the wrong hour — the cookie is what makes the requested view correct, so it is necessary to deliver that function rather than an analysis of you. It is set only on those creator-facing pages, never on a viewer page.

Deleting these cookies logs you out and forgets your language and gate choices. Nothing else breaks.

11. Who else receives data

We keep the list of recipients short on purpose. Each processes data only on our instructions and only for the purpose named beside it.

OVH — hosting
Our servers, uploads, and databases are hosted with OVH in Frankfurt, Germany. Everything described in this policy lives there, inside the European Union.
MailPace — email delivery
Sends our transactional email. It receives the recipient address and the message content. If MailPace is unreachable we fall back to a configured SMTP relay.
polar.sh — payments
Acts as merchant of record for subscriptions. Your payment details go to them, not to us; we receive only the subscription status described in section 5.
Cloudflare — content delivery, when enabled
Where the CDN is switched on, requests for uploaded media pass through Cloudflare and their edge sees the requesting IP address as part of delivering the file.
Webhook endpoints chosen by a creator
See section 7. These are configured by creators, not by us.

We sell nothing, and we share nothing for advertising. Beyond the list above, we disclose data only where a law or a binding order requires it.

12. How long we keep things

Content you create stays until you delete it. There is no automatic expiry — a sticker on a machine should still work in three years — unless you set an expiry date yourself. Everything else runs on a timer:

Scan and engagement records
30 days on the free tier, 180 days on Pro, 730 days on Business. Older rows are deleted automatically.
Leads, contact submissions, and form responses collected on a creator's page
The same windows as scan data: 30 days free, 180 days Pro, 730 days Business, measured from submission. Pages owned by a creator without an account use the free-tier window.
Unique-visitor deduplication hashes
One hour.
Rate-limiting records
Two hours. These sit in a separate, deliberately non-backed-up database.
Magic login links
15 minutes, or immediately once used.
Unverified new codes
72 hours, then files and records are deleted.
Abuse reports
365 days after the report is resolved; open reports are closed out after two years.
Administrative audit log
365 days. It records our own admin actions — deletions, moderation, searches — not your browsing.
Server logs
Our web server keeps standard access logs, which include IP addresses, for troubleshooting and attack investigation. They are rotated on a short cycle and are not merged with anything else.

13. How your data is protected

Personal data is encrypted at rest with AES-256-GCM: creator email addresses and IPs, account emails, billing records, webhook secrets, lead emails, contact submissions, form responses, and reporter emails. Where we need to look something up by email, we use a keyed HMAC index rather than storing anything readable.

Transport is TLS-only. API keys are stored as hashes, admin access is restricted to a named list of verified addresses and fails closed, uploads are checked against an extension allowlist, and outbound webhook requests are filtered to stop them being pointed at our own internal network. Backups are encrypted before they are written and synced to a separate location, and their freshness is monitored automatically.

14. Your rights

Under Art. 15 to 21 GDPR you can ask for access, correction, deletion, restriction, portability, and you can object to processing based on legitimate interest. Three of those are buttons rather than emails:

  • Export (Art. 20). Account holders can download a JSON file of their account data — email address, creation date, settings, tier, the list of their codes, webhook configuration, and subscription summary — from Account → Settings. Secrets such as edit tokens and webhook signing keys are deliberately excluded.
  • Deletion (Art. 17). Deleting your account offers two paths and defaults to the thorough one: delete everything, which erases your codes, their media, their analytics, and every record tied to your account; or detach, which leaves the codes working without an owner for cases where printed stickers are already in the field. The dialog states the consequences of each before you confirm.
  • Notification opt-out. Every scan notification carries a one-click opt-out link.

Made a bebber without an account? Use the edit link to change or delete it, or ask us at info@bebber.com to erase everything tied to your address — we can find it through the keyed email index.

We answer requests within one month, as Art. 12 (3) GDPR requires. Identifying you may require a reply from the address the data is filed under, which is the only proof of ownership our design allows us to check.

15. No profiling, no AI training

We do not profile you, and no automated decision produces a legal or similarly significant effect on you within the meaning of Art. 22 GDPR. Your content, your uploads, and the data collected through your pages are never used to train machine-learning models, and never sold or handed to anyone for that purpose. bebber content is not publicly indexed, and there is no public search, catalogue, or listing of it.

16. Complaints

If you think we are handling your data wrongly, tell us first — we would rather fix it than argue about it. You also have the right to complain to a supervisory authority at any time. Ours is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestr. 2–4, 40213 Düsseldorf, Germany
www.ldi.nrw.de

You may also complain to the authority where you live or work.

17. Changes to this policy

We update this page when the product changes, and the date at the top tells you when that last happened. Material changes affecting account holders are announced by email before they take effect.