Privacy Policy

Version 1.1 β€” Effective date: June 8, 2026

Applicable law: Swiss nFADP/nDSG (in force since 1 September 2023); EU GDPR where applicable.

These terms are currently under legal review.

1. Identity of the Data Controller

Ahmed Badiah
Individual operator β€” MiriSmartGuard
Switzerland

Contact: privacy@mirismartguard.com

2. Scope

This Privacy Policy applies to all personal data processed through mirismartguard.com, including data submitted by registered users ("Owners") and anonymous visitors ("Visitors").

3. Data We Collect and How

3.1 β€” Registered Users (Owners)

DataFormat storedPurpose
Full namePlain textProfile display
Email addressPlain textAuthentication, notifications
Phone numberAES-256-CBC encrypted (random IV)WhatsApp/Telegram contact buttons
Phone hashHMAC-SHA256Deduplication, fraud prevention
Telegram usernamePlain textPublic Telegram button
Telegram Chat IDPlain textNotification delivery
Profile photo URLURL referenceProfile display
Status and bioPlain textProfile display
Account planPlain textFeature access control
Notification preferencesBoolean flagsNotification delivery
Delivery address (optional)Plain textPhysical product shipment

3.2 β€” Visitors (non-registered)

DataFormat storedPurpose
Name (if voluntarily submitted)Plain textScan notification to Owner
IP addressHMAC-SHA256 hash only β€” never plain textFraud prevention, rate limiting

3.3 β€” Waitlist Subscribers (pre-launch)

DataPurposeRetentionLegal basis
Waitlist email (optional)Launch announcement, product updatesUntil launch + 6 months, or until unsubscribeConsent (nFADP Art. 6.6 / GDPR Art. 6(1)(a))

Waitlist subscribers may unsubscribe at any time by contacting contact@mirismartguard.com. Email addresses are stored in our Supabase database with row-level security and are never shared with third parties.

3.4 β€” Scan Logs (every QR code scan)

DataFormatRetention
TimestampPlain datetime12 months
IP addressHash only12 months
Country code (ISO 3166-1)2-letter code12 months
Device typeCategory (mobile/tablet/desktop/bot)12 months
User-agent stringTruncated to 500 characters12 months
Whether scan was blockedBoolean12 months

4. What We Do NOT Collect

  • We do not collect or store IP addresses in plain text β€” ever.
  • We do not sell, rent, or trade personal data to any unauthorized third party. Authorised delivery partners may confirm a delivery scan via our API β€” they receive only the recipient's name and QR serial, never phone numbers or addresses.
  • We do not use data for advertising or profiling.
  • We do not use third-party analytics tools (no Google Analytics, no Meta Pixel).

5. Legal Basis for Processing

Processing activityLegal basis
Account management and profile displayContract performance (Art. 6(1)(b) GDPR / Art. 31 nDSG)
Scan logging and notification deliveryContract performance
Rate limiting and fraud preventionLegitimate interests (Art. 6(1)(f) GDPR / Art. 31 nDSG)
Visitor contact form submissionConsent (freely given, specific, informed)
Payment processingContract performance + legal obligation
Report handling and abuse preventionLegitimate interests
Waitlist email collectionConsent (nFADP Art. 6.6 / GDPR Art. 6(1)(a))

6. Data Security Measures

  • AES-256-CBC with a random IV per encryption operation for all phone numbers
  • HMAC-SHA256 for IP address and phone hashing β€” computationally irreversible
  • Row-Level Security (RLS) enforced at the database level
  • Service role access restricted to server-side API routes only
  • Signed session cookies (httpOnly, Secure) β€” cannot be read by JavaScript
  • All data in transit encrypted via HTTPS/TLS

7. Data Sharing and Sub-processors

We do not sell data. Data may be shared with the following sub-processors solely to operate the Service:

Sub-processorRegionPurposeSafeguard
SupabaseEU (Germany)Database, authenticationSCCs
VercelEU (Frankfurt)Hosting, edge runtimeSCCs
StripeUS/EUPayment processing (cards)SCCs + DPA
ResendUSTransactional emailSCCs
TelegramDubai/USPush notificationsUser's own account

8. Data Retention

CategoryRetention period
Owner account dataUntil account deletion + 30-day grace period
Scan logs12 months from scan date
IP rate-limiting records30 days after block expires
Payment records10 years (Swiss accounting law β€” Art. 958f CO)
Abuse reportsUntil resolved + 6 months
Visitor data (name)12 months from last scan, then anonymised automatically
Transfer tokens48 hours (auto-expired)
Waitlist emailUntil launch + 6 months, or until unsubscribe request

9. Your Rights

Under nDSG (Art. 25–27) and GDPR (Art. 15–22), you have the following rights:

RightDescription
AccessRequest a copy of all personal data held about you
RectificationCorrect inaccurate or incomplete data
ErasureRequest deletion of your data (β€œright to be forgotten”)
RestrictionRequest temporary suspension of processing
PortabilityReceive your data in a machine-readable format
ObjectionObject to processing based on legitimate interests
Withdrawal of consentWithdraw any previously given consent at any time

To exercise any of these rights: privacy@mirismartguard.com

Requests will be responded to within 30 days as required by Art. 25 nDSG.

10. Right to Lodge a Complaint

If you believe your data protection rights have been violated, you may lodge a complaint with:

Federal Data Protection and Information Commissioner (FDPIC / PFPDT)
Feldeggweg 1, CH-3003 Bern
www.edoeb.admin.ch

EU residents may also contact their local Data Protection Authority.

11. Automated Decision-Making

The Service uses automated rate-limiting logic to detect and block abusive scanning behavior based solely on hashed IP activity patterns. This does not involve profiling of personal characteristics. Blocked users may contact the Operator to dispute a block.

12. Children's Data

The Service is not directed at persons under 16 years of age. We do not knowingly collect personal data from minors. If we become aware that a minor has submitted personal data, it will be deleted immediately.

13. Cookies

The Service uses a single signed session cookie (httpOnly, Secure, SameSite=Strict) strictly necessary for visitor identification. No advertising, tracking, or analytics cookies are used.

14. Changes to This Policy

This Privacy Policy may be updated periodically. The "Effective date" at the top reflects the most recent revision. Registered users will be notified of material changes via email. Continued use of the Service constitutes acceptance.

15. Contact

Ahmed Badiah
Individual operator β€” MiriSmartGuard, Switzerland

privacy@mirismartguard.com