Privacy Policy

Effective from 21 August 2026Individual entrepreneur Melai Daiana Dmytrivna

In short

  • We store no raw IP addresses and no user agents of your visitors — none at all.
  • We set only the cookies without which signing in is impossible. No analytics or advertising cookies.
  • There are no third-party trackers on our pages — no Google Analytics, no Meta Pixel, nothing.
  • Analytics is kept for 18 months and then deleted automatically.
  • We do not sell personal data and never have.

This is a plain-language summary. The full text below is what legally applies.

1.Who we are and what we are responsible for

The Abect service (abect.com) is provided by individual entrepreneur Melai Daiana Dmytrivna, Ukraine. Referred to below as «we».

For your account data we are the controller: we decide why and how it is processed.

For data left by visitors to YOUR sites — requests, orders, analytics — YOU are the controller and we act as a processor, handling it only on your instructions. In practice this means such a visitor’s requests are answered by you, and we are obliged to help you do that.

2.Your account data

So that you can sign in and use the service, we store:

  • Your name and email address.
  • Your password — only as an irreversible hash (bcrypt). Neither we nor anyone who gains access to the database can read it.
  • Your Google identifier — if you sign in with Google. In that case there is no password at all.
  • Your Google profile picture — as a link; we do not store a copy.
  • The date of your last sign-in and the device type of active sessions.

A SUB-ACCOUNT password is the exception, and we say so plainly: it is stored with reversible encryption, which means we can technically display it. That is deliberate — a sub-account has no email of its own, and the account owner is the only way to restore its access. If that does not suit you, do not create sub-accounts.

3.Data about visitors to your sites

When someone scans your QR code or opens your page, we record the event for statistics. This is the complete list of what goes into that record:

We recordWe do NOT record
Country and cityThe raw IP address
Device type, browser, OSThe full user agent
Date and time of the eventName, email, phone
Page address or QR codePersistent identifiers
Referrer hostThe full referrer URL

4.How we count unique visitors without tracking

Telling one visitor from ten requires some identifier. Instead of a cookie we use a daily hash:

SHA-256(secret daily salt + resource owner + IP + user agent)

The salt is generated once a day, lives only in the server’s memory and is wiped on rotation. It is not in the database, not in backups, not in logs. The consequence: not even we can recover an IP address from yesterday’s hash.

The owner identifier in the same formula means that the same person scanning codes of two different businesses gets DIFFERENT hashes. Correlating their movement between our customers is impossible even with full access to the database.

The formula follows Plausible Analytics — the de facto standard for cookieless analytics.

5.Requests and orders

If your site has a form, we store what the visitor filled in: name, phone, email, message, and for orders the cart contents and total.

This data belongs to you. We use it for nothing except showing it to you in your dashboard: we do not analyse it, do not enrich it, do not pass it to anyone and do not send campaigns from it.

Tell your own visitors about the collection yourself — you place the form, and you are the controller of that data. If your site targets the EU, you need your own privacy policy on it.

6.How long we keep things

DataRetention
QR scan analytics18 months, then deleted automatically
Page view analytics18 months, then deleted automatically
Requests and orders18 months from creation
Account dataWhile the account exists
Payment historyWhile the account exists — required for accounting
Technical server logs14 days
Sessions (refresh tokens)30 days, or until you sign out

Analytics deletion is performed by the database itself on a schedule, not by our team: the mechanism does not depend on anyone remembering it.

7.Cookies

We set exactly three cookies, and all of them are strictly necessary:

  • auth_token — keeps you signed in, lives 30 minutes.
  • refresh_token — renews your session without signing in again, lives 30 days and is sent only to the sign-in endpoints.
  • oauth_state — protects Google sign-in against request forgery, lives a few minutes.

We set no analytics, advertising or other optional cookies. That is why there is no cookie consent banner on this site: strictly necessary cookies do not require consent. The cart on customer sites is kept in the browser’s local storage and is not sent to our server until the visitor places an order.

8.Who we share data with

We do not sell personal data, do not trade it and do not pass it to advertising networks. Only those without whom the service cannot run receive any of it:

  • Brevo — email delivery (email confirmation, password reset, payment notices). Receives your address and the text of the message.
  • Monobank — payment processing when you pay for a plan. Card details never pass through us: we neither see nor store them.
  • Hetzner — the server the service runs on and where the database is stored (Germany, EU).

We may disclose data at the demand of a court or another authorised body — and only within the scope of that demand. Separately: we use Google Search Console to see how our own pages perform in search. It is verified by an HTML file or a DNS record, runs no code in your browser and sets no cookies — Google shows us data from its own search index, not from your visit.

9.Your rights

If you are in the EU, GDPR rights apply to you. Regardless of country, we grant them to all users equally:

  • Find out what data of yours we hold and receive a copy of it.
  • Correct inaccurate data.
  • Delete your account and all related data.
  • Receive your data in a machine-readable form to move to another service.
  • Object to processing or restrict it.
  • Lodge a complaint with the supervisory authority in your country.

There are no «delete account» and «export data» buttons in the dashboard yet — we fulfil these requests manually. Write to support@abect.com and we will respond within 30 days, as GDPR requires. We say this plainly, because a silent «contact support» in place of a missing button is worse.

10.For California residents (CCPA/CPRA)

The categories of data we collect are listed in sections 2–5. The business purpose is providing the service itself.

  • We do NOT sell personal information and have not done so in the past 12 months.
  • We do NOT share personal information for cross-context behavioural advertising.
  • We do not collect sensitive personal information.
  • We do not knowingly collect data from anyone under 16.

Because we sell nothing, there is no «Do Not Sell or Share My Personal Information» link on this site — there is nothing to sell. Access and deletion rights work exactly as described in section 8: by email to support@abect.com. We will not discriminate against you for exercising these rights.

11.Where data is stored

The server and database are located in Germany (Hetzner), that is, within the EU. We are a Ukrainian business, so technical access to the data happens from Ukraine.

Ukraine has been recognised by the European Commission as providing an adequate level of data protection, so no separate transfer mechanism is required for this.

The geolocation database is stored on our own server: to determine a visitor’s country we contact no one. Previously the request went to external services together with the IP address — we stopped doing that.

12.Security

  • Connections are encrypted (HTTPS).
  • Passwords are stored as irreversible hashes.
  • API keys are stored as hashes — shown once at creation and never again.
  • Session cookies are inaccessible to scripts (httpOnly).
  • Technical logs are cleared after 14 days.

Absolute security does not exist, and promising it would be a lie. If you have found a vulnerability, write to support@abect.com — we will respond.

13.Changes to this policy

If we change this document materially, we will notify you by email to your account address at least 14 days before it takes effect.

The effective date of the current version is shown at the top of this page.

Questions about your data

Write to us — requests are answered by us personally, there is no separate department here.

Email
support@abect.com
Phone
+380 98 027 58 19
Registered as
Individual entrepreneur Melai Daiana Dmytrivna
Response time
Up to 30 days (GDPR art. 12)