Skip to main content

Data Privacy & GDPR

GoValid is committed to protecting your personal data and complying with data privacy regulations.

GDPR Compliance

GoValid complies with the General Data Protection Regulation (GDPR) for users in the European Economic Area (EEA).

Your Rights Under GDPR

RightDescriptionHow to Exercise
AccessRequest a copy of your dataAccount → Data Export
RectificationCorrect inaccurate dataAccount → Profile Settings
ErasureRequest deletion of your dataAccount → Delete Account
PortabilityReceive data in machine-readable formatAccount → Data Export
RestrictionLimit processing of your dataContact Support
ObjectionObject to processingContact Support

Data We Collect

Account Data

  • Name and email address
  • Profile information
  • Authentication credentials (hashed)
  • 2FA settings

Usage Data

  • QR codes created and scanned
  • Scan analytics (location, device, time)
  • API usage statistics
  • Login history

Payment Data

  • Transaction history
  • Invoice records
  • Payment method tokens (not full card numbers)

Technical Data

  • IP address
  • Browser and device information
  • Cookies and session data

How We Use Your Data

PurposeLegal Basis
Provide GoValid servicesContract performance
Account managementContract performance
QR code generation and verificationContract performance
Analytics and improvementsLegitimate interest
Security and fraud preventionLegitimate interest
Marketing communicationsConsent
Legal complianceLegal obligation

Data Export

You can export all your data at any time:

  1. Go to AccountSecurityData Export
  2. Click Request Export
  3. You will receive an email when the export is ready
  4. Download your data in JSON format

Export Contents

  • Profile information
  • QR codes and metadata
  • Scan history and analytics
  • Transaction history
  • Login history
  • API key usage

Account Deletion

You can request permanent deletion of your account:

  1. Go to AccountSecurityDelete Account
  2. Review what will be deleted
  3. Confirm with your password
  4. Deletion is processed within 30 days

What Gets Deleted

  • Profile and account data
  • QR codes (verification pages become unavailable)
  • Scan history
  • API keys
  • Session data

What May Be Retained

  • Transaction records (legal requirement)
  • Anonymized analytics data
  • Data required for legal compliance

Data Retention

Data TypeRetention Period
Account dataUntil account deletion
QR code dataUntil QR code is deleted
Scan analytics2 years
Transaction records7 years (legal requirement)
Login logs1 year
Deleted accounts30 days (grace period)

Cookies

GoValid uses cookies for:

  • Session management (required)
  • Preferences (optional)
  • Analytics (optional)

You can manage cookie preferences in your browser settings.

Third-Party Data Sharing

GoValid may share data with:

Third PartyPurposeData Shared
StripePayment processingPayment token, amount
PayPalPayment processingPayment token, amount
CDN/security providerCDN and securityIP address, request data
Push notification providerPush notificationsDevice token
Cloud infrastructure providerInfrastructureEncrypted data

We do not sell your personal data to third parties.

Security Measures

  • Encryption: TLS for transit, AES-256 for storage
  • Access Controls: Role-based access to data
  • Auditing: Complete access logging
  • Backups: Encrypted backups with limited retention

Contact

For privacy-related inquiries: