Privacy Policy
Effective date: April 12, 2026 — Last updated: July 3, 2026
This Privacy Policy explains how mnrvAR, operated by Imaginary Polygons S. de R.L. (“we”, “us”, or “our”), collects, uses, and protects information when you use our Service. We take your privacy seriously and collect only what is necessary to operate the platform.
1. Information We Collect
Account information. When you register, we collect your email address via our authentication system. We do not collect your name, phone number, or physical address unless you provide it in direct communications.
Billing information. Payments are processed by Paddle. We never see or store your credit card details. Paddle shares with us only the subscription status, plan, and period end date required to enforce your plan limits.
AR scan events. When an end-user scans one of your published experiences, we receive a scan event that may include:
- A session identifier (random, not tied to any user account)
- User-agent string (browser/device type)
- IP address — used transiently for rate limiting only, not stored persistently
- Location, if the device sends GPS coordinates — processed server-side at ingest time to: (a) identify which of the experience owner’s custom geo-fences the scan fell inside (stored as fence identifiers only); (b) identify the country, stored as a two-letter country code; and (c) derive a regional position rounded to a 1° grid (~100 km resolution) for heatmap display. Raw coordinates are never written to persistent storage.
Usage data. We collect aggregate counts of scans and sessions to power the analytics dashboard. This data is not linked to any individual end-user identity.
Restaurant orders. If an experience owner uses our restaurant menu feature and an end-user places an order, we store the table number and the items selected so the order can be relayed to the business. This is processed on behalf of, and under the control of, the experience owner.
Loyalty program data. If an experience owner runs a loyalty program and an end-user chooses to participate by entering their phone number at checkout, we store that phone number together with accrued points and visit counts. We collect this only when the end-user voluntarily provides it. This information is held on behalf of the experience owner, who is the data controller for it; we act solely as a processor. We do not use loyalty phone numbers for our own marketing and never sell them.
2. How We Use Your Information
- To create and maintain your account
- To enforce plan limits and process billing
- To provide scan analytics to you as the experience owner
- To operate restaurant ordering and loyalty programs on behalf of experience owners — relaying orders to the business and tracking loyalty points against the phone number an end-user provides
- To rate-limit abuse on public endpoints
- To send transactional emails (account confirmation, password reset) via SendGrid
- To respond to your support requests
We do not sell your data. We do not use it for advertising.
3. Data Processors (Sub-processors)
We rely on the following third-party services to operate mnrvAR:
- Cloudflare (US/global) — asset storage (R2), CDN delivery, and DDoS protection
- SendGrid (US) — transactional email delivery (account confirmation, password reset)
- Paddle (UK) — payment processing and subscription management
- Redis — in-memory queue for scan event processing; data is ephemeral and not persisted beyond a few seconds
Each processor is bound by their own privacy and data protection agreements.
4. Cookies and Local Storage
We use session cookies for authentication only. We do not use advertising cookies or third-party tracking pixels. Your browser’s local storage may hold your auth session token.
5. Data Retention
Account data is retained until you delete your account. Scan analytics are retained indefinitely in aggregate form; no raw personal data is retained as part of analytics. IP addresses used for rate limiting are held in memory for 60 seconds and then discarded.
Restaurant order and loyalty records, including any end-user phone numbers, are retained on behalf of the experience owner until the owner deletes the relevant loyalty program, member record, or account, or until deletion is otherwise requested. End-users who joined a loyalty program may request removal of their data — see “Your Rights” below.
6. Your Rights
Depending on your location, you may have the right to access, correct, or delete your personal data. EU and UK residents have additional rights under GDPR and UK GDPR, including the right to data portability and the right to object to processing.
To exercise any of these rights, email [email protected]. We will respond within 30 days.
If your personal data — such as a phone number — was collected through a restaurant ordering or loyalty program run by a business using mnrvAR, that business is the data controller. Please direct access or deletion requests to them; we will assist them in fulfilling your request as their processor.
7. Data Security
We use industry-standard measures including TLS encryption in transit, role-based access controls, and row-level security on our database. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.
8. Children
The Service is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it.
9. International Transfers
Your data may be processed in the United States and other countries where our sub-processors operate. By using the Service, you consent to this transfer. For EU users, transfers occur under Standard Contractual Clauses or equivalent mechanisms as provided by our sub-processors.
10. Changes to This Policy
We may update this policy. We will notify you by email or in-app notice before material changes take effect. Continued use of the Service constitutes acceptance of the updated policy.
11. Contact
For privacy questions or to exercise your rights, contact us at [email protected].
Note: mnrvAR is operated as a sole proprietorship by Imaginary Polygons S. de R.L., Honduras. We are not currently registered as a data controller under GDPR but take our obligations to EU users seriously and will comply with applicable requirements. We recommend seeking independent legal advice if you have compliance concerns.