Privacy Policy

This document describes what personal data Papu processes, on what basis, and what rights you have under Regulation (EU) 2016/679 (GDPR). Effective 2026-07-23, version 1.0. The Czech version prevails in case of conflict.

Last updated: 2026-07-23

1. Data controller

The controller is Appsibly (Daniel Vazač), operator of the service at https://papu.work.

Data protection contact: daniel.vazac@email.cz. No data protection officer has been appointed, as the conditions of Art. 37 GDPR are not met.

2. What we process

CategoryDataWhen it is created
Account datausername, e-mail, password hash (argon2id), sign-up date, e-mail confirmation flag and date, admin flag, date and version of accepted termson registration
One-time tokensa hash of the e-mail confirmation link (valid 24 hours) or password reset link (valid 1 hour) and the address it was issued foron registration, e-mail change or password reset
Bill split dataparticipant names or nicknames, item names, amounts, discount, variable symbols, datewhen you create an order
Group order datathe owner's bank account (IBAN), delivery coordinates, chosen restaurant, participant names, their items and totals, paid status, delivery tracking linkwhen you create or join a group
Anonymous device ida random UUID stored in your browser and sent with your orderswhen using the service signed out
Slack connectionworkspace id and name, channel id and name, access token, optionally mapped Slack user idsonly if you enable the connection
Technical and operational dataIP address (in memory, for rate limiting), server logs of errors and sign-ins, cookie consent record (categories, time, version)automatically while using the service

Papu never processes card details or bank credentials and never moves money. A bank account number is stored only so the payment QR code can be generated.

If you enter someone else's name into an order, you are the one supplying their data. Keep it minimal (a first name or nickname) and do not add anything a split does not need.

3. Purposes and legal bases

PurposeLegal basis
Running the service - accounts, storing orders and groups, generating QR codesperformance of a contract, Art. 6(1)(b) GDPR
Signed-out use - keeping your orders under an anonymous identifierlegitimate interest in a working service, Art. 6(1)(f)
Security - rate limiting, abuse prevention, operational logslegitimate interest in securing the service, Art. 6(1)(f)
Transactional e-mail - address confirmation, password reset, account change noticesperformance of a contract and legitimate interest in account security, Art. 6(1)(b) and (f)
Posting messages to Slackperformance of a contract (a feature you enable), Art. 6(1)(b)
Anonymous traffic statisticsyour consent, Art. 6(1)(a) - withdrawable at any time
Legal obligations and defence of legal claimsArt. 6(1)(c) and (f)

4. Who receives the data

We do not sell data. Processors and recipients involved in running the service:

  • OVH SAS - server and database hosting, EU data centre.
  • Resend, Inc. - sending transactional e-mail (address confirmation, password reset, account change notices). Your e-mail address and username are passed on.
  • Cloudflare, Inc. - anonymous traffic statistics (Cloudflare Web Analytics, cookieless) and traffic protection. Loaded only after your consent. Transfers to the US are covered by standard contractual clauses and the EU-US Data Privacy Framework.
  • Slack Technologies (Salesforce) - only if you enable the Slack connection; participant names and amounts are posted to the channel you choose.
  • Bolt Food and Foodora - menu and restaurant lookups by delivery coordinates. Your name, e-mail and account id are never sent to them.
  • OpenStreetMap Foundation (Nominatim) - address lookup by text or coordinates.

Data may also be disclosed to public authorities where the law requires it.

5. How long we keep it

  • Account data and the orders and groups tied to it: for as long as the account exists. Deleted immediately when the account is deleted.
  • Orders created without an account: at most 90 days from creation, after which the personal content (participant names, items, amounts) is erased automatically.
  • One-time tokens: deleted automatically once used or expired (24 hours, or 1 hour respectively).
  • Cookie consent: 12 months, or until withdrawn.
  • Server logs: at most 90 days.
  • Data in backups: at most 30 days after deletion from the live database.

6. Your rights

Under the GDPR you have the right of access, rectification, erasure, restriction of processing, data portability, the right to object to processing based on legitimate interest, and the right to withdraw consent at any time (withdrawal does not affect processing done before it).

  • Access and portability: download a JSON export of your data in the Account section.
  • Erasure: delete your account, together with your orders and groups, in the Account section.
  • Rectification: change your e-mail and password in the Account section, anything else on request.
  • Cookie consent: withdraw it with the Cookie settings button on the Cookies page or in your account settings.
  • Anything else: write to daniel.vazac@email.cz. We reply within one month at the latest.

You may also lodge a complaint with the supervisory authority: Úřad pro ochranu osobních údajů (Czech Data Protection Authority), Pplk. Sochora 27, 170 00 Praha 7, www.uoou.gov.cz.

7. Cookies and browser storage

Papu uses necessary cookies for sign-in and for storing your consent, and keeps some data directly in your browser. The full list is in the Cookie Policy.

8. Security

Passwords are stored only as argon2id hashes. All traffic runs over HTTPS. Only the operator can reach the database, session cookies are HttpOnly and Secure, every sensitive action is authorised server-side, and request rates are limited.

No measure is absolute. If a breach were to put your rights at risk, you would be informed in line with Art. 34 GDPR.

9. Children

The service is not intended for anyone under 16 and their data is not knowingly processed. If you believe a child has given us data, write to us and it will be deleted.

10. Changes

This policy may be updated. A new version is published on this page with its effective date and version number; registered users are notified of material changes.