Privacy Policy
This document describes what personal data Papu processes, on what basis, and what rights you have under Regulation (EU) 2016/679 (GDPR). Effective 2026-07-23, version 1.0. The Czech version prevails in case of conflict.
Last updated: 2026-07-23
1. Data controller
The controller is Appsibly (Daniel Vazač), operator of the service at https://papu.work.
Data protection contact: daniel.vazac@email.cz. No data protection officer has been appointed, as the conditions of Art. 37 GDPR are not met.
2. What we process
| Category | Data | When it is created |
|---|---|---|
| Account data | username, e-mail, password hash (argon2id), sign-up date, e-mail confirmation flag and date, admin flag, date and version of accepted terms | on registration |
| One-time tokens | a hash of the e-mail confirmation link (valid 24 hours) or password reset link (valid 1 hour) and the address it was issued for | on registration, e-mail change or password reset |
| Bill split data | participant names or nicknames, item names, amounts, discount, variable symbols, date | when you create an order |
| Group order data | the owner's bank account (IBAN), delivery coordinates, chosen restaurant, participant names, their items and totals, paid status, delivery tracking link | when you create or join a group |
| Anonymous device id | a random UUID stored in your browser and sent with your orders | when using the service signed out |
| Slack connection | workspace id and name, channel id and name, access token, optionally mapped Slack user ids | only if you enable the connection |
| Technical and operational data | IP address (in memory, for rate limiting), server logs of errors and sign-ins, cookie consent record (categories, time, version) | automatically while using the service |
Papu never processes card details or bank credentials and never moves money. A bank account number is stored only so the payment QR code can be generated.
If you enter someone else's name into an order, you are the one supplying their data. Keep it minimal (a first name or nickname) and do not add anything a split does not need.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Running the service - accounts, storing orders and groups, generating QR codes | performance of a contract, Art. 6(1)(b) GDPR |
| Signed-out use - keeping your orders under an anonymous identifier | legitimate interest in a working service, Art. 6(1)(f) |
| Security - rate limiting, abuse prevention, operational logs | legitimate interest in securing the service, Art. 6(1)(f) |
| Transactional e-mail - address confirmation, password reset, account change notices | performance of a contract and legitimate interest in account security, Art. 6(1)(b) and (f) |
| Posting messages to Slack | performance of a contract (a feature you enable), Art. 6(1)(b) |
| Anonymous traffic statistics | your consent, Art. 6(1)(a) - withdrawable at any time |
| Legal obligations and defence of legal claims | Art. 6(1)(c) and (f) |
4. Who receives the data
We do not sell data. Processors and recipients involved in running the service:
- OVH SAS - server and database hosting, EU data centre.
- Resend, Inc. - sending transactional e-mail (address confirmation, password reset, account change notices). Your e-mail address and username are passed on.
- Cloudflare, Inc. - anonymous traffic statistics (Cloudflare Web Analytics, cookieless) and traffic protection. Loaded only after your consent. Transfers to the US are covered by standard contractual clauses and the EU-US Data Privacy Framework.
- Slack Technologies (Salesforce) - only if you enable the Slack connection; participant names and amounts are posted to the channel you choose.
- Bolt Food and Foodora - menu and restaurant lookups by delivery coordinates. Your name, e-mail and account id are never sent to them.
- OpenStreetMap Foundation (Nominatim) - address lookup by text or coordinates.
Data may also be disclosed to public authorities where the law requires it.
5. How long we keep it
- Account data and the orders and groups tied to it: for as long as the account exists. Deleted immediately when the account is deleted.
- Orders created without an account: at most 90 days from creation, after which the personal content (participant names, items, amounts) is erased automatically.
- One-time tokens: deleted automatically once used or expired (24 hours, or 1 hour respectively).
- Cookie consent: 12 months, or until withdrawn.
- Server logs: at most 90 days.
- Data in backups: at most 30 days after deletion from the live database.
6. Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction of processing, data portability, the right to object to processing based on legitimate interest, and the right to withdraw consent at any time (withdrawal does not affect processing done before it).
- Access and portability: download a JSON export of your data in the Account section.
- Erasure: delete your account, together with your orders and groups, in the Account section.
- Rectification: change your e-mail and password in the Account section, anything else on request.
- Cookie consent: withdraw it with the Cookie settings button on the Cookies page or in your account settings.
- Anything else: write to daniel.vazac@email.cz. We reply within one month at the latest.
You may also lodge a complaint with the supervisory authority: Úřad pro ochranu osobních údajů (Czech Data Protection Authority), Pplk. Sochora 27, 170 00 Praha 7, www.uoou.gov.cz.
7. Cookies and browser storage
Papu uses necessary cookies for sign-in and for storing your consent, and keeps some data directly in your browser. The full list is in the Cookie Policy.
8. Security
Passwords are stored only as argon2id hashes. All traffic runs over HTTPS. Only the operator can reach the database, session cookies are HttpOnly and Secure, every sensitive action is authorised server-side, and request rates are limited.
No measure is absolute. If a breach were to put your rights at risk, you would be informed in line with Art. 34 GDPR.
9. Children
The service is not intended for anyone under 16 and their data is not knowingly processed. If you believe a child has given us data, write to us and it will be deleted.
10. Changes
This policy may be updated. A new version is published on this page with its effective date and version number; registered users are notified of material changes.