privacy / Markerra
Markerra Privacy Policy
Version 2026-07-29, effective 29 July 2026. This document explains how we process data in the Markerra technical demo, on the website, and while technically operating client QR/NFC app deployments. Location is used for marker scanning or the map. The app does not continuously track location in the background or refresh location merely because it launches.
In short
Markerra is the technology layer for apps with physical QR/NFC points and may be used in projects, including deployments independently organized by the client. We use data to sign users in, save progress, check the configured area, issue rewards, handle errors, and prepare aggregated functional and technical reports. The client does not receive participants' personal data. Markerra does not provide strategy, creative, media, targeting, retargeting, campaign management or optimization, or advertising attribution.
Controller and deployment-specific roles
For markerra.app and the public demo, the controller is Przemysław Wiśniewski Digital, a sole proprietorship registered in CEIDG, Polish tax ID/NIP: 5243019522, REGON: 529876286, address: ul. Turmoncka 22/1103, 03-254 Warsaw, Poland.
A client deployment may require a different allocation of roles. Where the client determines purposes, participant groups, rules, content, rewards, or how data is used, the client may be a controller, a joint controller with PWD, or a separate controller; PWD may act as processor. Before launch we determine roles from the actual decisions, conclude an Article 28 GDPR processing agreement or Article 26 arrangement as appropriate, and identify the proper controller to participants in the deployment-specific notice. A deployment is not opened to real participants without that role allocation, the required agreement, and a published participant notice. The current demo is governed by the Technical Demo Participation Rules.
Privacy and support contact: [email protected].
Providers and recipients
- Appwrite Cloud acts as processor for app data and B2B inquiries; the project's primary region is Frankfurt in the EEA, while further subprocessors are covered by the DPA, SCCs, or an applicable adequacy decision.
- Cloudflare provides website hosting and Turnstile. Form protection receives data including IP address, user agent, TLS characteristics, sitekey/origin, and a verification token.
- Google provides login, Maps, code scanning, and — only after consent — website Google Analytics and Google Ads (Google Ireland Limited), which receives an aggregate form-submission conversion event without form content or email address. Apple provides login and iOS system services.
- A bug report sent through the email link reaches Gmail/Google with the text selected by the user and the included diagnostics.
- Depending on the platform, the app may use Apple, Google, and system map services.
- The deployment client receives only an aggregated functional and technical report, without users' personal data.
Providers may process data outside the EEA. Appwrite uses its DPA, subprocessor list, and Standard Contractual Clauses; Cloudflare and Google identify the EU–US Data Privacy Framework or SCCs depending on the recipient and transfer; for EEA users Apple generally acts through Apple Distribution International in Ireland and uses SCCs where needed. Information about the applicable mechanism and a copy of relevant safeguards can be requested from the controller's contact address.
Data we process
| Area | Data | Purpose |
|---|---|---|
| Account and login | Appwrite user ID, email, profile name, Google or Apple provider, session; data comes from the user and the selected login provider | Authentication, account maintenance, and progress storage |
| Evidence of organizer-rules acceptance | A protected Appwrite table stores user ID, deployment and organizer identifiers, document kind and version, language, SHA-256, the configured minimum age, confirmation that the condition is met, acceptance time, and evidence-format version. We do not store a date of birth. After the server record is confirmed, the app creates an immutable copy of the accepted document in private storage with deployment, account, platform, and app-version metadata. This copy is not additionally transmitted from the device | Performing the participation rules, keeping functions locked until acceptance, evidencing the exact version and acceptance time, and establishing, pursuing, or defending legal claims |
| Deployment and progress | campaignId (the technical deployment identifier), markerId, scan status, platform, event time |
Progress, duplicate checks, rewards, and deployment diagnostics |
| Location | Position and accuracy at scan time, approximate distance, or area status | Checking whether the marker is collected inside the configured deployment area |
| Optional app-use analytics | Feature-use events such as session start, opening the map or scanner, progress, reward display, and opening the final link | Stored only after a separate in-app opt-in for feature diagnostics and aggregated reporting. Refusal does not block login, scans, progress, or rewards |
| Website analytics | Client/cookie identifier, page view, and URL origin and path together with the campaign parameters utm_source, utm_medium, utm_campaign, utm_term, utm_content and utm_id — all other query parameters and the fragment are stripped before sending; language, contact-button and store-link use, form status, approximate location derived from IP, and device/browser data; no form content or email |
Assessing the website's technical operation and usability |
| Form protection | Turnstile token, IP, user agent, TLS connection characteristics, sitekey/origin, and security result | Necessary protection against bots, abuse, and automated spam |
| Reward | Code, link, or reward instruction assigned to the account; pseudonymous user hash for one-code-per-deployment control | Issuing the reward after the user meets the client-defined rules and preventing repeated reward claims |
| Bug report | Report content, account email, user ID, platform, app version, technical deployment identifier, progress, last scan status; the message is sent by the selected mail app to Gmail | Support and diagnostics |
| B2B contact | Brand, contact email, planned deployment description, scale, reward, message content, page path without query or fragment, source host, and a technical flag showing whether Turnstile was disabled in a non-production environment; additionally the campaign parameters utm_source, utm_medium and utm_campaign remembered when you entered the site (up to 160 characters each). We do not store the form's full URL. Stored in Appwrite |
Handling business inquiries, preparing a response, and establishing which source the inquiry reached us from |
Automatically collected Google service data on Android
The Android app uses the Google Maps SDK for Android and Google Code Scanner, which is part of ML Kit. These components may automatically transmit technical data to Google for diagnostics, usage analytics, and maintaining and improving the services:
- Google Maps SDK: device and request metadata (for example OS version, model, brand and form factor, SDK version, and number of results), an Internal Usage Attribution Identifier, IP address, stack traces and crash metrics, and a Maps SDK-specific pseudonymous identifier. Depending on how the map is used, the SDK may also collect interactions such as panning and zooming.
- Google Code Scanner / ML Kit: device and app information, a device identifier or per-installation identifiers, performance metrics such as latency, API configuration, input and output size, feature version and usage, event types, and error codes. Because the scanner uses auto-zoom, it may also transmit a randomly generated scanning-session identifier, zoom-level changes, and predicted coordinates of an area that may contain a code.
Transmission of this data to Google services is encrypted; the ML Kit documentation specifies HTTPS encryption and states that ML Kit does not transfer the listed data to third parties. Code images and scan results are processed on the device and, according to the Google Code Scanner documentation, Google does not store them. Markerra does not use data automatically collected by these SDKs for advertising, advertising profiling, or its own tracking of users across apps.
The detailed and current scope is described in Google's official documentation: Maps SDK for Android data disclosure, ML Kit data disclosure, and Google Code Scanner.
Legal bases
| Purpose | Legal basis |
|---|---|
| Login and account | GDPR Article 6(1)(b) — forming and performing the free app-service contract |
| Evidence of organizer-rules acceptance | GDPR Article 6(1)(b) — forming and performing the service contract; where necessary to establish, pursue, or defend legal claims, also Article 6(1)(f) — the controller's legitimate interest |
| Deployment progress | GDPR Article 6(1)(b) — storing progress and providing app functions |
| Location check at scan time | GDPR Article 6(1)(b); additionally Article 6(1)(f) — preventing abuse and protecting fair redemption |
| Reward, code, or link | GDPR Article 6(1)(b) — performing organizer-defined activity rules |
| Security and anti-fraud | GDPR Article 6(1)(f) — protecting accounts, systems, markers, and reward pools from fraud or attack |
| Optional app-use analytics | GDPR Article 6(1)(a) — separate, voluntary consent withdrawable in the app |
| Website analytics | GDPR Article 6(1)(a) and Polish Electronic Communications Law Article 399 — consent withdrawable in analytics settings |
| Aggregated report | GDPR Article 6(1)(b) or (f) before anonymisation — B2B performance and technical accountability; GDPR does not apply after effective anonymisation |
| Bug report | GDPR Article 6(1)(b) or (f) — handling the request and correcting a defect or threat |
| B2B contact | GDPR Article 6(1)(b) for steps requested before a contract, or Article 6(1)(f) for responding to business contact |
Location
Location is used for marker scanning or the map so the app can check whether the user is within the configured area. The app does not continuously track users in the background or refresh location merely because it launches.
New progress records do not store the user's raw phone location. For compatibility with the existing data structure, some technical fields may store the configured deployment circle center or an approximate distance bucket, not the precise phone position.
Website cookies and analytics
Google Analytics runs only after the user clicks “Accept” in the analytics banner. We measure basic website events, such as page views, contact-button use, language selection, store links, and the technical status of form submission.
We do not send form content, email addresses, client names, reward descriptions, or
message text to Google Analytics. Consent is voluntary, expires after 12 months, and can be withdrawn earlier
through “Analytics settings” in the footer. Withdrawal stops future measurement and removes available
_ga cookies from the website domain.
Under the same consent we also report an aggregate conversion event to Google Ads indicating that the
contact form was submitted. The measurement runs in consent mode without advertising cookies —
ad_storage, ad_user_data, and ad_personalization remain denied,
so we do not profile users, run remarketing, or build audience lists, and no form content or email
address is sent to Google Ads.
| Name / storage | Provider and purpose | Maximum duration |
|---|---|---|
markerraAnalyticsConsent and date in localStorage | Markerra — remembering the choice; necessary storage used to respect the decision | 12 months |
markerraCampaignSource in sessionStorage | Markerra — remembering the campaign parameters from your entry URL so we know which source an inquiry sent through the form came from; the legal basis is our legitimate interest (Art. 6(1)(f) GDPR) | until the browser tab is closed |
_ga, _ga_* | Google Analytics — distinguishing browsers and website statistics, only after consent | up to 13 months |
Turnstile token and possible cf_clearance | Cloudflare — necessary protection against bots and abuse | challenge duration or the period set by Cloudflare |
Functional and technical reports for clients
The deployment client receives an aggregated functional and technical report, such as the number of users, collected markers, completed flows, reward displays, and final-link opens. The client does not receive emails, user IDs, raw location, raw Appwrite exports, reward codes assigned to people, individual participant paths, advertising segments, or audience exports to advertising platforms.
The client must not attempt to reidentify participants. Report breakdowns are shown only when
they include at least 5 users. Smaller cells are marked as <5 or described qualitatively.
Data retention
| Data | Retention period |
|---|---|
| User account | Until account deletion; inactive accounts are reviewed after 24 months and are not removed without prior notice where contact is possible |
| Server-side evidence of organizer-rules acceptance | Stored with the account and deleted when the account is deleted. Separate, limited evidence may be retained after account deletion only where required by law or where its documented retention is necessary to establish, pursue, or defend legal claims, and no longer than that purpose justifies |
| Immutable organizer-rules copy and metadata in the app's private local storage | Until the user clears app data or uninstalls the app. Account deletion does not remove this personal copy; the user may save or share it outside the app before or after deleting the account |
| Login sessions | Until logout, session expiry, or account deletion |
| scan_attempts / scan diagnostics | Until deployment archival + up to 14 days, unless a longer period is needed for security or complaint handling |
| user_markers / progress | Until deployment archival + up to 180 days |
| rewards / codes and links | Until deployment archival + up to 365 days, or the period defined in the client's rules |
| reward_claims / pseudonymous reward claims | Until deployment archival + up to 365 days, or the period defined in the client's rules |
| analytics_events | Up to 180 days after archivedAt is set for the deployment, then deletion or effective anonymisation |
| Google Analytics / website consent | GA4 event data retention: 14 months; consent can be changed in the analytics settings in the footer |
| Bug reports | Case closure + 90 days |
| B2B forms and contact | 12 months from the last contact |
| Aggregated reports | Longer, if they do not contain personal data |
| Minimal account-deletion log | Up to 12 months for accountability and security |
Account deletion
A user can delete the account in the app or send a deletion request without the app. Instructions are available on the Delete account page. Account deletion removes the app account and the app data linked to that account, including progress, scan attempts, rewards, and analytics events, except data that we must keep for a limited time for security, complaint handling, or accountability. In particular, we may keep a pseudonymous reward claim to prevent one person from receiving multiple codes in the same deployment by deleting and recreating an account.
User rights
Users may request access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interest, and may lodge a complaint with the President of the Polish Personal Data Protection Office.
App analytics consent can be withdrawn in the app, while website Google Analytics consent can be withdrawn through the footer link. Withdrawal does not affect earlier lawful processing. Data required for the account, progress, and reward is voluntary, but those functions cannot operate without it; analytics consent is not required. Data comes from the user, device, login provider, and deployment configuration supplied by the client.
Geofencing, duplicate checks, and reward unlocking follow predetermined rules. We do not use advertising profiling or solely automated decisions producing legal or similarly significant effects. A rejected scan or reward can be challenged in a complaint reviewed by a person.
For privacy requests, contact: [email protected]. We respond without undue delay and generally no later than one month after receiving the request. For complex requests, this period may be extended by two additional months; we will inform the user within the first month and explain the reason for the extension.