Privacy Policy

1. Controller

ucepts UG (haftungsbeschränkt)
Kirchdorfer Str. 24 · 84104 Rudelzhausen · Germany
Represented by Tobias Bayer 
Handelsregister: HRB 212457
Registergericht: Amtsgericht München

Email: info@querycue.io

QueryCue is a brand of ucepts UG (haftungsbeschränkt). Contact for all privacy matters: info@querycue.io.

We are not required to appoint a data protection officer under § 38 BDSG. Your enquiry reaches us directly at the address above.

2. Hosting

querycue.io runs on a dedicated server that we rent from Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server is located in a data centre in Frankfurt am Main, Germany. We administer the server ourselves; Hetzner provides the infrastructure and has no access to the content of our databases in the ordinary course of operations.

We have concluded a data processing agreement (Art. 28 GDPR) with Hetzner. No personal data is transferred outside the European Union through hosting.

Server log files

Our web server automatically records information that your browser transmits when you visit the site:

  • IP address
  • Date and time of the request
  • The page or file requested, and the amount of data transferred
  • HTTP status code
  • Referring URL and browser/operating system identifier (user agent)

Purpose and legal basis: operating the website securely and reliably, detecting and tracing attacks and abuse. Legal basis is Art. 6 (1) (f) GDPR — our legitimate interest in a secure, functioning website. This data is not merged with other data sources and is not used to identify you.

Retention: log files are deleted after [[LOG_TAGE]] days.

3. Cookies

We do not use tracking, analytics or advertising cookies, and we do not run a cookie banner, because we set no cookies that would require your consent.

The only cookies that occur are strictly necessary ones:

CookiePurposeDuration
wordpress_logged_in_*wordpress_sec_*Keeps you signed in to your customer account after you click your sign-in link. Set only once you sign in — never for visitors who just browse the site.14 days, or until you sign out
wp-settings-*Stores interface preferences for signed-in users.up to 1 year

These cookies are strictly necessary to provide the service you explicitly requested (signing in). Legal basis: § 25 (2) no. 2 TDDDG and Art. 6 (1) (b) GDPR. They require no consent, and you cannot switch them off without losing the ability to sign in.

4. Your customer account (passwordless sign-in)

You can create an account to buy and manage a licence. We deliberately use no passwords. Instead, we send you a one-time sign-in link (“magic link”) by email.

What we store

  • Registration: first name, last name, email address, and your consent to this privacy policy.
  • Sign-in link: your email address, an expiry timestamp, and the link token — stored only as a SHA-256 hash, never in readable form. The link is valid for 15 minutes (24 hours for the welcome link after a purchase) and can be used once.
  • Abuse protection: to limit sign-in attempts (5 per 15 minutes) we store a cryptographic hash of your email address, your IP address and a secret server key. Your IP address itself is not stored — the hash cannot be reversed into an IP address, and it expires automatically.

Purpose, legal basis, retention

Purpose: providing and securing your account. Legal basis: Art. 6 (1) (b) GDPR (performance of a contract or pre-contractual measures) and Art. 6 (1) (f) GDPR (legitimate interest in preventing abuse of the sign-in form).

Retention: expired sign-in links are deleted automatically every day. Your account data is kept for as long as your account exists. You can ask us to delete your account at any time — see section 9. Statutory retention obligations under commercial and tax law (see section 8) remain unaffected.

5. Purchases and payment (Stripe)

Payments are processed by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (“Stripe”).

We never see or store your payment details. When you buy, you are redirected to Stripe’s own checkout page. Card numbers, bank details and similar payment data are entered there and processed exclusively by Stripe.

What we transmit to Stripe

  • the product and quantity you selected,
  • your email address (pre-filled if you are signed in),
  • an internal reference to your user account, so that we can assign the purchase to you,
  • where applicable, tax-relevant information for automatic VAT calculation.

Stripe collects your billing address and payment details directly from you and reports the outcome of the payment back to us. From Stripe we store a customer ID and the status and expiry date of your plan — nothing else.

Legal basis: Art. 6 (1) (b) GDPR (performance of the contract). Stripe processes data in part on servers of its affiliate Stripe, Inc. in the USA. For such transfers, Stripe relies on the EU Standard Contractual Clauses and is certified under the EU–U.S. Data Privacy Framework. Details: stripe.com/privacy.

Retention: invoices and the associated data are retained for 10 years under statutory commercial and tax law obligations (§ 147 AO, § 257 HGB).

6. Support requests (tickets)

Customers with an active Pro plan can open support requests in their dashboard.

  • What we store: the subject, the message text you write, the status of the request, timestamps, and the account it belongs to.
  • Screenshots: you may attach images (max. 3 per message, max. 5 MB each). These are not stored in the public media library and have no public URL. They are saved outside the publicly accessible area under a random file name and are delivered only to you and to our support team, after an authorisation check.
  • Notifications: when we reply, we send you an email telling you that a reply exists. We deliberately do not include the content of the reply in that email — email is an unencrypted channel. The conversation itself stays on our server.

Please do not send us passwords, payment details or personal data of your own website visitors in a support request. If we need such information to help you, we will tell you how to transmit it safely.

Legal basis: Art. 6 (1) (b) GDPR (performance of the contract, including support).

Retention: support requests are retained for as long as they are needed to handle your enquiry and to answer follow-up questions, and are deleted afterwards on request. A request that has been closed is not automatically deleted. You can ask us to delete your support history at any time — see section 9.

7. Email

We send transactional emails only: your sign-in link, a welcome message after a purchase, and support notifications. These emails are sent from our own mail server in the data centre in Frankfurt am Main — no external mail provider receives your address for this purpose.

Legal basis: Art. 6 (1) (b) GDPR. We do not send marketing emails without your separate, explicit consent (Art. 6 (1) (a) GDPR), which you can withdraw at any time.

8. Who receives your data

Outside our own infrastructure, personal data reaches only the following recipients:

RecipientPurposeLocation
Hetzner Online GmbHHosting (processor, Art. 28 GDPR)Germany
Stripe Payments Europe, Ltd.Payment processingIreland / USA (SCCs, Data Privacy Framework)
Tax advisor, auditors, authoritiesStatutory accounting and tax obligationsGermany

There is no one else. We use no analytics service, no advertising network, no CDN for fonts or scripts, and no customer relationship platform. We do not sell personal data.

9. Your rights

Under the GDPR you have the right to:

  • Access (Art. 15) — ask us what data we hold about you.
  • Rectification (Art. 16) — have incorrect data corrected.
  • Erasure (Art. 17) — have your data deleted, unless we are legally required to keep it (invoices, see section 5).
  • Restriction of processing (Art. 18).
  • Data portability (Art. 20) — receive your data in a machine-readable format.
  • Object (Art. 21) — object to processing based on our legitimate interest.
  • Withdraw consent (Art. 7 (3)) — with effect for the future, where processing is based on consent.

One email to info@querycue.io is enough. We will respond within one month.

Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority. The authority responsible for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 27, 91522 Ansbach, Germany
www.lda.bayern.de

10. Is providing data mandatory?

You can browse querycue.io without providing any personal data. To create an account or buy a licence, we need your email address and, for a purchase, the billing information required by law. Without it, we cannot conclude or perform the contract.

11. Automated decision-making

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.


12. A note on the QueryCue Forms plugin

This privacy policy covers querycue.io — our website and store. It does not describe what happens on your website when you install QueryCue Forms.

That distinction matters, and it is in your favour: the plugin sends no data to us. Form submissions collected with QueryCue Forms stay in the database of your own WordPress installation. There is no QueryCue cloud, no telemetry, no “phone home” with your visitors’ data. We never see the submissions your forms collect.

For those submissions, you are the controller under the GDPR — not us. Because no personal data flows to us, we do not act as your processor and a data processing agreement (Art. 28 GDPR) is not required for the operation of the plugin.

Optional features of the Pro edition can transmit data to third parties if you switch them on — for example a captcha provider (which receives your visitor’s IP address), an outbound webhook to a URL you choose, or a Calendly integration. These are off by default, you activate them deliberately, and you are responsible for reflecting them in your own privacy policy. The plugin tells you so in the settings screen.