Privacy Policy
This policy explains how Milivoj Segedinac pr WEB INVADERS (“we”, “operator”) processes data in connection with the Koji QR web application and related pages at www.webinvade.rs/qr/.
1. Who we are
Data controller: Milivoj Segedinac, sole proprietor (preduzetnik), trade name WEB INVADERS
Tax ID (PIB): 108861977 · Company ID: 63755320 · Activity code: 6201
Not registered for VAT (PDV)
Registered address: Železnička 1, PAK 382978, 21238 Čurug, Republic of Serbia
Privacy contact: privacy@webinvade.rs
2. What is Koji QR
Koji QR is a progressive web app (PWA) for personal record-keeping of fiscal receipts in the Republic of Serbia. It lets you scan receipt QR codes, load data from the official fiscal receipt verification system (SUF), track spending by period, and indicative warranty end dates.
Koji QR is not an official app of the Serbian Tax Administration and is not a substitute for accounting, tax advice, or legal advice.
3. What data we process
Depending on how you use the service, we may process:
- SUF verification URL, fiscal receipt number (PFR), purchase date and time;
- merchant details (name, tax ID, address when shown on the receipt);
- line items (product name, quantity, prices, GTIN when available);
- your labels (spending/warranty flags, warranty months, product category);
- app settings (UI language, default warranty period, date filters);
- with optional Google storage: your Google account email and profile picture for display;
- technical data when communicating with our server (IP address, request time) as described below.
Receipt data may be financial and personal in nature. You choose which receipts to add.
4. Purpose and legal basis
- Providing the service — storing and displaying your personal receipt, spending, and warranty records (performance of the service / your request).
- Optional Google Sheet — syncing data to your Google account based on consent when you sign in with Google.
- Technical operation and security — SUF proxy and OAuth proxy, abuse prevention (legitimate interest).
- Network reachability — occasional requests to Google infrastructure to detect offline status (legitimate interest).
5. Where data is stored
5.1 Default — on your device only
Without Google storage, receipts and line items are stored in browser IndexedDB. Settings and, if you use Google, session refresh tokens are stored in localStorage and sessionStorage.
We do not maintain a central database of your receipts on our servers.
5.2 Optional — your Google Sheet
If you enable Google Sheet storage, the source of truth is a spreadsheet on your Google Drive (tabs: receipts, line_items, settings). Google acts as an independent controller under its own terms and privacy policy.
6. Processing on the operator’s server
Although we do not permanently store receipts, some requests pass through our server at qr.webinvade.rs:
6.1 SUF proxy
When you load a receipt, the browser sends a request to our server, which forwards it to suf.purs.gov.rs (Serbian Tax Administration). The verification URL and HTML response pass through our server in real time; we do not store receipt content in a database. Your IP may be used for rate limiting (currently up to 40 requests per minute per IP).
6.2 Google OAuth proxy
When you sign in with Google, our server exchanges the authorization code for tokens with Google (/api/oauth/google/token). The OAuth client secret stays on the server. Receipt content is not sent through this endpoint.
7. Third parties
- Serbian Tax Administration — public SUF system (suf.purs.gov.rs).
- Google — optional sign-in and sync: OAuth, Sheets API, Drive API (metadata), userinfo; Google Privacy Policy.
- Google (connectivity) — occasional HEAD requests to
*.gstatic.com/generate_204for connectivity checks.
8. Camera and device permissions
The app may request camera access only to scan QR codes. Images are processed on your device; we do not upload receipt photos to our server. You can use URL entry, local image import, or CSV instead.
9. Cookies and local storage
Koji QR does not set operator cookies for login or marketing. We use browser storage (IndexedDB, localStorage, sessionStorage). SUF or Google may set their own cookies on their domains.
10. Analytics and tracking
We do not use Google Analytics, ad pixels, or similar profiling tools. We do not sell your data.
11. Retention
Data is kept as long as you keep it in the app, browser, or Google Sheet. You can delete it by clearing site data, exporting then deleting, deleting the Sheet, or revoking app access in your Google account.
12. Your rights
Under the Serbian Personal Data Protection Act, you have rights including access, rectification, erasure, restriction, objection, and portability where applicable. For Google Sheet data, you may also use Google’s tools.
Contact privacy@webinvade.rs. You may lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection: www.poverenik.rs.
You can export data (JSON/CSV) in the app under Export.
13. Security
Communication uses HTTPS. We limit server processing to what is necessary. You are responsible for device security and your Google account.
14. Children
The service is not intended for anyone under 15. We do not knowingly collect children’s data.
15. International transfers
Google and SUF infrastructure may process data on servers outside Serbia, under those providers’ policies.
16. Changes
We may update this policy. The new version will be posted here with the revision date. Continued use after publication means you are aware of the changes.
17. Contact
Privacy questions: privacy@webinvade.rs
Related: Terms of Service