Privacy, clearly explained.
What Diskvr collects, why it is used, where it is kept and the choices available to you.
Who this notice covers
This notice covers business owners who create an account, visitors who browse a folio, people who send an enquiry or safety report, and people who contact Diskvr support. Each business remains responsible for how it uses contact details received through its private enquiry inbox.
Information we process
- Account details: first name, last name, email address, password hash and session information.
- Business content: profile details, locations, contact links, photographs, testimonials, offerings, categories, tags and publication settings.
- Enquiries: the visitor name, message, email address or phone number supplied for a reply, relevant business branch, inbox status and submission time. An irreversible source fingerprint is retained for abuse controls; the enquiry does not store the raw IP address.
- Operational data: security events, limited request metadata, error records, daily page-view totals and aggregated contact-action counts.
- Safety and support information: the reported folio or image, selected reason, optional explanation, review status, correspondence and submission time. Public reports retain an irreversible source fingerprint for abuse limits, not the raw IP address.
Why we use it
We use this information to create and secure accounts, publish and deliver folios, deliver visitor enquiries to the selected business owner, enforce quotas, support editing, provide aggregated analytics, respond to abuse, prevent fraud, recover from failures and meet legal obligations. Diskvr does not send or broker the owner’s reply and does not take ownership of the customer relationship.
Public information
Anything an owner publishes in a folio is public and can appear in Diskvr Discovery, be viewed, indexed, searched, filtered, shared, copied or captured by others. Discovery uses only published business and offering information and does not create visitor profiles. Diskvr can restrict writes and keep the underlying R2 bucket private, but no website can prevent a visitor from saving an image that their browser is allowed to display.
Infrastructure, processors and external services
Diskvr runs on Cloudflare Workers, D1, R2, Turnstile and related delivery and security services. Transactional email may later be enabled for verification and password resets through the provider identified on this page at that time. Processing may occur where these providers operate, subject to their contractual and legal safeguards. External links such as WhatsApp, Instagram, YouTube, business websites and Google Maps are governed by those services when a visitor chooses to open them.
Retention and security
Account and folio information is retained while the account operates. Enquiries remain in the owner’s private inbox until the owner deletes them or the account is removed. Sessions expire after the configured session period. Safety, security and support records are retained only for review, abuse prevention, disputes and legal duties. Deleted information may remain temporarily in restricted recovery history before expiry. Images are stored in a private R2 bucket and served through Diskvr’s Worker. We use access checks, HttpOnly cookies, validation, file inspection, quotas, rate limiting, security headers, encryption in transit and platform protections. No system can promise absolute security.
Your choices and rights
Owners can edit or unpublish most business information from Studio. Depending on applicable law, a person may request access, correction, completion, deletion, consent withdrawal, grievance review or another available action concerning their personal data. Visit Privacy support to submit a request. Identity and authority may need to be verified before a request is completed. Public content concerns can be submitted with the Report content control on a folio.
Children
Diskvr business accounts are not intended for children. Content that exploits or endangers a child is prohibited and should be reported immediately using the child-safety reason.
Questions and grievances
Privacy questions and grievances can be sent through the current contact shown in Support. Include enough information to identify the relevant account, folio, enquiry or request, but never send a password or session token.
Changes
We will update the effective date and wording of this notice when our practices materially change. Account holders will receive additional notice where required.