Privacy Policy
Last updated: 2026-07-12
This policy explains what QR Tool collects and why. We designed the product to collect as little personal data as possible.
1. Account data
When you sign up we store your name, email, and a securely hashed password. Billing is handled by our Merchant of Record; we never see or store your card details.
2. Scan analytics: privacy by design
When someone scans a dynamic code, we record the country/region, device type, operating system, and timestamp. We do not store the scanner's IP address. To count unique scanners we store a one-way daily hash of (IP + user-agent + date) that cannot be reversed to identify a person. This is why we generally do not need a cookie consent banner for scan tracking.
3. Cookies
We use a strictly-necessary session cookie to keep you logged in and a workspace cookie for team switching. We do not use advertising cookies.
4. Uploaded content
Files you upload (e.g. PDFs) and page content you create are stored to serve your QR codes. They are deleted when you delete the code or your account.
5. Your rights (GDPR/CCPA)
- Export: download everything we hold about you as JSON from Settings.
- Deletion: delete your account from Settings; this permanently removes your data and uploaded files.
- Access, correction, and objection rights per applicable law.
6. Subprocessors
We use third parties to run the Service: hosting/CDN, database, transactional email, product analytics, error monitoring, and payments (Merchant of Record). [Lawyer/founder to publish the specific subprocessor list and Data Processing Addendum before launch.]
7. Data retention
Aggregate scan counts are kept indefinitely; raw scan events are pruned per your plan. [Confirm exact retention windows.]
8. Contact
Privacy questions or requests: [privacy email].