QRGenCode

Privacy

What a scan records, what it never records, and what you can ask us to do about it. Last updated 23 August 2026.

What a scan records

A QR code on a package is scanned by people who never agreed to anything with us. So a scan is recorded as an aggregate, not as an event about a person.

RecordedWhyKept
QR public id, organization idattribute the scan to a code25 months, aggregated
Timestamptrends over time25 months, minute precision
Country and regiongeographic reporting25 months, coarse
Device, OS and browser categoryproduct decisions25 months, category only
Referrer domainattribution25 months, domain only
UTM parameterscampaign attribution25 months

None of these fields identifies the person who scanned. They are stored as daily rollups per code, not as a row per scan.

What is never collected

  • Raw IP addresses (never written to storage)
  • Precise geolocation
  • Device identifiers or cross-site identifiers
  • Verbatim user agent strings
  • Cookies on the redirect domain
  • Scan-level profiles of individual people

For abuse detection only, a truncated and peppered hash of the IP address may be held for 30 days in a separate store. It is never joined to scan analytics, and rotating the pepper severs any correlation across periods.

The sign-in limiter keys on a peppered hash of the identifier and address together. The raw email and IP are not written to that store. Rotating the same pepper severs those counters too.

Cookies

The redirect domain sets no cookies at all. There is nothing on it to consent to. The dashboard sets only the cookies needed to keep you signed in and to protect forms against cross-site request forgery; there is no advertising or analytics cookie anywhere in the product.

Who is responsible for what

For scan analytics, the organization that owns the code is the controller and we are the processor: they decide what the code points at and whether to measure it. For account and billing data we are the controller.

Your rights

Access and portability. Settings has a button that exports your account as JSON — your profile, your memberships, the codes you created and the audit entries you can already read. A workspace owner can export the whole tenant.

Erasure. Deleting your account revokes every session first, then removes your profile and sign-in identity. Audit and security log entries are kept, with your identity removed from them — the actor becomes deleted user rather than the line being deleted. An intact security record with the person taken out of it is the balance we have chosen, and we would rather state it here than leave you to discover it. A workspace you own has to be deleted before your account can be, because printed codes still point somewhere. A deleted workspace is kept as a tombstone so the audit spine still has somewhere to point; after 30 days its destinations, page content and invitation addresses are removed. The organization row remains.

Rectification. Your profile is editable in the app.

Objection. Scan analytics can be turned off per code. The redirect still works; nothing beyond an unattributed counter is recorded.

Sub-processors

Supabase hosts the database and authentication. Cloudflare serves the redirect edge, stores uploaded images and provides bot protection on sign-in. Paid plans are billed through Stripe, which handles card details directly — we never receive them.

This installation is hosted in the United States. Hosting in an EU or Brazilian region is a deployment choice, not something this environment currently offers.

Contact

Privacy questions go to privacy@qrgencode.com. Security reports go to security@qrgencode.com and are acknowledged within one business day.

This notice describes how the system actually behaves. It has not yet been reviewed by a lawyer, and it is not a contract.