Back to home

Privacy Policy

How we collect, use, and protect your personal information.

Last updated: 2026-09-11

Introduction

We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use our service.

Information We Collect

We collect the following types of information to provide and improve our service:

  1. Account Information — Your name, email address, and other details you provide when creating an account.
  2. Usage Data — Information about how you interact with the service, including features accessed, frequency of use, and interaction patterns.
  3. Device Information — Device type, operating system, and browser type, used to optimize compatibility and performance.
  4. Cookies — Small data files stored on your device to remember preferences and improve your experience.
  5. Payment Information — Billing details handled by trusted third-party payment processors. We do not store full card numbers on our servers.

How We Use Your Information

We use the data we collect to:

  • Provide, maintain, and improve the service.
  • Process transactions and send related confirmations.
  • Send technical notices, security alerts, and support messages.
  • Respond to your questions, feedback, and support requests.
  • Detect, prevent, and address fraud and abuse.

Abuse Reports

Anyone can report a suspicious dynamic QR code without signing in. A report records the short code, the reason category, any additional context you write, and a contact email if you choose to give one.

  • Why we collect it — to review the report for safety; to follow up with you when you leave an address; and to recognise repeat submissions, so that sending the same report twice does not open two cases.
  • The email stays optional — a report is accepted without one. An unverified address is not treated as proof that a report is genuine.
  • How long we keep it — the optional contact email is erased in the same database write that closes the report's ticket, not by a later job. The report itself remains on file as a safety record.
  • What deleting the address does not remove — recognising repeat submissions works by storing fingerprints computed from the report's contents, including the address when one is given. Those fingerprints stay on the report after the address is deleted, and they can still be used to check whether a particular address filed a particular report. We would rather write that down than describe the deletion as more complete than it is.
  • The report record does not contain your IP address — our application uses it as a one-way rate-limit key, so that a script cannot flood the form, and does not write it into the report.
  • Our hosting platform is separate — the site runs on Cloudflare, which receives the connecting IP address and may keep it in its own platform logs under its retention and processing terms. Under Cloudflare's currently published Workers retention limits, those logs are kept for no more than 7 days. That is outside the report record described above, and we do not claim otherwise.

To ask about a report you filed, email support@qrcodebrain.com and quote the receipt ID shown when it was submitted.

QR Scan Statistics

When an active dynamic QR code successfully redirects, our application updates one anonymous daily aggregate. It records only the QR code, the UTC date, a validated two-letter country code (or ZZ when unavailable), a coarse device class (mobile, tablet, desktop, or unknown), the number of successful redirect requests, and the latest successful redirect time.

  • Why we process it — to give the code owner basic totals and daily, country, and device breakdowns, and to operate and troubleshoot that feature. Where applicable, we rely on performing the requested service and our legitimate interests in basic service analytics and reliability.
  • A count is not a person — bots, link previews, prefetching, and repeated requests may be counted. An aggregation failure does not block the redirect, so totals may also undercount. We do not describe these figures as people or unique visitors.
  • What the QR aggregate does not store — it does not store the raw IP address, complete User-Agent, a device fingerprint, a unique-visitor identifier, personal identity, or precise location. The complete User-Agent is used only during the request to choose the coarse device class and is then discarded from QR business data and logs.
  • Account and session records are separate — our existing account and session systems separately record IP addresses and User-Agent strings for authentication, security, and session management. Those records are not QR scan statistics and are not covered by the QR aggregate statements above.
  • Our hosting platform is separate — Cloudflare receives the connecting IP address and may keep platform logs under its own terms. Under Cloudflare's currently published Workers retention limits, those logs are kept for no more than 7 days. They are outside the QR aggregate described here.
  • How long we keep it — we keep the most recent 397 UTC calendar days of daily aggregates, counting today. Anything older is deleted by a scheduled job that runs once a day. Separately, when a QR code has been archived for 90 days, that code's aggregates are deleted in full; the code itself, its target history, and its audit records are not affected.
  • This is enforced by a job that runs, not by a promise — the deletion job is scheduled on our platform, its runs are recorded, and it reports how many rows it removed. We published these numbers only after a real production run had happened and been checked. Until then this section said there was no fixed deadline, because there was not one.

To ask about QR scan statistics or request help with data rights, email support@qrcodebrain.com.

Data Sharing

We do not sell your personal information. We may share data only in these limited cases:

  • With service providers who help us operate the service, under confidentiality agreements.
  • To comply with legal obligations or respond to lawful requests from public authorities.
  • To protect our rights, property, or safety, or that of our users.

Data Security

We implement industry-standard security measures including encryption in transit, access controls, and regular reviews. No method of transmission over the Internet is 100% secure, but we work continuously to protect your information.

Your Rights

Profile details that are currently available in account settings can be updated there. You can also delete your account yourself, from Settings → Profile. Personal-data export is still not offered; to request access, export or correction — or deletion, if you cannot sign in — email support@qrcodebrain.com. We verify account ownership before processing any request, including a self-service one.

What deleting your account does

Before anything irreversible happens we confirm it is you: a recent sign-in plus your password, or a one-time code sent to your email address if you sign in with Google or GitHub.

If your account is free, the request waits 7 days and you can undo it during that time. If you are inside a period you have already paid for, we cancel auto-renewal straight away, keep your service running until that period ends, and delete afterwards. Unused time is not refunded, and undoing the deletion does not switch auto-renewal back on.

What deletion removes is your account and your personal data — it is not an erasure of every trace:

  • Your sessions, sign-in credentials, API keys, roles and your own content are deleted.
  • Your user record is kept as an anonymous placeholder so that records referring to it stay intact. It can never be signed into again.
  • Every QR code you own is archived, not deleted. Any code you have already printed on our shared short domain answers HTTP 410 Gone from then on — it existed and was stopped, rather than 404, which would say it never existed. A short code is never reassigned to anyone else.
  • If you had bound your own customer domain, we remove it from our certificate provider and delete the binding at the same time. Codes printed on that domain no longer reach us afterwards, so we cannot answer them with 410; scanners see whatever your domain's DNS now points to, or a connection error. They never resolve into another account.
  • Target history, risk holds and audit records are kept, with your identity removed from them.
  • Scan statistics expire on their existing schedule (90 days after archiving, 397 days rolling). Deletion does not add a second cleanup path for them.

How long we keep what is kept

  • Ordinary support tickets and their messages: 12 months.
  • Abuse reports, security and audit records, and invitation records: 24 months.
  • Financial records — orders, subscriptions and credits: 7 years, because tax and accounting law requires it. Those records keep the account email you ordered with and the payer email the payment provider returned, which may not be the same address; both are kept for the same seven years and are not rewritten to the tombstone address when you delete your account.

When a period ends the record is deleted or irreversibly de-identified. If a record is under a legal hold, the hold takes precedence and nothing is deleted or de-identified until it is lifted.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by updating the date at the top of this page and, where appropriate, sending a notice through the service.

Contact Us

If you have questions about this Privacy Policy or want to exercise a data right, contact support@qrcodebrain.com.