BarcodesQR

Privacy & Cookie Policy

Last updated: June 11, 2026

1. Introduction

[LEGAL ENTITY NAME], trading as BarcodesQR ("we", "us", "our"), is the controller responsible for the personal information described in this policy. Our registered address is [REGISTERED ADDRESS]. This policy explains what we collect when you use BarcodesQR.com, why we collect it, who we share it with, and the choices you have.

It applies to everyone the service touches, wherever in the world they are: visitors browsing the site, account holders creating and managing QR codes, and people who scan a code made with BarcodesQR.

We honor the privacy frameworks that apply to you, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA). Where your local law gives you stronger rights than this policy describes, your local law wins.

2. Information We Collect

We collect four groups of information: first, information you give us directly; second, information collected automatically while you use the site; third, scan data generated when someone scans one of your codes; and fourth, information that reaches us through other routes — the email gate, feedback forms, and third-party sign-in. The four groups are itemized below, in that order.

  • Account details — the email address you register with and your sign-in credentials.
  • Passwords you set on password-protected codes — stored only as salted hashes; we cannot read the original password back, and neither can anyone who obtains the stored value.
  • QR content — everything you put into a code or its landing page, including uploaded files, logos, and avatar images.
  • Support requests — the messages, attachments, and contact details you include when you ask us for help.
  • Device and technical data — browser type and version, operating system, screen size, and language settings.
  • Approximate location — a country and region estimate derived from geolocation headers added by our hosting provider; we do not run our own IP-lookup database.
  • Usage data — the pages you visit, the features you use, and how you move through the creator and the dashboard.
  • Scan events — when someone scans a code you created, we record the timestamp, country, and city of the scan.
  • Scanner device profile — the device type, operating system, and browser family of the scanning device.
  • Referrer URL — the page the visitor arrived from, when their browser sends one.
  • Scan fingerprint — a keyed hash derived from the visitor's IP address and browser characteristics, used only to count unique scans. The raw IP address is not stored, and the hash cannot be recomputed from public inputs without our server-side key.
  • Email gate — if you enter an email address before creating an account, we store it as a lead so we can link the codes you made to your account once you register.
  • Feedback submissions — ratings and comments that visitors leave on feedback-type codes you run; these are stored against your code and shown in your dashboard.
  • Third-party sign-in — if you sign in through an identity provider, we receive the basic profile details that provider shares, typically your name and email address.

3. How We Use Your Information

We use the information above to run the service — nothing more exotic than that. In concrete terms:

  • Operating the product — generating your codes, serving dynamic redirects, rendering landing pages, and storing your designs and uploads.
  • Analytics for you — turning scan data into the charts, counts, and exports you see in your dashboard.
  • Billing — managing your trial, subscription, invoices, and payment state.
  • Support — answering your requests and troubleshooting problems on your account.
  • Security and abuse prevention — detecting fraudulent codes, malicious destinations, and attempts to break into accounts.
  • Service messages — emails about your account, your subscription, or material changes to the service or this policy.
  • Legal compliance — keeping records the law requires us to keep and responding to lawful requests.

We do not use your information to build advertising profiles, and we do not sell it.

5. Cookies and Local Storage

We keep cookies to the minimum the product needs to function:

  • Session and authentication cookies — keep you signed in and protect your account.
  • Password-unlock cookies — remember that a visitor has already entered the correct password for a protected code, so they are not asked again on every view.
  • Preference storage — small local values such as your chosen language and interface settings.

We do not set advertising or cross-site tracking cookies, and we do not sell data collected through cookies. Because everything we set is either essential or stores your own preferences, there is no advertising consent for you to manage.

6. When We Share Information

We share personal information only with the service providers that run the platform and in the limited situations listed below. We never sell personal information, and we do not share it for cross-context behavioral advertising.

  • Supabase — our database, authentication, and file-storage provider; it hosts account data, code content, uploads, and scan records on our behalf.
  • Vercel — our hosting and content-delivery provider; it serves the site, handles traffic, and supplies the geolocation headers we use for approximate location.
  • A payment provider — a payment processor will handle subscriptions and card details on our behalf; the specific provider is to be named before launch. Card numbers are handled by the processor, never stored by us.
  • Legal compliance — we may disclose information when a law, regulation, court order, or enforceable government request requires it.
  • Business transfer — if we merge, are acquired, or sell assets, personal information may transfer to the successor, which must keep honoring this policy.

Each processor acts under our instructions and only for the purposes described here.

7. How Long We Keep Data

We keep personal information only as long as it serves the purpose it was collected for, then delete or anonymize it. As a matter of policy:

  • Account data — kept while your account is active, then for 12 months after it closes.
  • Scan analytics — kept for 24 months from the date of the scan.
  • Billing records — kept for around 7 years, as tax and accounting law requires.
  • Support correspondence — kept for 3 years after the request is closed.
  • Server and security logs — kept for 12 months.
  • Backups — encrypted backups roll off within 90 days.

These periods are stated as policy. A copy of deleted data can persist in backups until those backups expire on the schedule above.

8. How We Protect Your Information

We apply technical and organizational measures appropriate to the data we hold:

  • Encryption in transit — all traffic to and from the service uses TLS.
  • Password hashing — passwords on protected codes are hashed with scrypt and a per-password salt; we never store them in readable form.
  • Keyed scan fingerprints — scan fingerprints are produced with a keyed hash, so they cannot be reversed or recomputed without our server-side secret.
  • Access controls — access to production data is restricted to the roles that need it.

No online service can promise perfect security, and we do not. If a breach affects your personal information, we will notify you and the relevant authorities as applicable law requires.

9. International Transfers

Our processors store and process data in the United States. If you use the service from the EU, the UK, or another jurisdiction with transfer rules, your information will move to the US as part of normal operation.

Where the GDPR or UK GDPR requires a transfer mechanism, we rely on the European Commission's Standard Contractual Clauses (with the UK addendum where relevant) with our processors, and we commit to keeping equivalent safeguards in place as processor relationships change.

10. Your Rights

Depending on where you live, you can exercise some or all of the following rights over your personal information:

  • Access — get a copy of the data we hold about you.
  • Correction — fix inaccurate or incomplete data.
  • Deletion — ask us to erase your data.
  • Restriction — pause certain processing while a dispute is resolved.
  • Objection — object to processing based on legitimate interests.
  • Portability — receive your data in a structured, machine-readable format.
  • Withdraw consent — where processing rests on consent, withdraw it at any time without affecting what was done before.

To exercise any of these rights, email privacy@barcodesqr.com. We aim to respond within one month; if a request is complex we may extend that period as the law allows, and we will tell you if we do. We may ask you to verify your identity before acting on a request. If you are unhappy with our answer, you can complain to your local data-protection authority.

11. Account Deletion

You can delete your account from the dashboard or by emailing privacy@barcodesqr.com. Deletion is irreversible: your codes, designs, uploads, and analytics are removed and cannot be restored.

Dynamic codes stop redirecting once the account is gone. Anyone scanning a printed code afterwards reaches an error page instead of your destination, so download or migrate anything you still need before deleting.

A small residue survives deletion for the periods listed in the retention section above: billing records that tax law requires, server logs, and backup copies until the backups expire.

12. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the CCPA/CPRA gives you specific rights and entitles you to specific disclosures, set out here.

In the last 12 months we have collected these categories of personal information: identifiers (email address), internet or network activity (usage and scan data), approximate geolocation, commercial information (subscription and billing history), and the content you upload. We collect them from you, from your devices, and from people who scan your codes, for the purposes described in "How We Use Your Information".

  • We do not sell personal information and have not sold it in the preceding 12 months.
  • We do not share personal information for cross-context behavioral advertising.
  • We honor the Global Privacy Control (GPC) signal as a valid opt-out where it applies.
  • You may exercise your rights to know, delete, and correct, and you will not be discriminated against — in price, service level, or otherwise — for doing so.

California requests go to privacy@barcodesqr.com. You may use an authorized agent, and we may verify the request before acting on it.

13. Other US State Privacy Laws

Residents of other states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Texas, Oregon, and Utah — have broadly similar rights: to confirm whether we process your data, to access and correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, sale, and profiling used for significant decisions.

Because we do not sell data, run targeted advertising, or profile anyone for significant decisions, the opt-out rights have nothing to act on — but access, correction, deletion, and portability work the same way as everywhere else: email privacy@barcodesqr.com. If we decline a request, you may appeal by replying to our decision; if the appeal also fails, you may contact your state attorney general.

14. Other Jurisdictions

We apply the substance of this policy globally and honor local frameworks where they reach us:

  • Canada (PIPEDA) — we process personal information with consent or as PIPEDA otherwise permits, and Canadian users can access and correct their information through the contacts below.
  • Brazil (LGPD) — Brazilian users have rights of confirmation, access, correction, anonymization, deletion, and information about sharing; the legal bases we rely on correspond to those recognized by the LGPD.
  • Australia (Privacy Act) — we handle personal information consistently with the Australian Privacy Principles, including notification of eligible data breaches.

If your jurisdiction grants rights this policy does not list, contact privacy@barcodesqr.com and we will assess your request under your local law.

15. Children's Privacy

The service is for adults: you must be at least 18 to create an account, and we do not knowingly collect personal information from anyone younger. If we learn that an account belongs to someone under 18, we will close it and delete its data.

QR codes live in the physical world, and a code printed on a poster can be scanned by anyone, including minors. Scan data is never knowingly linked to a scanner's identity, and the same minimization applies to every scan regardless of who made it: no raw IP storage, keyed fingerprints only.

17. Changes to This Policy

We will update this policy as the product and the law evolve. The "Last updated" date at the top always reflects the current version.

For material changes — anything that meaningfully expands what we collect or how we use it — we will give you at least 30 days' notice by email or in-product notice before the change takes effect. Continuing to use the service after the notice period means you accept the updated policy.

18. Contact Us

Questions about this policy or about your data are welcome:

  • Privacy questions and data-rights requests: privacy@barcodesqr.com
  • General support: help@barcodesqr.com
  • Post: [LEGAL ENTITY NAME], [REGISTERED ADDRESS]

privacy@barcodesqr.com is the fastest route for anything involving your personal information; the support address covers everything else.