Privacy & Cookie Policy
Last updated: June 11, 2026
- 1. Introduction
- 2. Information We Collect
- 3. How We Use Your Information
- 4. Legal Bases for Processing
- 5. Cookies and Local Storage
- 6. When We Share Information
- 7. How Long We Keep Data
- 8. How We Protect Your Information
- 9. International Transfers
- 10. Your Rights
- 11. Account Deletion
- 12. California Privacy Rights (CCPA/CPRA)
- 13. Other US State Privacy Laws
- 14. Other Jurisdictions
- 15. Children's Privacy
- 16. Third-Party Links and Destinations
- 17. Changes to This Policy
- 18. Contact Us
1. Introduction
[LEGAL ENTITY NAME], trading as BarcodesQR ("we", "us", "our"), is the controller responsible for the personal information described in this policy. Our registered address is [REGISTERED ADDRESS]. This policy explains what we collect when you use BarcodesQR.com, why we collect it, who we share it with, and the choices you have.
It applies to everyone the service touches, wherever in the world they are: visitors browsing the site, account holders creating and managing QR codes, and people who scan a code made with BarcodesQR.
We honor the privacy frameworks that apply to you, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA). Where your local law gives you stronger rights than this policy describes, your local law wins.
2. Information We Collect
We collect four groups of information: first, information you give us directly; second, information collected automatically while you use the site; third, scan data generated when someone scans one of your codes; and fourth, information that reaches us through other routes — the email gate, feedback forms, and third-party sign-in. The four groups are itemized below, in that order.
- Account details — the email address you register with and your sign-in credentials.
- Passwords you set on password-protected codes — stored only as salted hashes; we cannot read the original password back, and neither can anyone who obtains the stored value.
- QR content — everything you put into a code or its landing page, including uploaded files, logos, and avatar images.
- Support requests — the messages, attachments, and contact details you include when you ask us for help.
- Device and technical data — browser type and version, operating system, screen size, and language settings.
- Approximate location — a country and region estimate derived from geolocation headers added by our hosting provider; we do not run our own IP-lookup database.
- Usage data — the pages you visit, the features you use, and how you move through the creator and the dashboard.
- Scan events — when someone scans a code you created, we record the timestamp, country, and city of the scan.
- Scanner device profile — the device type, operating system, and browser family of the scanning device.
- Referrer URL — the page the visitor arrived from, when their browser sends one.
- Scan fingerprint — a keyed hash derived from the visitor's IP address and browser characteristics, used only to count unique scans. The raw IP address is not stored, and the hash cannot be recomputed from public inputs without our server-side key.
- Email gate — if you enter an email address before creating an account, we store it as a lead so we can link the codes you made to your account once you register.
- Feedback submissions — ratings and comments that visitors leave on feedback-type codes you run; these are stored against your code and shown in your dashboard.
- Third-party sign-in — if you sign in through an identity provider, we receive the basic profile details that provider shares, typically your name and email address.
3. How We Use Your Information
We use the information above to run the service — nothing more exotic than that. In concrete terms:
- Operating the product — generating your codes, serving dynamic redirects, rendering landing pages, and storing your designs and uploads.
- Analytics for you — turning scan data into the charts, counts, and exports you see in your dashboard.
- Billing — managing your trial, subscription, invoices, and payment state.
- Support — answering your requests and troubleshooting problems on your account.
- Security and abuse prevention — detecting fraudulent codes, malicious destinations, and attempts to break into accounts.
- Service messages — emails about your account, your subscription, or material changes to the service or this policy.
- Legal compliance — keeping records the law requires us to keep and responding to lawful requests.
We do not use your information to build advertising profiles, and we do not sell it.
4. Legal Bases for Processing
Where the GDPR or UK GDPR applies, every use of your data rests on one of four legal bases:
- Contract — most processing happens because it is needed to deliver the service you signed up for: creating codes, redirecting scans, and billing your plan.
- Legitimate interests — securing the platform, preventing abuse, measuring scans on your behalf, and improving the product, always balanced against your rights and expectations.
- Consent — used where the law requires it, for example the email address you volunteer at the email gate before you have an account. You can withdraw consent at any time.
- Legal obligation — retaining billing records for tax law and responding to binding requests from authorities.
7. How Long We Keep Data
We keep personal information only as long as it serves the purpose it was collected for, then delete or anonymize it. As a matter of policy:
- Account data — kept while your account is active, then for 12 months after it closes.
- Scan analytics — kept for 24 months from the date of the scan.
- Billing records — kept for around 7 years, as tax and accounting law requires.
- Support correspondence — kept for 3 years after the request is closed.
- Server and security logs — kept for 12 months.
- Backups — encrypted backups roll off within 90 days.
These periods are stated as policy. A copy of deleted data can persist in backups until those backups expire on the schedule above.
8. How We Protect Your Information
We apply technical and organizational measures appropriate to the data we hold:
- Encryption in transit — all traffic to and from the service uses TLS.
- Password hashing — passwords on protected codes are hashed with scrypt and a per-password salt; we never store them in readable form.
- Keyed scan fingerprints — scan fingerprints are produced with a keyed hash, so they cannot be reversed or recomputed without our server-side secret.
- Access controls — access to production data is restricted to the roles that need it.
No online service can promise perfect security, and we do not. If a breach affects your personal information, we will notify you and the relevant authorities as applicable law requires.
9. International Transfers
Our processors store and process data in the United States. If you use the service from the EU, the UK, or another jurisdiction with transfer rules, your information will move to the US as part of normal operation.
Where the GDPR or UK GDPR requires a transfer mechanism, we rely on the European Commission's Standard Contractual Clauses (with the UK addendum where relevant) with our processors, and we commit to keeping equivalent safeguards in place as processor relationships change.
10. Your Rights
Depending on where you live, you can exercise some or all of the following rights over your personal information:
- Access — get a copy of the data we hold about you.
- Correction — fix inaccurate or incomplete data.
- Deletion — ask us to erase your data.
- Restriction — pause certain processing while a dispute is resolved.
- Objection — object to processing based on legitimate interests.
- Portability — receive your data in a structured, machine-readable format.
- Withdraw consent — where processing rests on consent, withdraw it at any time without affecting what was done before.
To exercise any of these rights, email privacy@barcodesqr.com. We aim to respond within one month; if a request is complex we may extend that period as the law allows, and we will tell you if we do. We may ask you to verify your identity before acting on a request. If you are unhappy with our answer, you can complain to your local data-protection authority.
11. Account Deletion
You can delete your account from the dashboard or by emailing privacy@barcodesqr.com. Deletion is irreversible: your codes, designs, uploads, and analytics are removed and cannot be restored.
Dynamic codes stop redirecting once the account is gone. Anyone scanning a printed code afterwards reaches an error page instead of your destination, so download or migrate anything you still need before deleting.
A small residue survives deletion for the periods listed in the retention section above: billing records that tax law requires, server logs, and backup copies until the backups expire.
12. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the CCPA/CPRA gives you specific rights and entitles you to specific disclosures, set out here.
In the last 12 months we have collected these categories of personal information: identifiers (email address), internet or network activity (usage and scan data), approximate geolocation, commercial information (subscription and billing history), and the content you upload. We collect them from you, from your devices, and from people who scan your codes, for the purposes described in "How We Use Your Information".
- We do not sell personal information and have not sold it in the preceding 12 months.
- We do not share personal information for cross-context behavioral advertising.
- We honor the Global Privacy Control (GPC) signal as a valid opt-out where it applies.
- You may exercise your rights to know, delete, and correct, and you will not be discriminated against — in price, service level, or otherwise — for doing so.
California requests go to privacy@barcodesqr.com. You may use an authorized agent, and we may verify the request before acting on it.
13. Other US State Privacy Laws
Residents of other states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Texas, Oregon, and Utah — have broadly similar rights: to confirm whether we process your data, to access and correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, sale, and profiling used for significant decisions.
Because we do not sell data, run targeted advertising, or profile anyone for significant decisions, the opt-out rights have nothing to act on — but access, correction, deletion, and portability work the same way as everywhere else: email privacy@barcodesqr.com. If we decline a request, you may appeal by replying to our decision; if the appeal also fails, you may contact your state attorney general.
14. Other Jurisdictions
We apply the substance of this policy globally and honor local frameworks where they reach us:
- Canada (PIPEDA) — we process personal information with consent or as PIPEDA otherwise permits, and Canadian users can access and correct their information through the contacts below.
- Brazil (LGPD) — Brazilian users have rights of confirmation, access, correction, anonymization, deletion, and information about sharing; the legal bases we rely on correspond to those recognized by the LGPD.
- Australia (Privacy Act) — we handle personal information consistently with the Australian Privacy Principles, including notification of eligible data breaches.
If your jurisdiction grants rights this policy does not list, contact privacy@barcodesqr.com and we will assess your request under your local law.
15. Children's Privacy
The service is for adults: you must be at least 18 to create an account, and we do not knowingly collect personal information from anyone younger. If we learn that an account belongs to someone under 18, we will close it and delete its data.
QR codes live in the physical world, and a code printed on a poster can be scanned by anyone, including minors. Scan data is never knowingly linked to a scanner's identity, and the same minimization applies to every scan regardless of who made it: no raw IP storage, keyed fingerprints only.
16. Third-Party Links and Destinations
QR codes made with the service point wherever their creators aim them — websites, files, app stores, payment pages. We do not control those destinations, and this policy does not cover them. Once a scan leaves our redirect, the destination's own privacy practices apply.
The same goes for links inside landing pages and for external services a code embeds, such as a hosted video. If you are concerned about what a destination collects, read its policy.
17. Changes to This Policy
We will update this policy as the product and the law evolve. The "Last updated" date at the top always reflects the current version.
For material changes — anything that meaningfully expands what we collect or how we use it — we will give you at least 30 days' notice by email or in-product notice before the change takes effect. Continuing to use the service after the notice period means you accept the updated policy.
18. Contact Us
Questions about this policy or about your data are welcome:
- Privacy questions and data-rights requests: privacy@barcodesqr.com
- General support: help@barcodesqr.com
- Post: [LEGAL ENTITY NAME], [REGISTERED ADDRESS]
privacy@barcodesqr.com is the fastest route for anything involving your personal information; the support address covers everything else.