Privacy Policy

Last updated

This policy describes what QRFlowy stores, why, and for how long. It is written to be specific rather than exhaustive: where a general policy would say “we may collect device information”, this one says which field, in which table, and when it is deleted.

Two things are worth reading even if you read nothing else. A static QR code is generated entirely in your browser and its content never reaches our servers. And no scan of any QR code ever records an IP address.

The free generator stores nothing

When you create a static QR code on this site, the encoding, the rendering, the logo you add and every download happen in your browser. The content you type, the image and the logo are never uploaded. We do not know what you made.

There is one exception, and it only happens if you ask for it: if you choose “Send it to my e-mail”, we store your e-mail address and the code so we can send it, and we keep the download link for seven days. That is described under “E-mail addresses” below.

Scans of a dynamic QR code

A dynamic QR code points at our redirect service, which sends the visitor on to your destination. To count that scan we record:

When
The time of the scan.
Which code
The identifier of your QR code and its campaign.
Country and region
As reported by our network provider. Never a precise location.
Device kind, operating system, browser
Derived from the user-agent — for example “iOS, Safari, mobile”.
Referrer
The site the visitor came from, where one is sent.

We do not store the visitor's IP address, and we do not set a cookie on them. To tell a repeat scan from a new visitor without identifying anyone, we compute a one-way hash from the date, the code, the IP address and the user-agent, using a secret key, and keep only the first 16 characters of it. The IP address itself is discarded immediately and never written anywhere. Because the date is part of the hash, the value changes every day and cannot be used to follow anyone over time.

Individual scan records are kept for 90 days. Daily totals — scans and unique scans per code, per country, per device — are kept for as long as your account exists, because they are what your analytics show.

Your account

If you create an account we store your name, your e-mail address, and a hash of your password. We never store the password itself. If you sign in with Google we store the identifier Google gives us and your e-mail address, and no password at all.

We set a cookie to keep you signed in. It is required for the product to work and is not used for advertising or analytics. We do not use any third-party analytics or advertising scripts on this site.

We also keep a record of significant actions in your workspace — who changed a destination, who invited whom — so that you can see what happened and so we can investigate abuse.

E-mail addresses

We send two kinds of e-mail and keep them separate. Transactional e-mail — confirming your address, resetting your password, delivering a QR code you asked for, inviting you to a workspace — is sent because you asked for it or because it is necessary to run your account.

Marketing e-mail is sent only if you tick the box that says so. We store the fact that you consented, when, on which page, and the exact wording of the checkbox you agreed to, so that the record is meaningful rather than a claim. You can unsubscribe from any marketing e-mail, and doing so does not affect transactional e-mail.

Payments

Payments are handled by Stripe. Card details are entered on Stripe's own pages and never reach us — we store an identifier for your customer record, which plan you are on, and when the current period ends. We cannot see your card number.

Who else processes this data

Cloudflare
Hosting, database, storage and the network the redirect runs on.
Stripe
Payments and billing.
Loops
Sending transactional and marketing e-mail.
Google
Only if you choose to sign in with a Google account.

We do not sell personal data, and we do not share it for advertising. We are not in the business of knowing who scanned your code, and the product is deliberately built so that we cannot be.

Your rights

You can ask us for a copy of the data we hold about you, ask us to correct it, or ask us to delete it. Deleting your account removes your workspace, your codes and your account record. Write to support@qrflowy.com and we will answer.

Deleting your account stops your dynamic QR codes from resolving. If you have printed them, tell us and we will discuss how to keep them working — that is the whole point of the product, and we would rather not surprise you with it. Cancelling a paid plan, by contrast, never stops a code from redirecting; see the Terms.

Changes and contact

If we change this policy we will change the date at the top. If a change is significant — new data, a new processor, a longer retention period — we will tell account holders by e-mail rather than quietly editing the page.

Questions, requests or complaints: support@qrflowy.com.