QRHub
QR generatorFeaturesPricingResourcesFAQ
Sign inStart creating

Legal

Privacy PolicyTerms of ServiceRefund Policy

Other

DisclaimerReport abuseCancellation

Data & use

Acceptable useData processing (DPA)Subprocessors

Data processing (DPA)

Operator:qrhub operator

Effective date:Sep 27, 2026

Last updated:Sep 27, 2026

Contact:/contact

What qrhub processes on your behalf, why, for how long, and how the related requests are handled.

1. What this page is

This page explains what qrhub processes as a processor acting on your behalf as controller, why it is processed, how long it is kept, and which third-party services are involved.

It is not a signed contract in itself. If you need a signable version (with both parties, signature blocks and governing law), ask through the contact page and we will issue a countersignable text under your organisation’s name.

2. Scope and purpose

Data categories: account identifiers (email, name, language preference); the QR code records you create (name, type, content fields, appearance settings, folders and design templates); assets you upload; dynamic-code scan events (time, resolved country/region/city, device and operating system, and the pseudonymous identifier described in section 3); and what you submit through the contact and abuse forms.

Purposes: providing and maintaining QR code generation, resolution, landing page rendering and scan analytics; keeping the Service secure (rate limiting, anomalous traffic detection, investigating reported short links); replying to your enquiries and tickets.

Not used for: advertising profiles, cross-site tracking, or selling or sharing personal information with third parties. The Service sets no tracking cookies on the scanner’s side.

3. Security measures

Raw scanner IP addresses are not stored: a request is immediately converted to a keyed HMAC-SHA256 hash before it is written, the key is derived from a server secret and never stored alongside the data, and the hash is used only to tell whether two scans on the same day came from the same source.

Sign-in state is kept as a token in browser local storage; passwords are stored only as an irreversible derived value, never in plain text.

Operations-side actions (permission changes, content review, enforcement decisions) are recorded in an audit trail; form submissions are protected by human verification and rate limits.

Access on the operations side follows least privilege, and the admin API is authenticated separately from user data endpoints.

4. Retention and deletion

Scan detail records are kept for 90 days by default and then cleaned up by a background task according to the retention policy; that period is configurable by operations.

Daily aggregates are kept long term, but contain no IP hash and nothing that can be traced back to a single scan.

You can export your account data yourself in account settings (codes, landing pages, aggregated statistics and billing records), and delete QR codes and media you created. Closing your account starts a 7-day grace period, after which the account and its data are deleted; audit trails required by law are retained.

5. Subprocessors and transfers

The Service relies on a small number of third-party services (such as human verification and content delivery). Their purpose, processing location and notification procedure are listed on the Subprocessors page.

That page is updated before a subprocessor is added or replaced, and you can request the current list through the contact page.

6. Data subject requests

Scanners are not registered users of the Service; their requests (access, erasure) come to us through you or directly. We help once the request is verified as reasonable.

For data under your account, use the export and closure capabilities in account settings. For anything else, write through the contact page with the account email and what you need.

7. Changes

When the scope, security measures or retention periods change materially, this page is updated and the change is announced before it takes effect, in the app or by email.

Ask through the contact page if you need a historical version that records when each change took effect.

Return to the website

Cookie preferences

Choose the preferences that feel right for you.

Manage preferences
QRHub

QR code generation and management by the qrhub operations team

Product

QR generatorDynamic QRFeaturesPricing

Resources

BlogFAQAPI DocsDesign templates

Company & support

AboutContact usMy workspacePage directory

Legal

Privacy PolicyTerms of ServiceRefund PolicyDisclaimerReport abuseCancellationAcceptable useData processing (DPA)Subprocessors
© qrhub · qrhub operations teamProduction QR code generation, management and short-link services.