Privacy Policy
This policy explains what we collect, how we use and protect it, and the rights you can exercise.
1. What we collect
Account information: the email and name you give when registering, plus the language preference you set. When you change your password we record the time of the change, but we never store your password in clear text — only an irreversible derived value.
Content you create: QR code names, types, content fields, appearance settings, folders and design templates, along with any media files you upload to use the service.
Scan data: when someone scans one of your dynamic codes, we record the time of that scan, the country/region/city resolved from an offline geolocation database or a CDN request header, the device and operating system resolved from the browser identifier, and the hashed IP described below.
Channel attribution data: when you reach the site through a link carrying campaign parameters (an ad or a partner link, for instance) and register, we record the source identifiers those links carry — the campaign parameters (five utm_* values), ad platform click identifiers (gclid / fbclid / msclkid / ttclid), a referral code, plus the source page host and the first path visited. We also keep these identifiers in your browser’s local storage until you register successfully.
Forms you submit: the name, email, subject, message body and report type submitted through the contact or abuse form.
2. IP addresses and hashing
We do not store the raw IP address of anyone who scans. While the scan request is handled, the IP is converted on the spot into a keyed HMAC-SHA256 hash (a fixed-length hexadecimal string) and only then written to the database; the key is derived from a server-side secret and is not stored alongside the data. The hash cannot be reversed back to the original IP.
That hash has exactly one purpose: deciding whether "the same source appears on the same day", which is the deduplicated count of unique scans. We do not use it to trace anyone back, nor for advertising profiles.
Channel attribution data likewise stores no raw IP address and generates no visitor identifier: we use no third-party analytics script or advertising pixel, set no tracking cookie, and cannot link the same person’s visits across devices or browsers.
Geographic information comes from an offline geolocation database or from a CDN request header (such as a country field). Where none is configured or nothing can be resolved, that scan’s region is counted as "unknown", without affecting the other analytics dimensions.
3. Retention
Scan detail records are kept for 90 days by default and then cleaned up by a background task according to the retention policy; that period is configurable by operations.
Daily aggregates (totals of counts, regions and devices) are kept long term — aggregates contain no IP hash and nothing that can be traced back to a single scan, and serve only to show trends on your analytics and overview pages.
Channel attribution data is kept for the lifetime of your account and cleaned up when the account is closed. An account keeps only the first source record (first-touch attribution); later visits do not overwrite it.
You can export your own analytics as CSV.
4. How we use this information
To provide and maintain the service: generating and resolving QR codes, rendering landing pages, showing analytics, and managing your account and subscription.
To understand where customers come from: aggregating channel data by source, medium, campaign and referral code so we can tell which channels work. The result appears in the operations console as counts and channel labels, never as one account’s source detail.
For security and abuse handling: spotting anomalous traffic, rate limiting, and investigating reported short links.
To communicate: replying to messages you submit through the contact or abuse form. Where an operations mailbox is configured, those submissions are sent there as plain-text notifications with the same content you entered in the form.
We do not sell your personal information, nor use it for purposes this policy does not describe.
5. Cookies and local storage
Your sign-in state is kept as a token in your browser’s local storage so that a page refresh keeps you signed in; we use no third-party advertising cookies.
The channel source identifier is also kept in your browser’s local storage (under the key `qrhub.attribution`) and cleared once you register successfully. It is first-party storage, unreadable by anyone but us. Clearing your browser storage removes it yourself, at the cost of losing this visit’s source.
If you clear your browser storage, your sign-in state is lost and you will need to sign in again.
6. Your rights
You can review and edit your details, export your analytics, and delete QR codes and media you created, at any time in account settings.
You can export your account data yourself in account settings (codes, landing pages, aggregated statistics and billing records), and you can also close your account yourself: it then enters a 7-day grace period that you can cancel at any time, after which the account and its data are deleted. To access or correct any other data, write to us through the contact page.
7. Changes to this policy
This policy is updated as features and compliance requirements change. Material changes to what is collected or how it is used are announced before they take effect, in the app or by email.