Subprocessors
The categories of third-party services qrhub uses, and the purpose, data and processing location of each.
1. What this page covers
This page lists the categories of third-party services used to run qrhub, with the purpose, data and processing location of each.
Individual provider names and contract status are not published here. Ask through the contact page and we will provide the current list and the relevant terms for your review process.
2. Human verification and security
Purpose: telling humans from bots on registration, sign-in, password recovery and the contact and abuse forms, to hold back bulk registration and automated abuse.
Data: the technical signals used for the challenge (browser and network characteristics, challenge outcome). The service sets no advertising cookies and is not used for cross-site tracking.
Location: processed on that provider’s global edge nodes; we store only the verification outcome, not the raw challenge signals.
When the live widget is not enabled, forms run a local simulation and make no external request.
3. Email delivery
Purpose: sending transactional mail such as email verification, password resets, subscription expiry notices and ticket replies.
Data: the recipient address, the subject and the context the message needs (such as a QR code name or expiry date). No marketing mail is sent, and scan details are never handed to this provider.
Location: relayed by the delivery service in its own region; we keep delivery status and failure reasons for retries and troubleshooting.
4. Static assets and content delivery
Purpose: delivering the frontend build, landing page assets and QR images so scan latency does not depend on the visitor’s region.
Data: request path, time and network-layer information in access logs. Landing page rendering and QR image generation happen inside our own service; assets are not handed to a third party for processing.
Location: served by the nearest node of the content delivery network.
5. Analytics posture
Scan analytics run inside our own service: scan events are written and aggregated daily, with no third-party analytics script and no advertising pixel.
Scan data is therefore never handed to a third-party analytics provider; every number in the charts comes from our database.
6. Payments and subscriptions
No payment gateway is connected today: subscriptions are opened and renewed by the operations team after a request, so there is no payment subprocessor.
If a payment service is added, this page will be updated before it takes effect, describing the billing data involved and where it is processed.
7. Change notice
This page is updated before a subprocessor is added or replaced; changes that affect the data we hold about you are announced before they take effect, in the app or by email.
You can opt into these notices: add a contact address in account settings, or say through the contact page that you want to receive change notices.
Return to the website