Privacy Policy

How we handle your data

Last updated: June 2026

This policy explains what information qrcode.io ("we", "us") collects when you use our QR code generator, why we collect it, and the choices you have. The short version: static QR codes can be created without an account and without giving us any personal information; if you create an account or use dynamic QR codes, we collect what's described below and nothing more.

Information you give us

Account details. When you sign up we store your name, email address, and a hashed password. We never store passwords in plain text.

QR code content. The links, text, contact details, Wi-Fi names, or other content you encode in QR codes created while signed in are stored so you can manage and edit them. Static codes created without an account are generated in your session and are not tied to an identity.

Payment details. Paid plans are processed by Stripe. Your card number goes directly to Stripe and never touches our servers; we store only the subscription status, plan, and billing history Stripe reports back.

Support email. If you write to us, we keep the correspondence so we can answer you and recognize repeat issues.

Information collected automatically

Scan analytics (dynamic QR codes only). When someone scans a dynamic QR code, we record the time of the scan, the device type, operating system and browser, and an approximate location (city level) derived from the IP address using a local geolocation database. This is the analytics product that dynamic-plan customers pay for. We do not build profiles of people who scan codes, and we do not sell scan data.

Technical logs. Like every website, our servers and our CDN/security provider (Cloudflare) keep short-lived request logs (IP address, URL, user agent) used for security, abuse prevention, and debugging.

Cookies

We use cookies that are necessary for the site to work (your session, security tokens, and your cookie-banner choice). We also use Google Analytics to understand aggregate site traffic — how many people visit and which pages they use. It sets its own cookies; the statistics we see are aggregated, not tied to your account.

How we use information

To provide the service (generate codes, redirect dynamic codes, show scan statistics), to bill subscriptions, to answer support requests, to keep the service secure, and to send transactional email such as receipts and password resets through our email delivery provider. We do not send marketing email unless you opt in, and we do not sell personal data to anyone.

Who we share data with

Only the processors needed to run the service: Stripe (payments), our hosting provider (DigitalOcean), Cloudflare (CDN and security), and our transactional email provider. Each receives only what it needs to do its job. We disclose data beyond that only if the law requires it.

How long we keep it

Account data and QR codes are kept while your account exists. Scan statistics for a dynamic QR code are kept for as long as the code exists, so your analytics history stays complete. If you delete your account, we delete the data associated with it within 30 days, except records we must keep for tax or accounting reasons.

Your rights

You can ask us for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. Depending on where you live (for example the EU/EEA, UK, or California) you may have additional statutory rights. Email us at the address below and we will respond within 30 days.

Children

qrcode.io is not directed at children under 16 and we do not knowingly collect their data.

Changes

If we change this policy we will update this page and the date at the top. Material changes will be announced to account holders by email.

Contact

Questions about privacy or your data, or any request about the rights above: [email protected]. We answer every message.