Privacy
This policy explains what this service records, why, who else handles it, how long it is kept, and how you can have it corrected, exported or deleted.
What a scan records
When someone scans one of your codes, the following is recorded against that code. It is what you see in your dashboard.
- Time of the scan
- To the second.
- Country and city
- Derived from the request, at city level only.
- Device type
- Phone, tablet or desktop. Not a device identifier.
- Referrer
- Where the scan came from, when the scanning app sends it.
- A salted hash of the IP address
- The original IP address is not stored in the scan record. The hash is used only to count repeat scans.
The scan record does not include the name, email or account of the person scanning. The redirect sets no cookie and loads no third-party analytics. Our hosting provider also keeps standard request logs, described below.
Cookies
This site does not currently load Google Analytics or show a cookie banner. It sets only these cookies:
- sb-<project>-auth-token
- Keeps you signed in. Strictly necessary: without it you cannot use an account. Up to 400 days, renewed while you use the app, and removed when you sign out.
- qr-password-recovery
- Allows a password reset after a recovery link has been verified. Strictly necessary. Up to 10 minutes, and removed once the password is changed.
- tz
- Your timezone, set when you open your dashboard, so dates show in your local time. It holds no identifier. One year.
Who else processes your data
- Supabase: Database, sign-in and file storage
- Your account email, your codes, and the scan records described above.
- Vercel: Hosting and website statistics
- Standard request logs, including the IP address and browser type of each request, plus Vercel Web Analytics on the website pages: page views and referrer, with no cookie and no persistent identifier. It is not loaded on the scan redirect or on sign-in links.
- Stripe: Payments, for Pro subscriptions only
- Card details go to Stripe directly and never reach this service. We keep the customer and subscription ids, the subscription status and billing period, and the records needed to manage payments.
- Google (Gemini): Suggested campaign tags, only when you press the button
- The sentence you type, plus the destination URL and code name if set. Nothing is sent on any other action.
- Resend: Sends the monthly summary email to Pro accounts that have not switched it off
- Your account email, the subject and the message body (the same sentences as your dashboard, including the names you gave your codes), and delivery events such as sent or bounced, kept in Resend's email log. The message carries no tracking pixel and no click tracking.
What this service does not do
- No advertising tracking on scans. No advertising identifier, no cross-site profile and no cookie on the redirect. Scans are counted, and a pseudonymous identifier recognises repeat scans.
- No raw IP addresses in scan records. An IP address is turned into a salted hash so repeat scans can be counted. The original address is not stored in the scan record.
- Nothing sold or shared for advertising. Your codes, destinations and scan data are not sold, rented or given to an advertising network.
- No advertising page on a scan. A website code goes straight to its destination.
Why we may process it
Under Article 6 of the GDPR, each use described above relies on one of these legal bases.
- Contract, Article 6(1)(b) GDPR
- Your account, your codes and their destinations, and your subscription, which the service cannot be provided without. If you act for an organisation that is the customer, your contact and account details are processed on the basis of legitimate interests in managing that relationship.
- Legitimate interests, Article 6(1)(f) GDPR
- Recording scans so the owner of a code can see how it performs, and protecting the service against abuse with request limits and a pseudonymous identifier derived from the IP address. We keep this to what is needed for those purposes, and a scan redirect sets no cookie.
- Legal obligation, Article 6(1)(c) GDPR
- Invoices and payment records, which accounting and tax law require us to keep.
How long it is kept
- Codes and destinations: until you delete them. They are not removed after a set time, because a printed code that stops working is the failure this product exists to prevent. When you close your account and choose to keep your codes working, the destinations needed for the redirect are kept.
- Scan records: kept while the code exists. Deleting a code, or closing your account, deletes its scan detail.
- Billing records: kept for as long as accounting and tax law require, which can be longer than the account exists.
Your rights, and getting your data out
Every account can export a complete JSON backup of its codes at any time, on any plan, from Settings. No plan and no ended subscription blocks it.
Closing your account asks a separate question: whether the codes you have printed should keep working or be destroyed. If you keep them, your account and the scan detail are erased, and the short links keep redirecting. The destination addresses remain, so remove any personal information from them first. Records the law requires us to keep, such as invoices, are kept for the legal period. If you destroy the codes, this cannot be undone and every printed code stops working.
Under the conditions set by the GDPR, you have the right of access, rectification, erasure, restriction of processing and data portability, and the right to object. This service makes no decision based solely on automated processing that has legal or similarly significant effects on you. To use any of these rights, write to the address below, whether or not you have an account. You receive an answer within one month; if the law allows an extension for a complex request, you are told why within that month. You can also complain to the data protection authority where you live or work. In Romania that is ANSPDCP.
- Privacy requests: support@qrsteady.com
Security
Data is encrypted in transit and at rest by the providers listed above. Access controls are designed so that one account cannot read another account's data. Account passwords pass through this service only to sign you in or change them, and are stored in hashed form by the sign-in provider. A Wi-Fi password you add to a code is stored with that code and shown to the people who scan it.
No service can guarantee that a breach will never happen. What this service does is keep very little about the person scanning a code, so a breach would expose less.
Where data is held, and children
Account and scan data are stored in the European Union. Where a provider listed above processes data outside the European Economic Area, the transfer relies on an adequacy decision or on the European Commission's standard contractual clauses. You can ask for a copy of those safeguards at the privacy address above.
This service is not intended for children under 16, who should not create an account. Scanning a printed code produces the scan record described above, whatever the age of the person scanning.
Changes to this policy
If what is collected changes, this page is updated and account holders are told by email before the change takes effect.
Who operates this service
This service is run jointly by the two companies below, which act as joint data controllers. Their legal details will appear here once they are final. Until then, write to the contact address below.
- Company
- nVision Data Solutions
- Legal name
- [to be published]
- Registered office
- [to be published]
- Registration number
- [to be published]
- Fiscal code (CUI)
- [to be published]
- Company
- Stamiteki
- Legal name
- [to be published]
- Registered office
- [to be published]
- Registration number
- [to be published]
- Fiscal code (CUI)
- [to be published]
Contact: support@qrsteady.com