Privacy Policy
1. Scope
This policy explains how QR Inspector handles information when you visit qr-inspector.com, create or manage an account, make a QR code, purchase a product, or scan a tracked QR code. “QR Inspector,” “we,” and “us” refer to the operator of the service.
2. Information we handle
Account information
When you create an account, we store your email address, display name, username, a password hash, timezone, account status, and subscription state. We also retain login counters, the time of your last login, and the IP address used for that login for account security and abuse prevention. We do not store your plaintext password.
QR code information
We store the destination URL, title, selected colors, owner, creation date, active status, and aggregate scan count needed to generate, redirect, and manage each dynamic QR code.
QR scan information
A scan of a tracked QR code records the scan time, user agent, derived device/browser/operating-system categories, approximate city or country when available, and an estimated unique-scan flag. This information powers the scan reports shown to the QR code owner. A person can scan a QR code without creating a QR Inspector account.
We do not store the scanner's IP address. The address is used while the request is being handled — to look up an approximate location, and to work out whether this is a repeat scan of the same code — and is then discarded. What we keep in its place is:
- a keyed hash of the address and user agent together, computed with a secret key that we never publish and never change. It lets us recognise a repeat scan of the same QR code without holding the address, and it cannot be reversed or guessed by anyone who does not have the key; and
- a truncated network address — the first three parts of an IPv4 address, or the first 48 bits of an IPv6 one — which identifies roughly an area or an internet provider rather than a device, and which we keep so we can investigate abuse of a QR code.
QR code owners see the truncated network in their scan reports and exports. They never see the scanner's address, because we do not have it.
Approximate location is obtained by sending the address to the IP geolocation providers named in section 6 at the moment of the scan. It may be inaccurate.
Payment information
Stripe processes card and other payment details. QR Inspector does not receive or store complete card numbers. We store transaction identifiers, Stripe customer identifiers where applicable, amount, currency, payment status, discounts or credits used, and subscription state so we can provide purchases, prevent replay, and maintain payment history.
Operational and security information
Our servers record request, error, authentication, and audit logs. We use these records to keep the service available, diagnose faults, enforce limits, and investigate suspected abuse or security incidents.
These logs contain the IP address used for account actions — signing in, registering, and managing QR codes — because that address is part of protecting the account it belongs to. Audit entries written for a scan follow the rule above instead: they record the truncated network, never the scanner's address.
3. Cookies and optional Google measurement
Essential cookies
QR Inspector uses first-party session, sign-in, CSRF-protection, and preference cookies. These are necessary for account and security features. The analytics preference itself is stored in a first-party cookie for up to 180 days.
Google Analytics and Ads measurement
On the canonical production website, Google measurement code loads only after you choose Allow measurement. Google Analytics and a connected Google Ads destination help us understand page usage, ad results, and product steps such as account creation, QR creation, checkout, and verified purchases. The integration sends a general route category and referring-site origin instead of the full page URL or query string. It is designed not to send names, email addresses, QR destinations, or QR code identifiers. Advertising storage, advertising user data, advertising personalization, and Google signals remain disabled, and advertising identifiers are redacted. Google may still receive a cookieless, non-personalized measurement request after you opt in.
Choose Measurement preferences in the site footer at any time to change your choice. Selecting Essential only stops new optional measurement events and removes accessible Google analytics cookies for this site. You can also clear cookies in your browser.
4. Why we use information
We use the information described above to:
- create accounts and provide QR generation, redirects, reports, and billing;
- authenticate users, prevent fraud and abuse, and secure the service;
- answer support requests and send service-related notices;
- maintain, troubleshoot, and improve the product; and
- meet tax, accounting, legal, and dispute-resolution obligations.
Depending on where you live, these uses may rely on performance of our agreement with you, our legitimate interests in operating and securing the service, compliance with law, or your consent. You can withdraw optional measurement consent at any time.
5. When information is shared
We do not sell personal information. We disclose only what a provider needs in order to do its job; section 6 names every one of them and says what each one touches.
We may also disclose information when reasonably necessary to comply with law, protect users or the service, investigate fraud or security issues, enforce our terms, or complete a business transaction such as a merger or asset transfer. QR owners can see the scan analytics associated with QR codes they control.
6. Service providers
These are the companies that process information on our behalf, and what each of them touches. They handle it under their own terms and privacy obligations.
- DigitalOcean — hosting. The servers and the database the application runs on, so in principle everything described in this policy rests on their infrastructure.
- Cloudflare — DNS and traffic protection. Sees the network requests reaching the site, including visitor and scanner IP addresses in transit, before they arrive with us.
- Stripe — payments and subscriptions. Receives your card and billing details directly; we never see complete card numbers. We exchange transaction and customer identifiers, amounts, and subscription status with Stripe.
- Resend — transactional email. Receives your email address and the contents of messages we send you, such as address confirmations and password resets.
- ipapi.co and ipinfo.io — IP geolocation. At the moment of a scan we send the scanner's IP address to one of these providers to obtain an approximate city or country. We store what comes back, not what we sent.
- Google (Analytics and Ads) — optional website measurement, and only after you choose Allow measurement. Receives page-usage measurement as described in section 3. It is not used on the QR scan redirect, so scanning a code involves Google not at all.
- Google reCAPTCHA — anti-abuse. Shown on sign-in and registration when a request looks risky; Google receives the information needed to score the challenge.
We do not sell personal information and we do not share it with advertisers or data brokers. If we add a provider that handles personal information, we will update this section.
7. Retention and security
How long each kind of record is kept:
- Account information — for as long as the account exists. Deleting your account removes it immediately; see section 8.
- QR codes — for as long as the account that owns them exists, because a dynamic QR code has to keep resolving for as long as it is printed on something.
- Scan records — up to 400 days (about thirteen months), so an owner can compare a season against the same season a year earlier. Older scan records are deleted.
- Security and audit logs — up to 90 days.
- Payment records — kept for as long as tax, accounting and dispute-resolution law requires, which is longer than any of the above and is not something we can shorten on request. When an account is deleted these records stay, with the reference to the person removed.
Limited copies may persist in backups until those backups age out on their normal schedule.
We use technical and organizational safeguards such as encrypted transport, password hashing, access controls, CSRF protection, and payment verification. No internet service can guarantee absolute security, so please use a unique password and tell us promptly if you suspect unauthorized access.
8. Your choices and rights
Two of these you can exercise yourself, immediately, from your profile page — you do not need to ask us and we do not need to approve it.
- Download your data. Profile → Download my data produces a JSON file containing your account record, every QR code you own, the scan history for those codes, and your payment history.
- Delete your account. Profile → Delete my account, confirmed with your password, cancels any subscription and then erases your account, your QR codes, and their scan history. Payment records are kept with your name removed from them, because tax law requires the transaction to stay on the books. This cannot be undone, and any printed codes you own stop working straight away.
You can also update your profile information in your account and change optional measurement consent from the footer. For correction, or for anything the buttons above do not cover, contact us. We may need to verify your identity, and we may retain information where law or a legitimate security, payment, or dispute need requires it.
Privacy rights differ by location. Where applicable, you may also have rights to object to or restrict processing, withdraw consent, or appeal a decision. You may complain to your local data protection authority. We will not discriminate against you for exercising a privacy right.
9. International processing and children
QR Inspector and its providers may process information in countries other than your own. Privacy laws in those locations may differ. We use the service only for people able to form a binding agreement under applicable law, and it is not directed to children under 13. If you believe a child provided personal information, contact us so we can investigate and delete it where appropriate.
10. Changes to this policy
We may update this policy as the product or legal requirements change. We will post the revised version here and change the date above. If a change is material, we will provide additional notice when reasonably appropriate.
11. Contact us
Questions, privacy requests, or concerns can be sent to:
Email: hello@qr-inspector.com