Privacy Policy
Effective Date: June 9, 2026
Last Updated: June 9, 2026
1. Introduction
Easy QR Codes ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, applications, and services (collectively, the "Service").
This Privacy Policy applies to all users of the Service and is designed to comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.
By using the Service, you consent to the data practices described in this Privacy Policy. If you do not agree with the practices described here, please do not use the Service.
We encourage you to read this Privacy Policy carefully to understand our practices regarding your personal information.
2. Information We Collect
2.1 Information You Provide to Us
We collect information you voluntarily provide when you:
- Create an Account: Name, email address, password, and optional profile information.
- Subscribe to a Plan: Billing information, payment card details (processed by our payment processor), and billing address.
- Create QR Codes: URLs, text content, and any other data you include in your QR codes.
- Contact Us: Information you provide when you contact our support team or communicate with us.
- Participate in Surveys: Responses to surveys, feedback forms, or promotional activities.
2.2 Information Collected Automatically
When you access the Service, we automatically collect certain information, including:
- Device Information: Device type, operating system, browser type, and unique device identifiers.
- Log Data: IP address, access times, pages viewed, referring URL, and other usage statistics.
- QR Code Scan Data: When someone scans your QR codes, we collect scan location (country/city level), device type, browser, scan time, and referrer information. For customers on plans that include device analytics, we additionally collect a non-identifying technical fingerprint of the scanning device via a brief interstitial page. A coarse set of low-entropy device-class signals is collected by default; a set of four additional high-entropy fields is collected only after the scanner has explicitly consented, in any region — see QR Code Scan Telemetry for the full field list, tier breakdown, and consent model.
- Cookies and Similar Technologies: We use cookies, web beacons, and similar technologies to collect information about your browsing activities.
2.3 Information from Third Parties
We may receive information about you from third parties, including:
- Social Login Providers: If you sign in using Google, GitHub, or other social login providers, we receive your basic profile information.
- Analytics Providers: We receive aggregated analytics data from our analytics partners.
- Business Partners: If you are referred to us by a partner, we may receive limited information about you.
QR Code Scan Telemetry
When a visitor scans a QR code generated by Easy QR Codes, we redirect them through go.easyqrcodes.app before forwarding them to the destination URL. This brief redirect (typically under 500 ms) lets us record the scan and, for customers whose plan includes device analytics, collect a non-identifying technical fingerprint of the scanning device. This section explains exactly what is collected, when, and on what legal basis.
What we collect on every scan
These server-side fields are recorded for every scan, independent of the interstitial:
- Timestamp (UTC): from our server clock, for chronology and retention.
- Truncated, daily-salted IP hash: for uniqueness and rate limiting. The raw IP address is discarded after hashing and is never stored.
- Country / region / city: derived from MaxMind GeoLite2, for geographic breakdowns.
- Device / browser / operating system: derived from the
User-Agentheader. - Referrer: from the
Refererheader, if sent, for traffic-source analytics. - QR code identifier: from the URL path, to attribute the scan to its owner.
What we additionally collect on the interstitial (two tiers)
Coarse tier — the default for all scanners in every region, including non-EU scanners who have made no consent decision and EU scanners while the consent banner is pending. These are low-entropy, device-class signals:
- Timezone (IANA), from the browser's internationalization API.
- Primary language preference.
- Connection type (e.g. 3g / 4g / wifi), where the browser exposes it.
- Screen width and height.
- Approximate device memory and hardware concurrency (CPU cores).
- Touch support and pointer type.
- WebGL vendor (a coarse GPU-class bucket).
- Do Not Track signal, so we can honor it.
Full tier — collected only when the scanner has explicitly clicked Accept (setting an easyqr_consent=accept cookie), in any region. The full tier is the coarse set above plus these four higher-entropy fields:
- Canvas fingerprint hash: a one-way integer derived from rendering a small canvas; used for probabilistic uniqueness. It is not reversible to the device it came from.
- WebGL renderer (full detail): the GPU/driver string.
- Battery level and charging state: where the browser makes them available.
Our server independently enforces this boundary: even if a client payload includes the four high-entropy fields, the server discards them unless the request carries an explicit easyqr_consent=accept cookie with no DNT or Sec-GPC override.
Non-EU scanners are not shown the consent banner; they receive coarse collection silently and reach the full tier only if they carry a prior accept cookie (for example, from consenting at an earlier EU-detected scan on the same device). Scanners we detect as likely located in the EU, EEA, UK, or Switzerland are shown the banner before any interstitial runs; accepting upgrades them to the full tier.
What we never collect on scans
- Name, email address, phone number, postal address, or any other contact information.
- Scanner account credentials — scanners do not need to be signed in.
- Browsing history outside the scan itself.
- Contents of the device (files, photos, messages, contacts).
- Continuous tracking — the interstitial fires once per scan, and no persistent scanner identifier is stored on-device beyond the optional consent cookie.
Consent model (EU / EEA / UK / Switzerland)
We detect whether a scanner is likely in the EU / EEA / UK / Switzerland using a multi-signal score (IP geolocation, edge-provider country header, browser language, and client-side IANA timezone). Any one strong signal triggers the consent banner. When the banner is shown:
- Clicking Reject sets the
easyqr_consent=rejectcookie (Lax, 12-month lifetime) and proceeds directly to the destination URL. Only the minimal server-side scan event described above is recorded; no fingerprint is collected. - Clicking Accept sets the
easyqr_consent=acceptcookie and proceeds to the interstitial. Consent applies across all QR codes scanned from the same device within the 12-month cookie lifetime and can be cleared from browser settings at any time. - If a scanner takes no action, no cookie is set and the banner is shown again on future scans.
Legal basis for processing
- Full tier (four high-entropy fields), any region: explicit consent under GDPR Art. 6(1)(a) and ePrivacy Directive Art. 5(3), given by clicking Accept. This basis applies universally, not only to EU scanners, because the gated fields are consent-only in every region. Consent is freely given (rejection and no-action preserve full access to the destination), specific, informed, and unambiguous.
- Coarse tier, EU / EEA / UK / CH scanners who click Accept: covered by the same explicit consent.
- Coarse tier, EU / EEA / UK / CH scanners who reject or take no action: the coarse interstitial does not run before consent is decided; only the minimal server-side scan event is recorded, on the basis of legitimate interests under GDPR Art. 6(1)(f) (preventing abuse, measuring aggregate traffic).
- Coarse tier, non-EU scanners (no prior decision): legitimate interests under GDPR Art. 6(1)(f) where applicable, and the analogous basis in other jurisdictions. Only low-entropy device-class signals are collected on this basis.
- Global opt-out signals: we honor
DNT: 1,Sec-GPC: 1, and the Global Privacy Control on every scan, in every region — no interstitial runs and no fingerprint of any kind is collected.
Retention
- Server-side scan events are retained per the QR owner's plan (Basic: 3 months, Pro: 12 months, Enterprise: 24 months), extendable via the extra-retention add-on (+1 month per unit purchased).
- Fingerprint fields share the retention of the scan event they enrich.
- Raw IP addresses are never stored — only the daily-salted hash.
Scanner rights
Scanners may exercise rights of access, rectification, erasure, and portability by contacting us through our contact form. Because we do not store direct identifiers for scans, please provide either the specific QR URL you scanned with the approximate scan time, or the approximate IP address you scanned from with the date. We use the daily-salted IP hash to locate matching scan rows and honor the request within 30 days.
3. How We Use Information
We use the information we collect to:
3.1 Provide and Maintain the Service
- Create and manage your account.
- Process your transactions and send related information.
- Generate and manage your QR codes.
- Provide analytics and tracking for your QR codes.
- Respond to your inquiries and provide customer support.
3.2 Improve and Personalize the Service
- Understand how users interact with the Service.
- Develop new features and functionality.
- Personalize your experience based on your preferences.
- Conduct research and analysis to improve the Service.
3.3 Communicate with You
- Send administrative information, such as updates to our Terms or Privacy Policy.
- Send marketing communications (with your consent, where required).
- Respond to your comments, questions, and requests.
- Send you technical notices, security alerts, and support messages.
3.4 Ensure Security and Compliance
- Detect, prevent, and address technical issues.
- Protect against fraudulent, unauthorized, or illegal activity.
- Comply with legal obligations and enforce our Terms of Service.
3.5 Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), our legal basis for collecting and using your personal information depends on the specific information and context:
- Performance of a Contract: Processing necessary to provide the Service to you.
- Legitimate Interests: Processing necessary for our legitimate business interests, such as improving the Service.
- Consent: Where you have given us consent for specific processing activities, such as marketing communications.
- Legal Obligation: Processing necessary to comply with applicable laws.
4. Information Sharing
We do not sell your personal information. We may share your information in the following circumstances:
4.1 Service Providers
We share information with third-party service providers who perform services on our behalf, including:
- Payment processors (e.g., Stripe) for billing and payments.
- Cloud hosting providers for data storage.
- Analytics providers to help us understand Service usage.
- Email service providers for communications.
- Customer support tools and services.
Scan events and device-fingerprint fields are stored in our own analytics infrastructure (ClickHouse, hosted on infrastructure we operate). No third-party analytics partner receives scanner fingerprint data.
4.2 Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or uses of your personal information.
4.3 Legal Requirements
We may disclose your information if required to do so by law or in response to:
- Valid legal processes, such as a court order or subpoena.
- Requests from government authorities.
- Protection of our rights, privacy, safety, or property.
- Protection against legal liability.
4.4 With Your Consent
We may share your information with third parties when you have given us your explicit consent to do so.
5. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes for which it was collected and to comply with our legal obligations.
5.1 Account Data
We retain your account data for as long as your account is active. If you delete your account, we will delete or anonymize your personal information within 30 days, except as required by law.
5.2 QR Code Data
QR code content and associated analytics data are retained for as long as your account is active. Upon account deletion, this data will be permanently deleted within 30 days.
5.3 Log Data
Server logs and access logs are retained for up to 90 days for security and troubleshooting purposes.
5.4 Legal Requirements
We may retain certain information for longer periods if required by law, such as for tax, accounting, or legal compliance purposes.
6. Your Rights
6.1 Rights Under GDPR (European Users)
If you are located in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation:
- Right to Access: You have the right to request copies of your personal data.
- Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
- Right to Erasure: You have the right to request that we erase your personal data, under certain conditions.
- Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
- Right to Data Portability: You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.
- Right to Object: You have the right to object to our processing of your personal data, under certain conditions.
- Right to Withdraw Consent: Where we rely on your consent to process your personal data, you have the right to withdraw that consent at any time.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority if you believe we have violated your rights.
6.2 Rights Under CCPA (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act:
- Right to Know: You have the right to request information about the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out: You have the right to opt-out of the sale of your personal information. Note: We do not sell personal information.
- Right to Non-Discrimination: You have the right not to receive discriminatory treatment for exercising your CCPA rights.
6.3 Exercising Your Rights
To exercise any of these rights, please reach out through our contact form. We will respond to your request within the timeframes required by applicable law (generally 30 days for GDPR and 45 days for CCPA).
We may need to verify your identity before processing your request. If we cannot verify your identity, we may request additional information from you.
8. Security
We take the security of your information seriously and implement appropriate technical and organizational measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction.
8.1 Security Measures
Our security measures include:
- Encryption of data in transit using TLS/SSL.
- Encryption of sensitive data at rest.
- Regular security assessments and penetration testing.
- Access controls and authentication requirements.
- Employee training on data protection and security.
- Incident response procedures.
8.2 Your Responsibilities
You are responsible for maintaining the confidentiality of your account credentials. We recommend using a strong, unique password and enabling two-factor authentication when available.
8.3 Data Breach Notification
In the event of a data breach that affects your personal information, we will notify you and any applicable regulatory authorities as required by law.
9. Children's Privacy
The Service is not intended for children under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately.
If we become aware that we have collected personal information from a child under 16 without verification of parental consent, we will take steps to remove that information from our servers.
10. International Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that are different from the laws of your country.
10.1 Transfer Safeguards
When we transfer personal information outside the EEA, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission.
- Adequacy decisions by the European Commission for certain countries.
- Other legally approved transfer mechanisms.
10.2 Data Processing Locations
Our primary data processing facilities are located in the United States. By using the Service, you consent to the transfer of your information to these facilities.
11. Changes to Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons.
When we make material changes to this Privacy Policy, we will:
- Update the "Last Updated" date at the top of this page.
- Notify you via email (if you have an account) or through a prominent notice on the Service.
- Where required by law, obtain your consent before making changes.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of the Service after any changes indicates your acceptance of the updated Privacy Policy.
12. Contact Information
If you have any questions about this Privacy Policy or our data practices, please contact us:
- Contact: Contact Form
- Company: Easy QR Codes
Data Protection Officer
For data protection related inquiries, please contact our Data Protection Officer through our contact form.
Supervisory Authority
If you are located in the EEA and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority.

