CodeQR Cookie Policy
Last updated: 2026-07-19. This Cookie Policy explains how CodeQR ("CodeQR", "we" or "us") uses cookies and similar technologies on our website (codeqr.io), in our application (app.codeqr.io) and on the short link and QR code domains that power our customers' campaigns.
What Are Cookies?
Cookies are small text files stored on your device (computer, tablet or smartphone) when you visit a website. They can keep you signed in, remember your preferences and help measure how a site is used.
Consent on Our Website
On codeqr.io we use AdOpt (goadopt.io) as our consent management platform, together with Google Consent Mode v2 with all consent states denied by default. Google Tag Manager (Google Analytics 4) and the Meta Pixel only load after you give consent through the AdOpt banner. You can change or withdraw your consent at any time using the AdOpt widget available on the site.
Categories of Cookies and Tags We Use
The table below summarizes the cookies and similar technologies used on codeqr.io:
| Category | Cookies / providers | Purpose | Consent |
|---|---|---|---|
| Strictly necessary | Session (next-auth), CSRF token, locale and theme preferences | Sign-in, security and remembering your language and theme | Not required — always active |
| Analytics | Google Analytics 4, loaded via Google Tag Manager | Understanding how visitors use our website | Loads only after consent (Consent Mode v2, default denied) |
| Advertising | Meta Pixel | Measuring our advertising campaigns | Loads only after consent (Consent Mode v2, default denied) |
| Functional / experimentation | Statsig | Feature flags and product experiments | Used to deliver features consistently |
Cookies in the Application (app.codeqr.io)
The authenticated application does not load any advertising pixel. It uses session and preference cookies, plus internal product analytics that help us understand how the product is used.
Cookies on Short Link and QR Code Domains
When you click a short link or scan a QR code created by a CodeQR customer, the following first-party cookies may be set — during the redirect or, for attribution cookies, by the customer’s own site:
- cq_id — a random click identifier, scoped to the path of the link. It lasts 1 hour by default, or up to 30 days when the customer has enabled conversion tracking, and is used to attribute a later conversion to the click or scan.
- skipForm — set only when a form step is skipped, for 1 hour.
- cq_ref — set only on referral links, for 30 days.
- codeqr_pk / cq_pk — attribution cookies used when the conversion tracking feature is enabled by the customer on their own site.
How to Manage Cookies
You can change or withdraw your consent at any time through the AdOpt widget on codeqr.io. You can also block or delete cookies in your browser settings; blocking strictly necessary cookies may prevent parts of the Service from working, such as signing in.
Global Privacy Control (GPC)
We honor the Global Privacy Control (GPC) signal sent by your browser as a valid opt-out of the "sale" or "sharing" of personal data, as defined by US state privacy laws.
Changes to this Cookie Policy
We may update this Cookie Policy from time to time to reflect changes in our practices. We will post the updated version on this page with a new "Last updated" date.
Contact
If you have questions about this Cookie Policy or how we use cookies, contact:
CodeQR Privacy Team
E-mail: contact@codeqr.io