Privacy Policy
Last updated: 2026-07-19. This Privacy Policy explains how CodeQR ("CodeQR", "we", "us" or "our") collects, uses and shares personal data when you visit codeqr.io, create an account and use our platform (the "Service"), or when you interact with a short link, QR code or page created by one of our customers. If you have questions about this policy or about your personal data, contact us at contact@codeqr.io.
Who We Are
CodeQR provides a platform for creating and managing short links, QR codes and pages, with analytics about how they are used. We act in two distinct roles: for account, billing and marketing data, we are the data controller; for data about visitors who click, scan or visit our customers' links, QR codes and pages, we act as a processor on behalf of the customer. See "Our Roles: Controller and Processor" below.
Information We Collect
We collect the following categories of personal data:
- Account data: name, email address and password, workspace and company name, and the settings you configure.
- Billing data: plan, subscription status and payment information, processed by our payment provider (Stripe).
- Communications: messages you send to our support and privacy channels.
- Website usage data: analytics and advertising data collected on codeqr.io subject to your cookie consent, as described in our Cookie Policy.
- Visitor event data: data processed when someone interacts with a customer's short link, QR code or page, described in the next section.
For details about the cookies and similar technologies we use, including how to give and withdraw consent, see our Cookie Policy at codeqr.io/cookies.
Click, Scan and Page Visit Events
When someone clicks a short link, scans a QR code or visits a page created by a CodeQR customer, we process the following data on that customer's behalf:
- IP address, used to derive an approximate location and for security and anti-abuse purposes. The IP address of visitors from the European Union is not stored in event records.
- User-agent information (device type, browser and operating system).
- Approximate location (country, city and region).
- Referrer (the page that led to the click or visit).
- A derived pseudonymous identifier (a hash of IP address and user-agent) and randomly generated click identifiers.
Retention commitment: event-level identifiers are retained for up to 90 days. Aggregated statistics (such as click and scan counts) are retained to power the customer's dashboard.
Legal Bases for Processing
Where the GDPR, the UK GDPR or the LGPD applies, we rely on the following legal bases:
- Performance of a contract: to provide the Service and manage your account and subscription.
- Legitimate interests: to keep the Service secure and prevent abuse such as phishing, malware and spam.
- Consent: for marketing cookies and advertising tags on our website, and for marketing communications.
- Legal obligation: to comply with tax, accounting and other legal requirements.
How We Use Your Information
We use personal data to:
- Provide, operate and maintain the Service.
- Provide analytics dashboards and reports to our customers.
- Process payments and manage subscriptions.
- Communicate with you about the Service, including support and service updates.
- Send marketing communications where you have agreed to receive them.
- Detect, prevent and respond to fraud, abuse and security incidents.
- Comply with legal obligations.
How We Share Information: Subprocessors and Integrations
We do not sell personal data. We share personal data with service providers (subprocessors) that help us run the Service, in the following categories: hosting and CDN (Vercel), database (PlanetScale), event analytics (Tinybird), caching (Upstash), media storage (Cloudinary), payments (Stripe), transactional email (Resend), AI features (Anthropic) and consent management (AdOpt). The current list is available at codeqr.io/legal/subprocessors. We may also disclose data:
- To integrations that you, as a customer, choose to enable (such as Meta, Kiwify, HubSpot, Kommo, RD Station or Slack) — these receive data only when you activate them.
- To comply with legal obligations, such as responding to a court order or another binding request from authorities.
- To protect and defend our rights, our users or the public, including when investigating abuse of the Service.
International Data Transfers
Our infrastructure is located primarily in the United States. Transfers of personal data from the European Union and the United Kingdom are covered by Standard Contractual Clauses (and, for the UK, the UK Addendum) entered into with our subprocessors. Transfers from Brazil rely on contractual clauses consistent with the LGPD and applicable ANPD guidance.
Data Retention
We keep account data for as long as your account exists and, after that, only for the periods required by law (for example, tax and accounting obligations). Backups expire on a regular cycle. Visitor event data follows the retention commitment described above: event-level identifiers for up to 90 days, with aggregated statistics retained for customer dashboards.
Data Security
We use administrative, technical and organizational measures designed to protect personal data. No security measure is perfect and no method of transmission or storage can be guaranteed against every risk, but we work to protect the data we process and to respond quickly to incidents.
Your Rights under the GDPR and UK GDPR
If you are in the European Economic Area or the United Kingdom, you have the following rights over your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your personal data, under certain conditions.
- Restriction — ask us to restrict the processing of your data, under certain conditions.
- Objection — object to processing based on legitimate interests.
- Portability — receive your data in a structured, machine-readable format.
- Complaint — lodge a complaint with your supervisory authority.
To exercise any of these rights, contact contact@codeqr.io. We respond within one month; this period may be extended where the law allows.
Your Rights under the LGPD (Brazil)
If you are in Brazil, Article 18 of the LGPD gives you the right to obtain from CodeQR:
- Confirmation that we process your personal data, and access to that data.
- Correction of incomplete, inaccurate or outdated data.
- Anonymization, blocking or deletion of data that is unnecessary, excessive or processed in violation of the LGPD.
- Portability of your data to another provider.
- Information about the entities with which we have shared your data.
- Information about the possibility of refusing consent, and revocation of consent at any time.
- You may also lodge a complaint with the Brazilian data protection authority (ANPD).
US State Privacy Rights
If you live in a US state with a comprehensive privacy law, you may have the following rights:
- Know and access the personal data we process about you.
- Delete your personal data, subject to legal exceptions.
- Correct inaccurate personal data.
- Opt out of the "sale" or "sharing" of personal data — we do not sell personal data.
- Non-discrimination for exercising any of these rights.
We honor Global Privacy Control (GPC) signals as a valid opt-out.
Our Roles: Controller and Processor
For account, billing and marketing data, CodeQR is the controller. For visitor event data generated by our customers' links, QR codes and pages, CodeQR is a processor and the customer is the controller. If you interacted with a customer's link, QR code or page, please direct requests about your data to that customer first — we support our customers in responding. Our Data Processing Agreement (DPA) is available at codeqr.io/legal/dpa and is incorporated by reference into our customer contracts.
Representatives and Data Protection Officer
We are in the process of appointing our EU representative (Article 27 GDPR) and our UK representative (UK GDPR); their details will be published here as soon as the appointment takes effect. In Brazil, our Data Protection Officer (Encarregado) can be contacted at contact@codeqr.io.
Children
The Service is not directed to anyone under 18 years of age, and we do not knowingly collect personal data from children.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational or regulatory reasons. We will post the updated policy on this page with a new "Last updated" date, and we encourage you to review it periodically.
Contact
For privacy questions or to exercise your rights, contact:
CodeQR Privacy Team
E-mail: contact@codeqr.io