Privacy Policy
Effective date: 2026-08-28
This Privacy Policy explains how customqrcode.io collects, uses, discloses, and retains personal data when you visit our websites, create or manage QR codes, use our applications and integrations, contact us, or scan a QR code that uses our redirect service.
Scope and our role
This policy applies to the customqrcode.io Service. It does not apply to a website, application, or other destination that opens after a QR code is scanned, or to a third-party service you connect to your account.
We generally decide how personal data about website visitors and account users is handled. When we process scan analytics and other data solely to provide features to a QR code owner, we act as a service provider or processor for that owner where applicable law uses those terms. The owner is responsible for its own privacy notices, legal basis, and instructions for that data.
Questions or privacy requests may be sent to support@customqrcode.io.
Data you provide
We collect the information you provide when using the Service, which may include:
- Account and profile information, such as your name, email address, authentication identifiers, and workspace membership.
- Customer Content, such as QR code names and destinations, text, contact details, Wi-Fi details, files, images, logos, design settings, folders, templates, routing rules, and access-control settings.
- Communications, such as support requests, privacy requests, feedback, and related correspondence.
- API, webhook, and integration information, such as token names, webhook URLs and delivery records, connected-store details, and credentials or authorization tokens for services you choose to connect.
- AI feature inputs, such as a design prompt and the QR content needed to generate an image. Generated images are returned to you without being stored by us, while generation metadata and the prompt are retained with your account.
Data collected through the Service
When you use our websites and applications, we may collect device and usage information such as your IP address, browser and device information, pages viewed, actions taken, timestamps, referring page, diagnostic data, and cookie or consent identifiers.
We also record operational information needed to secure and run the Service, such as authentication events, API-token use, webhook attempts, integration status, link-health checks, rate-limit events, and error logs.
Data collected when a managed QR code is scanned
When someone scans a QR code that uses qr.customqrcode.io, the request passes through our redirect service. We record the scan timestamp, QR code and account identifiers, content type, whether the request was forwarded or blocked, the destination used at the time of the scan, coarse location provided by the network edge (country, region, and city when available), device type, operating-system family, browser family, referrer when provided, and the reason a scan was blocked when applicable.
The scanner's IP address and user-agent string are used transiently at the network edge to create a pseudonymous visitor hash that changes each day. We do not store the scanner's IP address in the scan event. The rotating hash lets us estimate unique scans for a day without recognizing the same scanner across different days.
The QR code owner can view scan counts, outcomes, time trends, and coarse device and location breakdowns. Scan data is collected to provide the owner-requested redirect and analytics features, not to build an advertising profile of the scanner.
How we use personal data
We use personal data to:
- Provide, personalize, maintain, and improve the Service.
- Create and resolve managed QR codes, apply routing and access rules, produce analytics, and monitor destination health.
- Authenticate users, administer accounts and workspaces, and provide APIs, webhooks, integrations, uploads, and exports.
- Send service messages, respond to support and privacy requests, and notify users about important account or security events.
- Protect users, scanners, third parties, and the Service from fraud, abuse, malware, phishing, and other security threats.
- Debug and measure the Service, understand feature use, and develop new features.
- Comply with law, enforce our agreements, and establish, exercise, or defend legal claims.
Legal bases
Where applicable law requires a legal basis, we process personal data as needed to perform our contract with you, based on our legitimate interests in operating and securing the Service, with your consent, or to comply with legal obligations. You may withdraw consent at any time, but withdrawal does not affect processing that already occurred.
Cookies and consent
We use the following categories of cookies and similar technologies:
- Necessary technologies, including Clerk session cookies that keep you signed in, qrgen_consent for 12 months to remember your privacy choices, and qrgen_pending for up to 1 hour to preserve temporary sign-up state.
- Product analytics from PostHog, enabled only after you consent to analytics where consent is required.
You can change your choice at any time using 'Cookie preferences' in the site footer. If your browser sends a Global Privacy Control signal and you have not already saved a choice, optional categories default to off.
How we disclose personal data
We disclose personal data only as needed for the purposes described in this policy:
- Service providers that operate on our behalf, including Clerk for authentication, Railway for application and database hosting, Cloudflare for edge redirects, networking, and file storage, PostHog for consent-based product analytics, Loops for email delivery, and Replicate when you use an AI image feature.
- Third-party integrations you choose to connect, such as Canva, Shopify, or Square. We send those services the information needed to perform the action you request.
- Other members of a workspace, according to their role and access.
- Professional advisers, auditors, insurers, and potential transaction partners when reasonably necessary and subject to appropriate confidentiality protections.
- Courts, regulators, law enforcement, or other parties when we believe disclosure is required by law, necessary to protect rights or safety, or needed to investigate abuse or enforce our agreements.
- A successor in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business, subject to applicable law.
We do not sell personal data. We do not share personal data for cross-context behavioral advertising or use scan data for targeted advertising.
Connected services and credentials
When you connect a third-party service, we receive and store the account details and credentials needed to maintain that connection. Integration credentials are encrypted at rest. You may disconnect an integration from the Service, but the third party may retain data it previously received under its own terms and privacy policy.
API tokens are stored as one-way hashes after creation. Webhook signing secrets and delivery data are stored so you can verify and troubleshoot deliveries. You are responsible for keeping credentials shown to you secure.
Retention
We keep personal data only as long as reasonably necessary for the purposes described in this policy:
- Account data and Customer Content, including saved codes, folders, templates, uploads, integration connections, and account-level analytics rollups: until you delete the content or your account, subject to limited backup, security, and legal-retention needs.
- Raw scan events: 24 months.
- Daily visitor hashes used to estimate unique scans: 35 days.
- Resolved support requests: 24 months. If you delete your account sooner, the support record is retained in anonymized form.
- Completed account-deletion records: 24 months.
Some records may be kept longer when required by law or reasonably necessary for security, fraud prevention, dispute resolution, or enforcement. Aggregated or de-identified information that can no longer reasonably identify a person may be retained longer.
Security
We use technical and organizational safeguards designed to protect personal data, including access controls, encryption of integration credentials, hashed API tokens, and limited retention of scanner identifiers. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.
International data transfers
We and our service providers may process personal data in the United States and other countries that may have different data-protection laws from your country. Where required, we use contractual or other recognized safeguards for international transfers.
Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal data; object to or restrict certain processing; withdraw consent; or appeal a decision about a privacy request. You may also have the right not to receive discriminatory treatment for exercising a privacy right.
You can update some account information and delete your account through the Service. You can change optional cookie choices through 'Cookie preferences' and can unsubscribe from non-essential email using the link in the message.
To exercise another privacy right, contact support@customqrcode.io. We may need to verify your identity and authority before completing a request. An authorized agent may submit a request where permitted by law, but we may require proof of authorization.
If your request concerns data collected by a QR code owner through its destination or campaign, contact that owner directly. We will assist the owner with a valid request when we process the relevant data on its behalf.
Account deletion
You can request deletion from customqrcode.io/dashboard/account/delete. Account deletion removes the local account, codes, templates, folders, scan events, analytics rollups, daily visitor hashes, and authentication identity associated with the account. It also anonymizes linked support records. We retain a minimal deletion-request record for the period described above so we can document that the request was completed.
If you own a shared workspace, you may need to transfer or delete that workspace before account deletion can be completed.
Children
The Service is not directed to children under 18, and we do not knowingly collect personal data from a child under 13. If you believe a child provided personal data to us, contact support@customqrcode.io so we can investigate and take appropriate action.
Changes to this policy
We may update this Privacy Policy as the Service or law changes. We will update the effective date above and provide additional notice when a change is material or when applicable law requires it.
Contact
Failpunk LLC operates the Service. Questions and privacy requests may be sent to support@customqrcode.io or mailed to 8117 Rock Port Cir, Las Vegas, NV 89128, United States.