Legal
Privacy Policy
Last updated: July 30, 2026
The short version
We designed QRCDN to know as little as possible. Scan analytics never store a raw IP address: we keep a one-way hash made with a salt that changes every day, so scans can't be traced to a person or even correlated across days. We can't sell what we don't have.
Who this covers
Two kinds of people interact with QRCDN: account holders (you sign up and make QR codes) and scanners (you point a camera at a code someone printed). This policy covers both, separately, because we treat them differently.
If you hold an account
We collect what the product needs to work:
- Your email address, to sign you in (magic link) and send you service email. If you sign in with Google, we receive your name and email from your Google profile. Nothing else.
- What you create: brand kits, styles, dynamic codes, their destinations, and any logo you upload.
- Payment details never touch our servers. When paid billing opens, it will be handled by Stripe; we store only your subscription status.
We never sell this data, and we never use it for advertising.
If you scan a code
This is the part most QR platforms bury. Here is everything a scan records:
- The code that was scanned, and when.
- Coarse location (country, region, and city) derived at the network edge. Never GPS, never precise.
- A device category (phone, tablet, desktop) parsed from your browser's user-agent string.
- The referring page, if your browser sent one.
- A one-way hash of your IP address, computed with a salt that rotates daily. Your raw IP address is never written to our database. The rotating salt means the same phone scanning on Tuesday and Wednesday produces two unrelated hashes: we can count unique visitors within a day, and nothing more.
Raw scan events are kept for 30 days (codes owned by free accounts) or 365 days (Pro), then deleted on a daily schedule. Aggregate daily counts (how many scans a code got, by country, by device type) persist so the code's owner keeps their totals.
Scanning a code sets no cookie and requires no account.
Who processes data for us
We run on a small set of infrastructure providers, each processing data only to provide the service: Vercel (application hosting, visitor analytics), Supabase (database and authentication), Cloudflare (network, scan redirects), Resend (transactional email), and, once billing opens, Stripe (payments). Application data is stored in the United States (us-east-1). Backups are encrypted.
Your rights
You can export what you've made (your codes and styles are yours), and you can delete your account at any time by writing to us. Deletion is immediate and cascades: your codes, kits, keys, and their scan history are permanently removed.
Children
QRCDN is not directed at children under 13, and we don't knowingly collect their data.
Changes
If this policy changes in a way that matters, account holders get an email before it takes effect. The date at the top is always current.
Contact
hello@qrcdn.com: a person reads it.