QRCDN

Legal

Privacy Policy

Last updated: July 30, 2026

The short version

We designed QRCDN to know as little as possible. Scan analytics never store a raw IP address: we keep a one-way hash made with a salt that changes every day, so scans can't be traced to a person or even correlated across days. We can't sell what we don't have.

Who this covers

Two kinds of people interact with QRCDN: account holders (you sign up and make QR codes) and scanners (you point a camera at a code someone printed). This policy covers both, separately, because we treat them differently.

If you hold an account

We collect what the product needs to work:

  • Your email address, to sign you in (magic link) and send you service email. If you sign in with Google, we receive your name and email from your Google profile. Nothing else.
  • What you create: brand kits, styles, dynamic codes, their destinations, and any logo you upload.
  • Payment details never touch our servers. When paid billing opens, it will be handled by Stripe; we store only your subscription status.

We never sell this data, and we never use it for advertising.

If you scan a code

This is the part most QR platforms bury. Here is everything a scan records:

  • The code that was scanned, and when.
  • Coarse location (country, region, and city) derived at the network edge. Never GPS, never precise.
  • A device category (phone, tablet, desktop) parsed from your browser's user-agent string.
  • The referring page, if your browser sent one.
  • A one-way hash of your IP address, computed with a salt that rotates daily. Your raw IP address is never written to our database. The rotating salt means the same phone scanning on Tuesday and Wednesday produces two unrelated hashes: we can count unique visitors within a day, and nothing more.

Raw scan events are kept for 30 days (codes owned by free accounts) or 365 days (Pro), then deleted on a daily schedule. Aggregate daily counts (how many scans a code got, by country, by device type) persist so the code's owner keeps their totals.

Scanning a code sets no cookie and requires no account.

Cookies

Signing in sets authentication cookies (via Supabase, our auth provider). That's what keeps you logged in. There are no advertising or cross-site tracking cookies anywhere on this site. Our visitor analytics (Vercel Web Analytics) is cookieless and identifies visits with a hash that resets daily.

Who processes data for us

We run on a small set of infrastructure providers, each processing data only to provide the service: Vercel (application hosting, visitor analytics), Supabase (database and authentication), Cloudflare (network, scan redirects), Resend (transactional email), and, once billing opens, Stripe (payments). Application data is stored in the United States (us-east-1). Backups are encrypted.

Your rights

You can export what you've made (your codes and styles are yours), and you can delete your account at any time by writing to us. Deletion is immediate and cascades: your codes, kits, keys, and their scan history are permanently removed.

Children

QRCDN is not directed at children under 13, and we don't knowingly collect their data.

Changes

If this policy changes in a way that matters, account holders get an email before it takes effect. The date at the top is always current.

Contact

hello@qrcdn.com: a person reads it.