Privacy Policy
Last updated: May 28, 2026
This Privacy Policy explains how Create QRcode ("we", "us", "our") collects, uses, shares, and protects your personal data when you use the Create QRcode website and services (the "Service"). We are committed to handling your data responsibly and in accordance with applicable data protection laws.
1. Information we collect
We collect the following categories of information:
- Account information. Your email address and authentication details when you sign up, managed securely through our authentication provider.
- QR code content. The destination URLs, names, colours, and any images you upload to create and customise your QR codes.
- Scan analytics. When someone scans your QR code, we record data such as the time of the scan, approximate location (country and city derived from IP address), device type, operating system, and browser. We do not store full IP addresses for the purpose of identifying individual scanners.
- Payment information. When you subscribe to a paid plan, payments are processed by Stripe. We do not store your full card details on our servers; Stripe handles your payment data under its own privacy policy.
- Usage and technical data. Log data, cookies, and similar technologies used to operate, secure, and improve the Service.
2. How we use your information
- To provide, operate, and maintain the Service, including redirecting QR codes and generating analytics;
- To process payments, manage subscriptions, and send billing-related communications;
- To authenticate you and keep your account secure;
- To respond to your support requests and communicate important updates;
- To detect, prevent, and address fraud, abuse, and security issues;
- To comply with our legal obligations.
3. Legal bases for processing
Where applicable, we process your personal data on the basis of: performance of our contract with you (to deliver the Service); your consent (where required); our legitimate interests (to secure and improve the Service); and compliance with legal obligations.
4. Service providers we share data with
We share data only with trusted third-party processors who help us operate the Service, under appropriate contractual safeguards. These include:
- Stripe — payment processing and subscription billing.
- Supabase — authentication and database hosting.
- Cloudinary — storage and delivery of images you upload.
- Hosting and infrastructure providers — to run and deliver the Service.
We do not sell your personal data. We may disclose information if required by law, to enforce our terms, or to protect the rights, safety, and security of our users and the public.
5. Cookies
We use essential cookies to keep you signed in and to operate the Service securely. We may also use limited analytics cookies to understand how the Service is used. You can control cookies through your browser settings, though disabling essential cookies may affect functionality.
6. Data retention
We retain your account data and QR code data for as long as your account is active. Scan analytics are retained to provide historical reporting. When you delete your account, we delete or anonymise your personal data within a reasonable period, except where we are required to retain it for legal, accounting, or fraud-prevention purposes.
7. Your rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you;
- Request correction of inaccurate data;
- Request deletion of your data;
- Object to or restrict certain processing;
- Request a copy of your data in a portable format;
- Withdraw consent where processing is based on consent.
To exercise any of these rights, email us at nirupamapaldev@gmail.com from your registered email address. We will respond within the timeframe required by applicable law.
8. Data security
We use industry-standard technical and organisational measures to protect your data, including encryption in transit, access controls, and secure infrastructure. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. International transfers
Your data may be processed and stored on servers located outside your country of residence. Where we transfer data internationally, we take steps to ensure it is protected by appropriate safeguards consistent with this Policy and applicable law.
10. Children's privacy
The Service is not directed to individuals under the age of 18, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the "Last updated" date. If changes are material, we will notify you by email or through the Service.
12. Contact us
If you have any questions or concerns about this Privacy Policy or how we handle your data, contact us at nirupamapaldev@gmail.com. You can also reach our support team for assistance.