Use Cases

Resources

Pricing

FAQs

Login

Try for free

Try for free

Try for free

Try for free

Resources

Pricing

FAQs

Login

Use Cases

Privacy Policy

1. Scope and Who We Are

This Privacy Policy explains how QR-Codes.com, LLC, which owns and operates QR-Codes.com, collects, uses, discloses, and protects personal data through our websites, application, QR Code redirection service, analytics tools, and related services. We refer to these collectively as the "Services."

In this Policy, "QR-Codes.com," "we," "us," and "our" mean QR-Codes.com, LLC.

This Policy applies to:

  • People who visit our website or application

  • People who create or manage QR Codes through an account

  • People who contact us, use support, or communicate with us

  • People who scan a dynamic QR Code that uses our redirection or analytics service

A QR Code may direct you to a website, form, application, file, or other destination controlled by a QR-Codes.com customer or another third party. The destination operator's privacy practices apply to information collected at that destination. QR-Codes.com does not control those independent privacy practices.

2. Important Information About QR Code Scans

Scanning a QR Code does not require a person to provide QR-Codes.com with a name, email address, phone number, postal address, or other direct identifier.

To redirect the scan, provide analytics, estimate unique scans, maintain reliability, and protect the Services, we may process limited technical and location-related information such as:

  • The QR Code or redirect link that was scanned

  • The date and time of the scan

  • Internet Protocol address

  • Approximate location derived from an Internet Protocol address, network information, or similar technical data

  • Device type or model, browser, operating system, language, and related technical information

  • Referral or campaign information when available

  • Identifiers or event data used to estimate unique scans, detect abuse, and maintain security

If a feature requests more precise location, the location is collected only after the scanner grants permission through the browser or device. Location accuracy can be affected by device settings, browser permissions, network routing, virtual private networks, mobile carriers, and other factors.

This scan data is not intended to directly identify an individual scanner. However, some privacy laws define Internet Protocol addresses, device identifiers, and location data as personal data. We therefore describe and protect this information as personal data where applicable.

Customers who own or manage a QR Code may receive analytics about scans of that code, such as scan counts, estimated unique scans, scan times, device information, and approximate locations. A standard scan alone does not provide the customer with the scanner's name, email address, phone number, or other direct contact information.

If the destination reached after a scan asks a person to submit contact information or other personal data, that is a separate interaction governed by the destination operator's privacy notice.

3. Personal Data We Collect

Account and Profile Data

When you create or manage an account, we may collect your name, email address, company information, country, account credentials, preferences, and other information you choose to provide.

QR Code and Customer Content

We process the information needed to create and operate QR Codes, including destination URLs, campaign names, designs, logos, files, settings, and other content you submit to the Services.

Scan Data

When a person scans a dynamic QR Code that uses our service, we may collect the scan data described in Section 2.

Billing and Transaction Data

We may collect billing contact information, subscription details, invoices, transaction status, and limited payment-method information made available to us by Stripe. Stripe, rather than QR-Codes.com, collects and processes full payment card details through its payment interface. We do not receive or store a full payment card number or card security code through that interface.

Communications and Support Data

We collect information that you provide when you contact us by email, contact form, support request, chat, social media, or another communication channel. This may include your contact details, message, attachments, and our response history.

Website and Application Usage Data

When you use our website or application, we and our service providers may collect:

  • Internet Protocol address

  • Browser, device, operating system, language, and time-zone information

  • Pages viewed, buttons or links selected, referring pages, and navigation activity

  • Log-in events, product interactions, errors, and performance information

  • Cookie identifiers, advertising identifiers, and similar technologies

  • General location derived from technical information

Marketing Data

We may collect your communication preferences, responses to emails, interactions with advertisements, and information used to measure campaigns or show relevant advertising, subject to applicable consent and opt-out requirements.

Information From Third Parties

We may receive information from service providers, analytics and advertising partners, payment processors, social networks, referral partners, and other sources. We use that information only for the purposes described in this Policy or as otherwise disclosed when it is collected.

4. How We Use Personal Data

We use personal data to:

  • Provide, operate, maintain, and improve the Services

  • Create, redirect, manage, and measure QR Codes

  • Estimate unique scans and provide campaign analytics

  • Create and administer accounts

  • Process subscriptions and transactions

  • Communicate with you and provide customer support

  • Personalize features and remember preferences

  • Monitor performance, diagnose errors, and maintain availability

  • Detect, investigate, and prevent fraud, abuse, malicious activity, and security incidents

  • Measure website, application, and advertising performance

  • Send service messages and, where permitted, marketing communications

  • Enforce our terms and protect our rights, users, and the public

  • Comply with legal, tax, accounting, regulatory, and reporting obligations

  • Establish, exercise, or defend legal claims

We may aggregate or de-identify information so that it is not reasonably linkable to an individual. We may use and disclose aggregated or de-identified information for lawful purposes and will not attempt to re-identify it except as permitted by law.

5. Legal Bases for Processing

If you are in the European Economic Area, United Kingdom, Switzerland, or another jurisdiction that requires a legal basis, we rely on one or more of the following:

  • Contract, when processing is necessary to provide the Services you request

  • Legitimate interests, including operating and improving the Services, providing scan analytics, securing the Services, communicating with customers, and understanding business performance

  • Consent, including for more precise location, nonessential cookies, certain advertising technologies, and marketing where consent is required

  • Legal obligation, when processing is necessary to comply with applicable law

When we rely on legitimate interests, we consider the nature of the data, the expected use of the Services, and the potential effect on individuals. You may have the right to object to this processing as described below.

6. How We Disclose Personal Data

We may disclose personal data to:

QR-Codes.com Customers

Customers who own or manage a QR Code may receive scan analytics for that code, as described in Section 2. A standard scan alone does not give a customer the scanner's name, email address, phone number, or other direct contact information.

Service Providers

We use service providers for cloud infrastructure, website hosting, payments, analytics, advertising, consent management, communications, customer support, security, and other business functions. Current providers may include:

  • DigitalOcean for application infrastructure and cloud services

  • Framer for the public website and related services

  • Stripe for payment processing and fraud prevention

  • Google for tag management, analytics, advertising, and conversion measurement

  • LinkedIn for advertising and conversion measurement

  • PostHog for product and usage analytics

  • Brevo, formerly Sendinblue, for communications, chat, and automation

  • Cookiebot for cookie consent management

These providers process information under their own terms, our instructions, or both, depending on the service and legal context. We may update our providers as our Services change.

Professional Advisers

We may disclose information to attorneys, accountants, auditors, insurers, and other professional advisers where reasonably necessary.

Legal and Safety Purposes

We may disclose information when we reasonably believe it is required by law, legal process, or a valid government request, or when necessary to protect the rights, property, safety, and security of QR-Codes.com, our users, or others.

Business Transactions

We may disclose or transfer information as part of a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar business transaction, subject to applicable law.

With Your Direction or Consent

We may disclose information when you direct us to do so or provide consent.

7. Our Role and Our Customers' Role

For account administration, billing, service security, our website and application analytics, and communications with you, QR-Codes.com generally acts as the controller or business responsible for the processing.

When a customer uses the Services to process personal data for its own purposes, the customer may be the controller or business, and QR-Codes.com may act as a processor or service provider on the customer's behalf. The roles depend on the context and applicable law. Customers are responsible for providing any notices, obtaining any consents, and establishing any legal bases required for their use of the Services and their destination content.

8. Cookies, Analytics, and Advertising

We and our providers use cookies, pixels, tags, local storage, and similar technologies for the following purposes:

  • Essential technologies needed for security, authentication, network management, and core functionality

  • Preference technologies that remember settings and choices

  • Analytics technologies that help us understand and improve use of the Services

  • Advertising technologies that measure campaigns and may help show relevant advertisements

On our public marketing website, we use Cookiebot to present cookie choices and manage nonessential technologies where consent is required. Cookiebot's Privacy Trigger is enabled. After a visitor records a consent choice, the trigger can be used to review or change that choice. You may also control cookies through your browser, although blocking essential technologies may affect the Services.

We do not respond to the older browser "Do Not Track" setting because there is no consistent industry standard for that signal. On our public marketing website, where required by applicable law, we treat a recognized Global Privacy Control signal or another qualifying universal opt-out mechanism as a request to opt out of sale, sharing, or targeted advertising for that browser or device.

9. Sale, Sharing, and Targeted Advertising

We do not sell personal data for money.

Some analytics and advertising technologies on our website or application may allow providers to collect identifiers and online activity for measurement, advertising, or cross-context behavioral advertising. Certain U.S. state laws may define those disclosures as a "sale," "sharing," or use for "targeted advertising," even when no money is exchanged.

Where applicable, you may opt out of advertising technologies on our public marketing website through Cookiebot's Privacy Trigger when displayed, a recognized universal opt-out signal, or by contacting us at info@qr-codes.com. We do not knowingly sell or share personal data of individuals under 16.

10. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including providing the Services, maintaining security and business records, complying with legal obligations, resolving disputes, and enforcing agreements.

Retention depends on factors such as:

  • How long an account, subscription, QR Code, or customer relationship remains active

  • The nature, sensitivity, and volume of the data

  • Whether the information is needed to provide analytics or maintain the Services

  • Security, fraud-prevention, backup, and disaster-recovery needs

  • Tax, accounting, payment, regulatory, litigation, and legal-preservation requirements

  • A user's deletion request and any applicable legal exceptions

Backups may retain information for a limited period after it is removed from active systems. We may retain de-identified or aggregated information where it no longer identifies an individual.

11. Security

We use administrative, technical, and organizational measures designed to protect personal data. These measures include encryption in transit, access controls, secure session controls, software updates, monitoring, backups, and limits on administrative access.

Our application infrastructure uses DigitalOcean, whose cloud platform maintains SOC 2 Type II and SOC 3 Type II certifications issued by an independent auditor. We combine that infrastructure with application-level safeguards and use Stripe to process full payment card details through Stripe's payment interface.

No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we work to prevent, detect, and respond to security issues. If a legally reportable breach occurs, we will provide notices as required by applicable law.

For more information, visit our Security page at https://www.qr-codes.com/security.

12. International Data Transfers

QR-Codes.com is based in the United States, and we and our providers may process information in the United States and other countries. Those countries may have privacy laws that differ from the laws where you live.

Where required, we use an appropriate transfer mechanism, which may include the European Commission's Standard Contractual Clauses, the applicable United Kingdom or Swiss transfer terms, a valid adequacy decision, or another mechanism recognized by law. Our providers may rely on their own approved transfer mechanisms where appropriate.

13. Your Privacy Rights

Depending on where you live and subject to legal exceptions, you may have the right to:

  • Know whether we process your personal data

  • Access or obtain a copy of your personal data

  • Correct inaccurate personal data

  • Delete personal data

  • Receive certain data in a portable format

  • Restrict or object to certain processing

  • Withdraw consent at any time where processing is based on consent

  • Opt out of sale, sharing, targeted advertising, or certain profiling

  • Limit certain uses of sensitive personal information

  • Appeal a decision concerning a privacy request

  • Not be discriminated against for exercising a privacy right

  • Complain to a data protection authority

To submit a request, email info@qr-codes.com with the subject line "Privacy Request" or write to the address in Section 18. You may also use Cookiebot's Privacy Trigger when displayed to review or change cookie and advertising choices.

We may need to verify your identity and authority before completing a request. If an authorized agent submits a request for you, we may require proof of authorization and verification of your identity. We will respond within the period required by applicable law.

If we deny a request and your law provides a right to appeal, you may appeal by replying to our decision or emailing info@qr-codes.com with the subject line "Privacy Appeal."

14. California and Other U.S. State Privacy Disclosures

The categories of personal data we may have collected during the preceding 12 months include:

  • Identifiers, such as name, email address, postal address, Internet Protocol address, account identifier, and online identifiers

  • Customer-record information, such as contact and billing information

  • Commercial information, such as subscriptions, purchases, and transaction history

  • Internet or electronic network activity, such as browsing, application interactions, and QR Code scan activity

  • Geolocation data, including approximate location and, if permission is granted, more precise location

  • Inferences, such as preferences or likely interests derived from interactions with the Services

  • Sensitive personal information, such as account credentials and more precise geolocation when permission is granted. Stripe processes full payment card details through its payment interface

We collect these categories directly from individuals, automatically through the Services, from our customers, and from the service providers and partners described in this Policy. We use them for the purposes in Section 4 and disclose them to the recipients in Section 6.

We do not sell personal data for money. As explained in Section 9, disclosures of identifiers and online activity to analytics and advertising providers may be considered sale, sharing, or targeted advertising under some state laws. You may opt out where applicable.

We use sensitive personal information only for purposes permitted by applicable law, such as providing requested services, authenticating users, processing permitted location features, maintaining security, and preventing fraud, unless we provide additional notice.

15. Children

QR-Codes.com accounts and paid Services are intended for people who are at least 18 years old or the age of majority where they live. The Services are not directed to children under 13, and we do not knowingly collect personal data from a child under 13. If you believe a child has provided personal data to us, contact info@qr-codes.com so we can review and take appropriate action.

A publicly displayed QR Code may be scanned by anyone. Customers should consider their audience and comply with laws that apply to destination content intended for children.

16. Third-Party Destinations and Services

The Services may contain links to, or QR Codes may redirect to, third-party websites, forms, applications, files, and services. We do not control and are not responsible for their content, security, or privacy practices. Review the privacy notice of the destination before providing personal data.

17. Changes to This Policy

We may update this Policy to reflect changes to the Services, our practices, or applicable law. We will post the updated Policy and revise the "Last Updated" date. If a change materially affects how we use personal data, we will provide additional notice when required by law.

18. Contact Us

For privacy questions or requests, contact:

QR-Codes.com, LLC
ATTN: Privacy
P.O. Box 49
Chester, NY 10918
United States
Email: info@qr-codes.com

Last updated: September 1, 2026

1. Scope and Who We Are

This Privacy Policy explains how QR-Codes.com, LLC, which owns and operates QR-Codes.com, collects, uses, discloses, and protects personal data through our websites, application, QR Code redirection service, analytics tools, and related services. We refer to these collectively as the "Services."

In this Policy, "QR-Codes.com," "we," "us," and "our" mean QR-Codes.com, LLC.

This Policy applies to:

  • People who visit our website or application

  • People who create or manage QR Codes through an account

  • People who contact us, use support, or communicate with us

  • People who scan a dynamic QR Code that uses our redirection or analytics service

A QR Code may direct you to a website, form, application, file, or other destination controlled by a QR-Codes.com customer or another third party. The destination operator's privacy practices apply to information collected at that destination. QR-Codes.com does not control those independent privacy practices.

2. Important Information About QR Code Scans

Scanning a QR Code does not require a person to provide QR-Codes.com with a name, email address, phone number, postal address, or other direct identifier.

To redirect the scan, provide analytics, estimate unique scans, maintain reliability, and protect the Services, we may process limited technical and location-related information such as:

  • The QR Code or redirect link that was scanned

  • The date and time of the scan

  • Internet Protocol address

  • Approximate location derived from an Internet Protocol address, network information, or similar technical data

  • Device type or model, browser, operating system, language, and related technical information

  • Referral or campaign information when available

  • Identifiers or event data used to estimate unique scans, detect abuse, and maintain security

If a feature requests more precise location, the location is collected only after the scanner grants permission through the browser or device. Location accuracy can be affected by device settings, browser permissions, network routing, virtual private networks, mobile carriers, and other factors.

This scan data is not intended to directly identify an individual scanner. However, some privacy laws define Internet Protocol addresses, device identifiers, and location data as personal data. We therefore describe and protect this information as personal data where applicable.

Customers who own or manage a QR Code may receive analytics about scans of that code, such as scan counts, estimated unique scans, scan times, device information, and approximate locations. A standard scan alone does not provide the customer with the scanner's name, email address, phone number, or other direct contact information.

If the destination reached after a scan asks a person to submit contact information or other personal data, that is a separate interaction governed by the destination operator's privacy notice.

3. Personal Data We Collect

Account and Profile Data

When you create or manage an account, we may collect your name, email address, company information, country, account credentials, preferences, and other information you choose to provide.

QR Code and Customer Content

We process the information needed to create and operate QR Codes, including destination URLs, campaign names, designs, logos, files, settings, and other content you submit to the Services.

Scan Data

When a person scans a dynamic QR Code that uses our service, we may collect the scan data described in Section 2.

Billing and Transaction Data

We may collect billing contact information, subscription details, invoices, transaction status, and limited payment-method information made available to us by Stripe. Stripe, rather than QR-Codes.com, collects and processes full payment card details through its payment interface. We do not receive or store a full payment card number or card security code through that interface.

Communications and Support Data

We collect information that you provide when you contact us by email, contact form, support request, chat, social media, or another communication channel. This may include your contact details, message, attachments, and our response history.

Website and Application Usage Data

When you use our website or application, we and our service providers may collect:

  • Internet Protocol address

  • Browser, device, operating system, language, and time-zone information

  • Pages viewed, buttons or links selected, referring pages, and navigation activity

  • Log-in events, product interactions, errors, and performance information

  • Cookie identifiers, advertising identifiers, and similar technologies

  • General location derived from technical information

Marketing Data

We may collect your communication preferences, responses to emails, interactions with advertisements, and information used to measure campaigns or show relevant advertising, subject to applicable consent and opt-out requirements.

Information From Third Parties

We may receive information from service providers, analytics and advertising partners, payment processors, social networks, referral partners, and other sources. We use that information only for the purposes described in this Policy or as otherwise disclosed when it is collected.

4. How We Use Personal Data

We use personal data to:

  • Provide, operate, maintain, and improve the Services

  • Create, redirect, manage, and measure QR Codes

  • Estimate unique scans and provide campaign analytics

  • Create and administer accounts

  • Process subscriptions and transactions

  • Communicate with you and provide customer support

  • Personalize features and remember preferences

  • Monitor performance, diagnose errors, and maintain availability

  • Detect, investigate, and prevent fraud, abuse, malicious activity, and security incidents

  • Measure website, application, and advertising performance

  • Send service messages and, where permitted, marketing communications

  • Enforce our terms and protect our rights, users, and the public

  • Comply with legal, tax, accounting, regulatory, and reporting obligations

  • Establish, exercise, or defend legal claims

We may aggregate or de-identify information so that it is not reasonably linkable to an individual. We may use and disclose aggregated or de-identified information for lawful purposes and will not attempt to re-identify it except as permitted by law.

5. Legal Bases for Processing

If you are in the European Economic Area, United Kingdom, Switzerland, or another jurisdiction that requires a legal basis, we rely on one or more of the following:

  • Contract, when processing is necessary to provide the Services you request

  • Legitimate interests, including operating and improving the Services, providing scan analytics, securing the Services, communicating with customers, and understanding business performance

  • Consent, including for more precise location, nonessential cookies, certain advertising technologies, and marketing where consent is required

  • Legal obligation, when processing is necessary to comply with applicable law

When we rely on legitimate interests, we consider the nature of the data, the expected use of the Services, and the potential effect on individuals. You may have the right to object to this processing as described below.

6. How We Disclose Personal Data

We may disclose personal data to:

QR-Codes.com Customers

Customers who own or manage a QR Code may receive scan analytics for that code, as described in Section 2. A standard scan alone does not give a customer the scanner's name, email address, phone number, or other direct contact information.

Service Providers

We use service providers for cloud infrastructure, website hosting, payments, analytics, advertising, consent management, communications, customer support, security, and other business functions. Current providers may include:

  • DigitalOcean for application infrastructure and cloud services

  • Framer for the public website and related services

  • Stripe for payment processing and fraud prevention

  • Google for tag management, analytics, advertising, and conversion measurement

  • LinkedIn for advertising and conversion measurement

  • PostHog for product and usage analytics

  • Brevo, formerly Sendinblue, for communications, chat, and automation

  • Cookiebot for cookie consent management

These providers process information under their own terms, our instructions, or both, depending on the service and legal context. We may update our providers as our Services change.

Professional Advisers

We may disclose information to attorneys, accountants, auditors, insurers, and other professional advisers where reasonably necessary.

Legal and Safety Purposes

We may disclose information when we reasonably believe it is required by law, legal process, or a valid government request, or when necessary to protect the rights, property, safety, and security of QR-Codes.com, our users, or others.

Business Transactions

We may disclose or transfer information as part of a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar business transaction, subject to applicable law.

With Your Direction or Consent

We may disclose information when you direct us to do so or provide consent.

7. Our Role and Our Customers' Role

For account administration, billing, service security, our website and application analytics, and communications with you, QR-Codes.com generally acts as the controller or business responsible for the processing.

When a customer uses the Services to process personal data for its own purposes, the customer may be the controller or business, and QR-Codes.com may act as a processor or service provider on the customer's behalf. The roles depend on the context and applicable law. Customers are responsible for providing any notices, obtaining any consents, and establishing any legal bases required for their use of the Services and their destination content.

8. Cookies, Analytics, and Advertising

We and our providers use cookies, pixels, tags, local storage, and similar technologies for the following purposes:

  • Essential technologies needed for security, authentication, network management, and core functionality

  • Preference technologies that remember settings and choices

  • Analytics technologies that help us understand and improve use of the Services

  • Advertising technologies that measure campaigns and may help show relevant advertisements

On our public marketing website, we use Cookiebot to present cookie choices and manage nonessential technologies where consent is required. Cookiebot's Privacy Trigger is enabled. After a visitor records a consent choice, the trigger can be used to review or change that choice. You may also control cookies through your browser, although blocking essential technologies may affect the Services.

We do not respond to the older browser "Do Not Track" setting because there is no consistent industry standard for that signal. On our public marketing website, where required by applicable law, we treat a recognized Global Privacy Control signal or another qualifying universal opt-out mechanism as a request to opt out of sale, sharing, or targeted advertising for that browser or device.

9. Sale, Sharing, and Targeted Advertising

We do not sell personal data for money.

Some analytics and advertising technologies on our website or application may allow providers to collect identifiers and online activity for measurement, advertising, or cross-context behavioral advertising. Certain U.S. state laws may define those disclosures as a "sale," "sharing," or use for "targeted advertising," even when no money is exchanged.

Where applicable, you may opt out of advertising technologies on our public marketing website through Cookiebot's Privacy Trigger when displayed, a recognized universal opt-out signal, or by contacting us at info@qr-codes.com. We do not knowingly sell or share personal data of individuals under 16.

10. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including providing the Services, maintaining security and business records, complying with legal obligations, resolving disputes, and enforcing agreements.

Retention depends on factors such as:

  • How long an account, subscription, QR Code, or customer relationship remains active

  • The nature, sensitivity, and volume of the data

  • Whether the information is needed to provide analytics or maintain the Services

  • Security, fraud-prevention, backup, and disaster-recovery needs

  • Tax, accounting, payment, regulatory, litigation, and legal-preservation requirements

  • A user's deletion request and any applicable legal exceptions

Backups may retain information for a limited period after it is removed from active systems. We may retain de-identified or aggregated information where it no longer identifies an individual.

11. Security

We use administrative, technical, and organizational measures designed to protect personal data. These measures include encryption in transit, access controls, secure session controls, software updates, monitoring, backups, and limits on administrative access.

Our application infrastructure uses DigitalOcean, whose cloud platform maintains SOC 2 Type II and SOC 3 Type II certifications issued by an independent auditor. We combine that infrastructure with application-level safeguards and use Stripe to process full payment card details through Stripe's payment interface.

No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we work to prevent, detect, and respond to security issues. If a legally reportable breach occurs, we will provide notices as required by applicable law.

For more information, visit our Security page at https://www.qr-codes.com/security.

12. International Data Transfers

QR-Codes.com is based in the United States, and we and our providers may process information in the United States and other countries. Those countries may have privacy laws that differ from the laws where you live.

Where required, we use an appropriate transfer mechanism, which may include the European Commission's Standard Contractual Clauses, the applicable United Kingdom or Swiss transfer terms, a valid adequacy decision, or another mechanism recognized by law. Our providers may rely on their own approved transfer mechanisms where appropriate.

13. Your Privacy Rights

Depending on where you live and subject to legal exceptions, you may have the right to:

  • Know whether we process your personal data

  • Access or obtain a copy of your personal data

  • Correct inaccurate personal data

  • Delete personal data

  • Receive certain data in a portable format

  • Restrict or object to certain processing

  • Withdraw consent at any time where processing is based on consent

  • Opt out of sale, sharing, targeted advertising, or certain profiling

  • Limit certain uses of sensitive personal information

  • Appeal a decision concerning a privacy request

  • Not be discriminated against for exercising a privacy right

  • Complain to a data protection authority

To submit a request, email info@qr-codes.com with the subject line "Privacy Request" or write to the address in Section 18. You may also use Cookiebot's Privacy Trigger when displayed to review or change cookie and advertising choices.

We may need to verify your identity and authority before completing a request. If an authorized agent submits a request for you, we may require proof of authorization and verification of your identity. We will respond within the period required by applicable law.

If we deny a request and your law provides a right to appeal, you may appeal by replying to our decision or emailing info@qr-codes.com with the subject line "Privacy Appeal."

14. California and Other U.S. State Privacy Disclosures

The categories of personal data we may have collected during the preceding 12 months include:

  • Identifiers, such as name, email address, postal address, Internet Protocol address, account identifier, and online identifiers

  • Customer-record information, such as contact and billing information

  • Commercial information, such as subscriptions, purchases, and transaction history

  • Internet or electronic network activity, such as browsing, application interactions, and QR Code scan activity

  • Geolocation data, including approximate location and, if permission is granted, more precise location

  • Inferences, such as preferences or likely interests derived from interactions with the Services

  • Sensitive personal information, such as account credentials and more precise geolocation when permission is granted. Stripe processes full payment card details through its payment interface

We collect these categories directly from individuals, automatically through the Services, from our customers, and from the service providers and partners described in this Policy. We use them for the purposes in Section 4 and disclose them to the recipients in Section 6.

We do not sell personal data for money. As explained in Section 9, disclosures of identifiers and online activity to analytics and advertising providers may be considered sale, sharing, or targeted advertising under some state laws. You may opt out where applicable.

We use sensitive personal information only for purposes permitted by applicable law, such as providing requested services, authenticating users, processing permitted location features, maintaining security, and preventing fraud, unless we provide additional notice.

15. Children

QR-Codes.com accounts and paid Services are intended for people who are at least 18 years old or the age of majority where they live. The Services are not directed to children under 13, and we do not knowingly collect personal data from a child under 13. If you believe a child has provided personal data to us, contact info@qr-codes.com so we can review and take appropriate action.

A publicly displayed QR Code may be scanned by anyone. Customers should consider their audience and comply with laws that apply to destination content intended for children.

16. Third-Party Destinations and Services

The Services may contain links to, or QR Codes may redirect to, third-party websites, forms, applications, files, and services. We do not control and are not responsible for their content, security, or privacy practices. Review the privacy notice of the destination before providing personal data.

17. Changes to This Policy

We may update this Policy to reflect changes to the Services, our practices, or applicable law. We will post the updated Policy and revise the "Last Updated" date. If a change materially affects how we use personal data, we will provide additional notice when required by law.

18. Contact Us

For privacy questions or requests, contact:

QR-Codes.com, LLC
ATTN: Privacy
P.O. Box 49
Chester, NY 10918
United States
Email: info@qr-codes.com

Last updated: September 1, 2026

1. Scope and Who We Are

This Privacy Policy explains how QR-Codes.com, LLC, which owns and operates QR-Codes.com, collects, uses, discloses, and protects personal data through our websites, application, QR Code redirection service, analytics tools, and related services. We refer to these collectively as the "Services."

In this Policy, "QR-Codes.com," "we," "us," and "our" mean QR-Codes.com, LLC.

This Policy applies to:

  • People who visit our website or application

  • People who create or manage QR Codes through an account

  • People who contact us, use support, or communicate with us

  • People who scan a dynamic QR Code that uses our redirection or analytics service

A QR Code may direct you to a website, form, application, file, or other destination controlled by a QR-Codes.com customer or another third party. The destination operator's privacy practices apply to information collected at that destination. QR-Codes.com does not control those independent privacy practices.

2. Important Information About QR Code Scans

Scanning a QR Code does not require a person to provide QR-Codes.com with a name, email address, phone number, postal address, or other direct identifier.

To redirect the scan, provide analytics, estimate unique scans, maintain reliability, and protect the Services, we may process limited technical and location-related information such as:

  • The QR Code or redirect link that was scanned

  • The date and time of the scan

  • Internet Protocol address

  • Approximate location derived from an Internet Protocol address, network information, or similar technical data

  • Device type or model, browser, operating system, language, and related technical information

  • Referral or campaign information when available

  • Identifiers or event data used to estimate unique scans, detect abuse, and maintain security

If a feature requests more precise location, the location is collected only after the scanner grants permission through the browser or device. Location accuracy can be affected by device settings, browser permissions, network routing, virtual private networks, mobile carriers, and other factors.

This scan data is not intended to directly identify an individual scanner. However, some privacy laws define Internet Protocol addresses, device identifiers, and location data as personal data. We therefore describe and protect this information as personal data where applicable.

Customers who own or manage a QR Code may receive analytics about scans of that code, such as scan counts, estimated unique scans, scan times, device information, and approximate locations. A standard scan alone does not provide the customer with the scanner's name, email address, phone number, or other direct contact information.

If the destination reached after a scan asks a person to submit contact information or other personal data, that is a separate interaction governed by the destination operator's privacy notice.

3. Personal Data We Collect

Account and Profile Data

When you create or manage an account, we may collect your name, email address, company information, country, account credentials, preferences, and other information you choose to provide.

QR Code and Customer Content

We process the information needed to create and operate QR Codes, including destination URLs, campaign names, designs, logos, files, settings, and other content you submit to the Services.

Scan Data

When a person scans a dynamic QR Code that uses our service, we may collect the scan data described in Section 2.

Billing and Transaction Data

We may collect billing contact information, subscription details, invoices, transaction status, and limited payment-method information made available to us by Stripe. Stripe, rather than QR-Codes.com, collects and processes full payment card details through its payment interface. We do not receive or store a full payment card number or card security code through that interface.

Communications and Support Data

We collect information that you provide when you contact us by email, contact form, support request, chat, social media, or another communication channel. This may include your contact details, message, attachments, and our response history.

Website and Application Usage Data

When you use our website or application, we and our service providers may collect:

  • Internet Protocol address

  • Browser, device, operating system, language, and time-zone information

  • Pages viewed, buttons or links selected, referring pages, and navigation activity

  • Log-in events, product interactions, errors, and performance information

  • Cookie identifiers, advertising identifiers, and similar technologies

  • General location derived from technical information

Marketing Data

We may collect your communication preferences, responses to emails, interactions with advertisements, and information used to measure campaigns or show relevant advertising, subject to applicable consent and opt-out requirements.

Information From Third Parties

We may receive information from service providers, analytics and advertising partners, payment processors, social networks, referral partners, and other sources. We use that information only for the purposes described in this Policy or as otherwise disclosed when it is collected.

4. How We Use Personal Data

We use personal data to:

  • Provide, operate, maintain, and improve the Services

  • Create, redirect, manage, and measure QR Codes

  • Estimate unique scans and provide campaign analytics

  • Create and administer accounts

  • Process subscriptions and transactions

  • Communicate with you and provide customer support

  • Personalize features and remember preferences

  • Monitor performance, diagnose errors, and maintain availability

  • Detect, investigate, and prevent fraud, abuse, malicious activity, and security incidents

  • Measure website, application, and advertising performance

  • Send service messages and, where permitted, marketing communications

  • Enforce our terms and protect our rights, users, and the public

  • Comply with legal, tax, accounting, regulatory, and reporting obligations

  • Establish, exercise, or defend legal claims

We may aggregate or de-identify information so that it is not reasonably linkable to an individual. We may use and disclose aggregated or de-identified information for lawful purposes and will not attempt to re-identify it except as permitted by law.

5. Legal Bases for Processing

If you are in the European Economic Area, United Kingdom, Switzerland, or another jurisdiction that requires a legal basis, we rely on one or more of the following:

  • Contract, when processing is necessary to provide the Services you request

  • Legitimate interests, including operating and improving the Services, providing scan analytics, securing the Services, communicating with customers, and understanding business performance

  • Consent, including for more precise location, nonessential cookies, certain advertising technologies, and marketing where consent is required

  • Legal obligation, when processing is necessary to comply with applicable law

When we rely on legitimate interests, we consider the nature of the data, the expected use of the Services, and the potential effect on individuals. You may have the right to object to this processing as described below.

6. How We Disclose Personal Data

We may disclose personal data to:

QR-Codes.com Customers

Customers who own or manage a QR Code may receive scan analytics for that code, as described in Section 2. A standard scan alone does not give a customer the scanner's name, email address, phone number, or other direct contact information.

Service Providers

We use service providers for cloud infrastructure, website hosting, payments, analytics, advertising, consent management, communications, customer support, security, and other business functions. Current providers may include:

  • DigitalOcean for application infrastructure and cloud services

  • Framer for the public website and related services

  • Stripe for payment processing and fraud prevention

  • Google for tag management, analytics, advertising, and conversion measurement

  • LinkedIn for advertising and conversion measurement

  • PostHog for product and usage analytics

  • Brevo, formerly Sendinblue, for communications, chat, and automation

  • Cookiebot for cookie consent management

These providers process information under their own terms, our instructions, or both, depending on the service and legal context. We may update our providers as our Services change.

Professional Advisers

We may disclose information to attorneys, accountants, auditors, insurers, and other professional advisers where reasonably necessary.

Legal and Safety Purposes

We may disclose information when we reasonably believe it is required by law, legal process, or a valid government request, or when necessary to protect the rights, property, safety, and security of QR-Codes.com, our users, or others.

Business Transactions

We may disclose or transfer information as part of a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar business transaction, subject to applicable law.

With Your Direction or Consent

We may disclose information when you direct us to do so or provide consent.

7. Our Role and Our Customers' Role

For account administration, billing, service security, our website and application analytics, and communications with you, QR-Codes.com generally acts as the controller or business responsible for the processing.

When a customer uses the Services to process personal data for its own purposes, the customer may be the controller or business, and QR-Codes.com may act as a processor or service provider on the customer's behalf. The roles depend on the context and applicable law. Customers are responsible for providing any notices, obtaining any consents, and establishing any legal bases required for their use of the Services and their destination content.

8. Cookies, Analytics, and Advertising

We and our providers use cookies, pixels, tags, local storage, and similar technologies for the following purposes:

  • Essential technologies needed for security, authentication, network management, and core functionality

  • Preference technologies that remember settings and choices

  • Analytics technologies that help us understand and improve use of the Services

  • Advertising technologies that measure campaigns and may help show relevant advertisements

On our public marketing website, we use Cookiebot to present cookie choices and manage nonessential technologies where consent is required. Cookiebot's Privacy Trigger is enabled. After a visitor records a consent choice, the trigger can be used to review or change that choice. You may also control cookies through your browser, although blocking essential technologies may affect the Services.

We do not respond to the older browser "Do Not Track" setting because there is no consistent industry standard for that signal. On our public marketing website, where required by applicable law, we treat a recognized Global Privacy Control signal or another qualifying universal opt-out mechanism as a request to opt out of sale, sharing, or targeted advertising for that browser or device.

9. Sale, Sharing, and Targeted Advertising

We do not sell personal data for money.

Some analytics and advertising technologies on our website or application may allow providers to collect identifiers and online activity for measurement, advertising, or cross-context behavioral advertising. Certain U.S. state laws may define those disclosures as a "sale," "sharing," or use for "targeted advertising," even when no money is exchanged.

Where applicable, you may opt out of advertising technologies on our public marketing website through Cookiebot's Privacy Trigger when displayed, a recognized universal opt-out signal, or by contacting us at info@qr-codes.com. We do not knowingly sell or share personal data of individuals under 16.

10. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including providing the Services, maintaining security and business records, complying with legal obligations, resolving disputes, and enforcing agreements.

Retention depends on factors such as:

  • How long an account, subscription, QR Code, or customer relationship remains active

  • The nature, sensitivity, and volume of the data

  • Whether the information is needed to provide analytics or maintain the Services

  • Security, fraud-prevention, backup, and disaster-recovery needs

  • Tax, accounting, payment, regulatory, litigation, and legal-preservation requirements

  • A user's deletion request and any applicable legal exceptions

Backups may retain information for a limited period after it is removed from active systems. We may retain de-identified or aggregated information where it no longer identifies an individual.

11. Security

We use administrative, technical, and organizational measures designed to protect personal data. These measures include encryption in transit, access controls, secure session controls, software updates, monitoring, backups, and limits on administrative access.

Our application infrastructure uses DigitalOcean, whose cloud platform maintains SOC 2 Type II and SOC 3 Type II certifications issued by an independent auditor. We combine that infrastructure with application-level safeguards and use Stripe to process full payment card details through Stripe's payment interface.

No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we work to prevent, detect, and respond to security issues. If a legally reportable breach occurs, we will provide notices as required by applicable law.

For more information, visit our Security page at https://www.qr-codes.com/security.

12. International Data Transfers

QR-Codes.com is based in the United States, and we and our providers may process information in the United States and other countries. Those countries may have privacy laws that differ from the laws where you live.

Where required, we use an appropriate transfer mechanism, which may include the European Commission's Standard Contractual Clauses, the applicable United Kingdom or Swiss transfer terms, a valid adequacy decision, or another mechanism recognized by law. Our providers may rely on their own approved transfer mechanisms where appropriate.

13. Your Privacy Rights

Depending on where you live and subject to legal exceptions, you may have the right to:

  • Know whether we process your personal data

  • Access or obtain a copy of your personal data

  • Correct inaccurate personal data

  • Delete personal data

  • Receive certain data in a portable format

  • Restrict or object to certain processing

  • Withdraw consent at any time where processing is based on consent

  • Opt out of sale, sharing, targeted advertising, or certain profiling

  • Limit certain uses of sensitive personal information

  • Appeal a decision concerning a privacy request

  • Not be discriminated against for exercising a privacy right

  • Complain to a data protection authority

To submit a request, email info@qr-codes.com with the subject line "Privacy Request" or write to the address in Section 18. You may also use Cookiebot's Privacy Trigger when displayed to review or change cookie and advertising choices.

We may need to verify your identity and authority before completing a request. If an authorized agent submits a request for you, we may require proof of authorization and verification of your identity. We will respond within the period required by applicable law.

If we deny a request and your law provides a right to appeal, you may appeal by replying to our decision or emailing info@qr-codes.com with the subject line "Privacy Appeal."

14. California and Other U.S. State Privacy Disclosures

The categories of personal data we may have collected during the preceding 12 months include:

  • Identifiers, such as name, email address, postal address, Internet Protocol address, account identifier, and online identifiers

  • Customer-record information, such as contact and billing information

  • Commercial information, such as subscriptions, purchases, and transaction history

  • Internet or electronic network activity, such as browsing, application interactions, and QR Code scan activity

  • Geolocation data, including approximate location and, if permission is granted, more precise location

  • Inferences, such as preferences or likely interests derived from interactions with the Services

  • Sensitive personal information, such as account credentials and more precise geolocation when permission is granted. Stripe processes full payment card details through its payment interface

We collect these categories directly from individuals, automatically through the Services, from our customers, and from the service providers and partners described in this Policy. We use them for the purposes in Section 4 and disclose them to the recipients in Section 6.

We do not sell personal data for money. As explained in Section 9, disclosures of identifiers and online activity to analytics and advertising providers may be considered sale, sharing, or targeted advertising under some state laws. You may opt out where applicable.

We use sensitive personal information only for purposes permitted by applicable law, such as providing requested services, authenticating users, processing permitted location features, maintaining security, and preventing fraud, unless we provide additional notice.

15. Children

QR-Codes.com accounts and paid Services are intended for people who are at least 18 years old or the age of majority where they live. The Services are not directed to children under 13, and we do not knowingly collect personal data from a child under 13. If you believe a child has provided personal data to us, contact info@qr-codes.com so we can review and take appropriate action.

A publicly displayed QR Code may be scanned by anyone. Customers should consider their audience and comply with laws that apply to destination content intended for children.

16. Third-Party Destinations and Services

The Services may contain links to, or QR Codes may redirect to, third-party websites, forms, applications, files, and services. We do not control and are not responsible for their content, security, or privacy practices. Review the privacy notice of the destination before providing personal data.

17. Changes to This Policy

We may update this Policy to reflect changes to the Services, our practices, or applicable law. We will post the updated Policy and revise the "Last Updated" date. If a change materially affects how we use personal data, we will provide additional notice when required by law.

18. Contact Us

For privacy questions or requests, contact:

QR-Codes.com, LLC
ATTN: Privacy
P.O. Box 49
Chester, NY 10918
United States
Email: info@qr-codes.com

Last updated: September 1, 2026

Generate fully customized QR Codes with color, shape and logo, plus track the time and location of every scan.

Use Cases

Marketing

Mobile Payments

Real Estate

Retail Promotions

Product Information

Resources

QR Code Analytics

QR Code for Google Reviews

QR Code for Android and IOS Apps

Custom QR Code Design Features

Tools

QR Code Decoder

Custom Domains

Live Notifications

Support

FAQs

Contact

© 2026 QR-Codes.com

QR Code is a registered trademark of DENSO WAVE INCORPORATED

Terms of Service

Privacy Policy

Copyright Policy

Accessibility Policy

Generate fully customized QR Codes with color, shape and logo, plus track the time and location of every scan.

Use Cases

Marketing

Mobile Payments

Real Estate

Retail Promotions

Product Information

Resources

QR Code Analytics

QR Code for Google Reviews

QR Code for Android and IOS Apps

Custom QR Code Design Features

Tools

QR Code Decoder

Custom Domains

Live Notifications

Support

FAQs

Contact

© 2026 QR-Codes.com

QR Code is a registered trademark of DENSO WAVE INCORPORATED

Terms of Service

Privacy Policy

Copyright Policy

Accessibility Policy

Generate fully customized QR Codes with color, shape and logo, plus track the time and location of every scan.

Use Cases

Marketing

Mobile Payments

Real Estate

Retail Promotions

Product Information

Resources

QR Code Analytics

QR Code for Google Reviews

QR Code for Android and IOS Apps

Custom QR Code Design Features

Tools

QR Code Decoder

Custom Domains

Live Notifications

Support

FAQs

Contact

© 2026 QR-Codes.com

QR Code is a registered trademark of DENSO WAVE INCORPORATED

Terms of Service

Privacy Policy

Copyright Policy

Accessibility Policy