Privacy policy
Last updated:
This policy covers people who use a QRCodeTransfer account and people who interact with a shared QR code, link, page or form. The information involved depends on the action you take. A link destination or the organization that created a form may have its own privacy notice.
Who uses the information
QRCodeTransfer uses account and contact information to provide and protect the service and respond to requests. A workspace member chooses the content and questions that their workspace publishes. For information collected through a customer's form, that customer determines its purpose; we provide the storage and access needed for their use of the service.
Account and workspace information
Registration and workspace activity can involve your name, email address, password-derived security data, membership role, session records and the assets you create. Uploaded documents, logos, destination URLs, page content and settings can also contain information about you or other people. Only supply information you are entitled to use.
Contact messages may include your name, email address, the question or report you send and any attachment you choose to provide. This information is used to handle the request. Avoid putting passwords, payment details or unnecessary sensitive records into a message or screenshot.
Scans, clicks and device information
A dynamic redirect can record its asset, the visit time, browser information and a derived visitor identifier. The identifier is used to estimate distinct scans within the chosen workspace and date range; it is not a count of identified people. The scan-event records do not store the raw IP address, but connection and infrastructure logs may handle IP information to deliver and protect a request.
Static QR codes contain their destination or other data directly. Scanning one does not go through our redirect service, so we do not receive that static scan. The destination you open may collect its own information.
Optional precise location
A workspace can ask a visitor to share precise location through an enabled dynamic code. Coordinates are collected only after explicit permission and are made available to that workspace. Refusing permission or a failed location request does not prevent continuing to the destination. Review the requester and purpose before consenting; browser permission can also be managed in your device settings.
Forms and submitted information
When you submit a form, the answers and permitted uploads are stored for the workspace that owns it, together with the applicable form version and submission records. A browser visitor identifier can help prevent repeated submissions. The form creator decides which questions to ask and who in their workspace can access the answers.
Information for form creators
Explain your identity, purposes, required fields, sharing and retention to respondents. Obtain a lawful basis and any consent needed for your collection. Your own notice must cover how you use responses after exporting them; it is not replaced by this policy. Do not collect authentication secrets or sensitive data without appropriate arrangements.
Forms on another website
A third-party site can direct people to a form or display shared content. That site may collect information separately. Check both the form creator's notice and the surrounding website's privacy practices, particularly before providing personal information or an upload.
Why information is processed
- To create and maintain accounts, determine workspace access, store content and make chosen assets available to their intended audience.
- To produce scan reports, handle form responses, carry out requested integrations, answer contact requests and maintain records of important account actions.
- To validate inputs, investigate errors or abuse, protect credentials and respond to lawful requests. Information should be used for a purpose connected to the service or otherwise explained to the person concerned.
Cookies and browser storage
What these technologies do
Cookies are small values a browser sends back to a site. Local storage can retain values on the same device. They do not give a website general access to all files on your computer. Some values support a sign-in session; others preserve a language choice or a QR design that you are preparing.
How this service uses them
The service uses session cookies for sign-in and workspace access, preference storage for language, and temporary browser state for selected workflows. A form or optional location flow may use a visitor value to handle its interaction. These functions are distinct from measuring a dynamic redirect's server-side scan activity.
Your browser choices
You can clear or block cookies and local storage through browser settings. Signing in, retaining a draft or preventing duplicate form submissions may then work differently. On a shared device, sign out and remove drafts containing information you do not want another person to see.
Purposes and legal bases
The relevant basis depends on the information, the person responsible and the law that applies. Providing an account or a requested feature can involve fulfilling an agreement. Protecting the service can involve a legitimate security interest. Optional precise location requires consent. Responding to a binding legal obligation can require retaining or disclosing specific records.
Balancing security and privacy
Access checks, derived visitor identifiers and audit records help protect the service and understand activity. These controls should be proportionate to their purpose. A customer collecting answers through a form must identify its own lawful basis and must not assume that a QRCodeTransfer account authorizes every type of data collection.
Sensitive information
Do not place unnecessary health, identity, financial or other sensitive records into public content, a general form or a support attachment. A service feature being able to accept text or a file is not an assurance that it meets special legal, industry or contractual requirements for that information.
Access, sharing and service providers
Authorized workspace members can access the information their permissions allow. Published pages, forms, files and redirect destinations can be available to people holding their link. Support or administrative access may be necessary to handle a request, investigate misuse or maintain the service. Do not treat a public link as a confidential access control.
An enabled integration sends the information needed for the action you request to the connected service. That service applies its own rules. We do not sell or rent your personal information. Disclosure required by law or necessary to protect lawful rights is assessed in the circumstances. Ask about providers and processing arrangements before sharing data subject to specific contractual restrictions.
Location and transfer requirements
Where your organization or respondents are located can affect the rules that apply to a transfer or service arrangement. If you require a particular hosting region, transfer safeguard or processing agreement, discuss it with us before providing the affected data. This page does not promise a data-center location or an approved international-transfer arrangement.
Storage, retention and removal
Account records, workspace content, file versions, responses and security records support different purposes. Pausing or unpublishing an asset removes an access route; it does not automatically erase every associated record. A recycle-bin action can retain material for restoration. Contact us about removing an account or information beyond those product actions.
A deletion request must also consider lawful recordkeeping, outstanding requests, security needs and the rights of others. We do not state a universal retention period for every data category. Describe the record and purpose in a request so the relevant scope and restrictions can be assessed.
Protecting information
The service separates workspace access, protects passwords with one-way derivation, controls access to session and API credentials, and validates supported uploads. Users also need to choose suitable permissions and protect exported data. No online service can remove every risk. The security page explains these controls and how to report a concern.
External destinations and public sharing
A linked website, app store or embedded service may process information after you leave QRCodeTransfer. Its policy applies to that interaction. Files and QR data can contain information you supplied, including contact details or Wi-Fi credentials. Check what will become public before downloading, printing or publishing it.
Your privacy choices and rights
Depending on applicable law, you may be able to request access, correction, deletion, restriction, portability or an objection to processing. You can also withdraw consent for an optional purpose, without changing the lawfulness of earlier processing. Some requests are subject to exceptions that protect legal obligations or other people's rights.
If your request concerns a customer's form response or published content, contact the organization that collected or published it as well. It may hold an exported copy outside our service. A change made in QRCodeTransfer cannot by itself remove data from another organization or from printed materials.
Making a request and verifying ownership
Use the contact page and explain the information or account involved and the action you seek. To protect others, we may ask for proportionate evidence that you can act for the account or person concerned. Do not send a government identity document or password unless a specific, appropriate verification process has first been agreed.
Questions and complaints
Contact us if you believe information has been mishandled, and include enough detail to locate the issue without exposing unnecessary personal data. Applicable law may also let you complain to a relevant data-protection authority or seek another remedy. A contact request does not prevent exercising those rights.
Updates and further information
The update date identifies this version. Review this policy when using a new feature or sharing information for a new purpose. Material changes will be reflected here and any notice required by applicable law will apply. The terms, security page, help center and contact page provide related information.