Security & Compliance
Your QR codes and links can be important contact points for your customers. This page explains the controls used by QRCodeTransfer and the choices that help you protect accounts and shared information.
It describes product behavior, not an independent security certificate.
Account and technical controls
Password protection
Passwords are stored using a one-way, salted derivation rather than as readable passwords. Use a unique password and do not send it to support or another workspace member. A secure password cannot protect an account if it is disclosed or reused on a compromised service.
Session protection
Sign-in uses a session cookie that ordinary page scripts cannot read. The service checks the session for private requests, and signing out invalidates it. Sign out before leaving a shared device. If someone else can use your unlocked browser, a session cookie alone cannot stop them acting as you.
Workspace roles and access
Private requests are checked against the actual account, workspace and membership. A viewing role is not permission to edit or manage billing. Owners should grant the least access needed, review members and remove access when responsibilities change. Data from another workspace is not made available merely by changing a workspace number in a URL.
API keys and webhook secrets
API requests are checked for the workspace, supported plan and permitted read or write operations. New keys and webhook signing secrets are displayed once when issued. Store them privately and revoke exposed credentials. Giving a key to an integration gives that integration the access the key permits.
Files, logos and rendering
Supported uploads are checked for type, size and ownership. Logo and image rendering have additional bounds, and download conversion rejects active or external SVG resources. Do not assume an allowed file is harmless or private; inspect it before sharing and keep sensitive material out of public links.
Connections and sign-in options
Check the site address and use a secure HTTPS connection when entering account information. Do not bypass a browser security warning. Only rely on the sign-in options actually offered by the service; a disabled single sign-on or recovery option does not provide extra protection for an account.
Form and response safeguards
Response access and publication
Form responses are associated with the form's owning workspace and require appropriate access to review them. Publishing a form exposes its questions to visitors, not the private response list. Keep the collection purpose clear and limit the people who can export or otherwise use responses.
Validation and repeated submissions
The service validates submitted answers against the published form schema and applies configured response rules. Submission identifiers and browser visitor state can reduce accidental duplicates. A browser-based repeat restriction is not identity verification and can be affected by clearing storage or changing a device.
Respondent uploads
A form's upload field must use its designated upload flow and supported formats. The form creator remains responsible for whether requesting an image is appropriate. Respondents should not attach unnecessary identity, financial or health records to an ordinary form.
Visitor identifiers and privacy
Derived visitor values support specific interaction controls. They are not proof of a real person's identity. Browser and connection information can still be personal data in some circumstances. Form creators should describe their collection and should not present a scan estimate as a list of identified visitors.
Operational responsibilities
Administrative and support access
Workspace permissions protect ordinary account access. Administrative or support access may be needed to investigate a reported issue or protect the service, and important business actions can be recorded for audit. When contacting support, send only what is needed to locate the problem and remove secrets from screenshots.
Versions, backups and retention
File versions and saved records serve different purposes from backups. Do not assume that a recycle bin provides disaster recovery or that closing a link erases all related records. Keep your own required exports. Discuss recovery, backup or retention requirements before relying on the service for critical records; this page makes no fixed recovery-time promise.
Reporting a security concern
Use the contact page to report a suspected compromise or vulnerability. Include the affected feature, approximate time and steps needed to understand the issue, but omit passwords, live API keys and unnecessary personal records. Do not access another person's data or disrupt the service to demonstrate a finding.
Hosting and independent assurance
Requirements for hosting location, encryption at rest, infrastructure protection and independently audited standards should be agreed on their actual evidence. No SOC 2, ISO certification or provider-specific assurance is claimed here. Ask for the information relevant to your organization before uploading data that depends on such a requirement.
Privacy and responsible sharing
What scan reporting means
Dynamic scan reports use recorded visit activity and an estimated distinct visitor value. The scan-event records do not contain raw IP addresses; infrastructure handling is a separate matter. Static scans do not reach our redirect service. Review the privacy policy for the information involved and the limits of these measures.
Explicit location choice
Precise location is optional and requires an explicit permission step. A refusal or failed request can continue to the intended destination. Coordinates supplied with permission are available to the workspace that asked for them. Check the purpose and requester before agreeing.
Processing agreements and special requirements
If your organization needs a data-processing agreement, a specific retention period, residency restrictions or audit evidence, raise those requirements before sharing the affected information. A feature's availability or a contact inquiry does not itself establish a signed agreement or prove regulatory compliance.
Further information and changes
Read the terms and privacy policy alongside this page. Product controls can change as features change, so review the update date and current options when assessing a new use. The help center explains ordinary tasks; use the contact page for a concern specific to your account or security requirements.
Last updated:
Back to top ↑