Privacy Policy

Effective August 21, 2026

This policy describes what QRCR.us collects, why, and what we do with it. The short version: we collect the minimum needed to run the service and keep it safe from abuse, we set no cookies when a code is scanned, and we never sell data to anyone.

1. If you have an account

When you sign in with Google we receive and store your email address, your name, and your profile picture URL, along with a Google account identifier used to recognize you on future sign-ins. We also store the links you create (destination URL, title, QR style, timestamps), your credit balance, and a ledger of credit purchases and spends. You may optionally tell us your business name, what you use QR codes for, and how you heard about us on your Account page; these details are never required, never shown publicly, and used only to understand our customers and improve the service.

2. If you scan a QRCR code

When a code is scanned we record the time of the scan, the referring page if your browser sends one, and your browser's user-agent string. This is shown to the link's owner as scan statistics. We also record the scan's IP address, used solely for rate limiting and abuse prevention — it is not shown to link owners. We set no cookies on scans (scan redirects and the paused page carry no analytics), and we do not build profiles of scanners or track them across links or sites. The redirect is the whole product.

3. Payments

Purchases are processed by Stripe. Your card number never touches our servers; we store only a Stripe transaction reference and the number of credits purchased.

Email we send you

We send a small number of transactional emails to the address on your Google account: a welcome note when you sign up, a tip sheet when you create your first code, a warning when your balance runs low, a notice when your codes pause because the balance hit zero, and a confirmation when a purchase lands. Each is triggered by something that happened on your own account. We do not send newsletters or marketing email. These messages are delivered by Resend, which processes your email address and the message content in order to deliver it.

4. Cookies and analytics

We use a signed session cookie to keep you logged in. Our website pages (the homepage, guides, and your dashboard — not scan redirects) use Google Analytics, which sets cookies to help us understand how the site is used. There are no advertising cookies.

5. Service providers

We rely on a small set of processors to operate: Google (sign-in and website analytics), Stripe (payments), Resend (transactional email), and Cloudflare (network proxying and denial-of-service protection — Cloudflare processes visitor IP addresses in transit as part of serving the site). Our servers are hosted in the United States. Each provider processes data under its own privacy policy.

6. How we use data

To operate the service: authenticate you, serve and track your links, bill scans against your balance, and answer support requests. We do not sell or rent personal data, and we do not share it with third parties except the processors above or where the law requires.

7. Retention and deletion

Deleting a link permanently deletes its scan history. You can delete your account and all associated data yourself at any time from your Account page, or by emailing [email protected] from your account's address — note that unused credits are forfeited on deletion (see the Terms of Service). Purchase records may be retained where required for tax and accounting purposes.

8. Security

Traffic is encrypted in transit, sessions are signed, and access to production systems is restricted. No system is perfectly secure; if a breach affects your data, we will notify you at your account email.

9. Children

The service is not directed at children under 13, and we do not knowingly collect their personal information.

10. Changes and contact

Updates to this policy appear on this page with a new effective date. Questions: [email protected].