Effective August 11, 2026
This policy describes what QRCR.us collects, why, and what we do with it. The short version: we collect the minimum needed to run the service, we don't store scanners' IP addresses, and we never sell data to anyone.
When you sign in with Google we receive and store your email address, your name, and your profile picture URL, along with a Google account identifier used to recognize you on future sign-ins. We also store the links you create (destination URL, title, QR style, timestamps), your credit balance, and a ledger of credit purchases and spends.
When a code is scanned we record the time of the scan, the referring page if your browser sends one, and your browser's user-agent string. This is shown to the link's owner as scan statistics. We do not store your IP address, we set no cookies on scans, and we do not build profiles of scanners or track them across links or sites. The redirect is the whole product.
Purchases are processed by Stripe. Your card number never touches our servers; we store only a Stripe transaction reference and the number of credits purchased.
We use a single signed session cookie to keep you logged in. There are no analytics or advertising cookies.
We rely on a small set of processors to operate: Google (sign-in), Stripe (payments), and Cloudflare (network proxying and denial-of-service protection — Cloudflare processes visitor IP addresses in transit as part of serving the site). Our servers are hosted in the United States. Each provider processes data under its own privacy policy.
To operate the service: authenticate you, serve and track your links, bill scans against your balance, and answer support requests. We do not sell or rent personal data, and we do not share it with third parties except the processors above or where the law requires.
Deleting a link permanently deletes its scan history. To delete your account and all associated data, email [email protected] from your account's address — note that unused credits are forfeited on deletion (see the Terms of Service). Purchase records may be retained where required for tax and accounting purposes.
Traffic is encrypted in transit, sessions are signed, and access to production systems is restricted. No system is perfectly secure; if a breach affects your data, we will notify you at your account email.
The service is not directed at children under 13, and we do not knowingly collect their personal information.
Updates to this policy appear on this page with a new effective date. Questions: [email protected].