Privacy Policy

Draft content — not yet reviewed by a lawyer. This page describes our actual data practices but still needs legal review, and the bracketed placeholders below (company name, address, contact email, jurisdiction) filled in, before this site accepts real users or payments.

Last updated: [date]

1. Who we are

MyPersonalQR ("we", "us") provides a QR code creation, hosting, and analytics service at this website. This policy explains what personal data we collect when you use it and why.

Legal entity: [company legal name]. Registered address: [registered address]. Data protection contact: [privacy contact email].

2. What we collect

  • Account data: your email address (used for one-time-code sign-in), and optionally a name/avatar if you sign in with a third-party provider.
  • QR code content: whatever you enter into a QR code — a destination URL, Wi-Fi credentials, a vCard's contact details, a menu, a business profile, and so on. This is your content; see Section 5 of our Terms for how we use it.
  • Scan data: when someone scans one of your dynamic QR codes, we record the timestamp, the IP address the request came from, a country/city derived from that IP, and coarse device/OS/browser information.
  • Payment data: if you subscribe to a paid plan, card details are collected and processed directly by Stripe, our payment processor — we never see or store your full card number.
  • Server logs: standard technical logs (request URLs, status codes, timestamps) kept for operating and securing the service.

3. How we use it

To operate your account and QR codes, show you scan analytics, process subscription payments, keep the service secure and prevent abuse (e.g. bot-checking anonymous downloads), and respond to support requests. We do not sell your personal data. We only send marketing/product email if you've separately opted in to receive it.

4. Scan data & retention

Raw scan records (IP address, timestamp, coarse location, device info) are kept for as long as the associated QR code and account exist, so you can see historical analytics for that code. If you delete (archive) a QR code or your account, its associated scan history is deleted or de-identified along with it. We do not currently run a separate automatic-anonymization job on a fixed schedule shorter than this — if your jurisdiction requires a stricter retention limit, treat this section as needing further legal review before launch.

5. Your rights (GDPR)

If you are in the EU/UK, you have the right to access, correct, delete, export, and object to our processing of your personal data, and to withdraw consent at any time. To exercise any of these rights, contact us at [privacy contact email]. You also have the right to lodge a complaint with your local data protection authority.

6. Cookies

We set one essential, httpOnly session cookie (mpqr_session) to keep you signed in — it is required for the service to function and isn't used for advertising or cross-site tracking, so it doesn't require consent under most cookie-law frameworks. The QR builder also stores your in-progress, unpublished draft in your browser's local storage so you don't lose it on refresh; this never leaves your device until you save. See our cookie banner for how to manage preferences.

7. Third parties

  • Stripe — payment processing for paid subscriptions (stripe.com/privacy).
  • Hosting provider — [hosting provider name], for running our servers and database.
  • Email delivery provider — [email provider name], for sending sign-in codes and transactional email.
  • If you sign in with Google, Apple, Meta, Microsoft, GitHub, or LinkedIn, that provider processes your authentication per its own privacy policy.

8. Contact

For any privacy question or request, contact us at [privacy contact email].