Privacy Policy

Last updated: September 12, 2026

1. Who We Are

QRtracer ("we", "us", "our") is a free QR code generator with optional scan tracking. Here's what we collect and why.

2. Data We Collect

2.1 Account holders

When you create an account, we store your email address and a hashed password. We need this to run your dashboard.

2.2 QR code scan analytics

When someone scans a tracked QR code we store: approximate country and city (from the request edge, not a stored IP), device type, browser, operating system, timestamp, and an HMAC IP hash salted with the UTC date. The hash is same-day only — it cannot link a visitor across days. New scans do not store a raw IP. Historical rows may still contain an IP until we complete a one-time null-out (flagged for review). We do not collect names or emails from scanners.

2.3 QR generation events

We record successful QR creation events to count generator usage, including creation without an account. New records contain the destination domain, generator source, timestamp, tracking status at creation, and your account ID if you are signed in. The generation log does not retain destination paths, query strings, IP addresses, or browser user-agents for new events. Older records may contain those fields. This operational log is separate from optional site analytics.

2.4 Optional site analytics

If you accept analytics, Google Analytics, Vercel Web Analytics, and Vercel Speed Insights may receive a scrubbed page path and technical information needed to measure visits, product actions, and performance. We remove query strings and redact likely identifiers from paths before sending them. Advertising storage, advertising user data, and ad personalization signals are disabled. These services are not loaded before you accept.

3. How We Use Your Data

  • To provide and improve QRtracer's services
  • To display scan analytics in your dashboard
  • To send transactional emails (verification, password reset)

We do not sell personal data or use site analytics for advertising.

4. Data Processor

We use Supabase as our database and authentication provider. Supabase acts as a data processor on our behalf. If you accept optional analytics, Google and Vercel also process the analytics and performance data described above. Their processing locations and retention are governed by our service configuration and their applicable terms.

5. Your Rights (GDPR)

EU/EEA residents can:

  • Access their personal data
  • Correct or delete their data
  • Export their data
  • Object to processing
  • Withdraw consent at any time

To exercise any of these rights, contact us at privacy@qrtracer.io.

6. Cookies

QRtracer uses essential browser storage for authentication and product preferences. We store your analytics choice in localStorage. If you accept analytics, Google Analytics may set measurement cookies; you can withdraw consent at any time through the Privacy settings button. Declining analytics does not affect QR creation or account features.

7. Data Retention

Account data is retained while your account is active. Scan user-agent and referrer are trimmed after 180 days; parsed device/browser/OS, country, city, and bot flags stay. Aggregates are kept. You can export or delete your account from Settings — deleting an account deletes your codes (printed codes will stop resolving) and cascaded scans.

8. Changes to This Policy

If we change this policy, we'll email registered users about anything significant.

9. Contact

For privacy-related questions, email privacy@qrtracer.io. For anything else, reach us at hello@qrtracer.io.