QRSyncHQ

Privacy Policy

Last updated: August 8, 2026

This page describes exactly what QRSyncHQ collects, why, and what it does not. Where the product changes, this page is meant to change with it — it is written to match the code, not a template filled in once and forgotten.

What we collect

Account information: the name and email address you register with, and a cryptographically hashed copy of your password — never the password itself. If we are ever breached, there is no plaintext password to steal.

Signup country: a best-effort two-letter country code read from your connection at the moment you register, used only in the admin panel to understand where accounts come from. It is not refreshed afterward and does not track your location on later visits.

Scan analytics — dynamic codes only: when someone scans a dynamic QR code you created, we record the timestamp, a coarse device type (mobile, tablet or desktop), operating system, referrer, and a best-effort country. This is what powers the analytics dashboard on your own account.

Nothing for static codes: a static QR code (a WiFi network, a contact card, plain text, a fixed link) is generated entirely inside your browser. Its contents never reach our servers, whether or not you have an account, and no data is collected when it is scanned.

Cookies

Exactly two cookies exist, and both are strictly necessary for the service to function — neither is used for advertising or cross-site tracking, and no third-party tracking cookie is set by this application.

A session cookie, set when you sign in, that identifies your account to the server on each request.

A guest cookie, set only if you create a QR code before registering, that remembers which anonymous trial code is yours so it can be handed over to your account when you sign up. It carries no identity of its own.

Because both are strictly necessary and neither is used for tracking or advertising, this site does not show a cookie-consent banner — there is nothing optional to ask consent for.

How we use what we collect

To operate your account: authenticate you, enforce the limits of your plan, and show you the codes and analytics that belong to you.

To send transactional email only: an address-confirmation code at registration, a password-reset code when you request one, and a notice if a paid plan lapses. We do not send marketing email, and nothing here is used to build an advertising profile.

Who we share it with

Our email-delivery provider, solely to transmit the transactional messages above — it sees the recipient address and message content, nothing more.

If a paid plan is active on your account and billing is live, a payment processor handles that transaction directly; we do not receive or store your card details.

We do not sell personal data, and we do not share it with anyone else.

How long we keep it

Account and code data is kept for as long as your account exists. Deleting your account removes your personal information; if you would like this done manually, contact us using the details below.

Your rights

You may ask to see, correct, or delete the personal data we hold about you at any time, using the contact details below.

Children

This service is not directed at children, and we do not knowingly collect data from anyone under the age required by their local law to hold an account without parental consent.

Changes to this policy

If what we collect or how we use it changes, this page is updated and the date above reflects it. Material changes will be communicated to registered accounts by email.

Contact

Questions about this policy can be sent to privacy@qrsynchq.dev.