Privacy Policy
Last updated: 2026-07-24
This policy explains what QRvora collects, why we collect it, how long we keep it, and what you can do about it. The product was built to need as little personal data as possible, and the sections below say exactly where that holds and where it does not.
Two different roles we play
This distinction decides who is responsible for what, so it comes first rather than buried at the end.
- For your account, we are the data controller. You gave us your details, and this policy governs them.
- For scans of your codes, you are the controller and we are your processor. The scan data belongs to your relationship with the person scanning. If you point a code at a page that collects personal data, or you enable your own analytics on a hosted page, that processing is yours to disclose and justify, not ours.
What we collect
Account data. Your name, email address, and a password stored only as a salted scrypt hash. We cannot read your password. We also store your plan, trial dates, and any brand name you set.
Scan analytics. When someone scans a dynamic code we record the time, the coarse location our host reports (country and city), the device type, and the operating system. We do not store the scanner's IP address. To tell repeat scanners from new ones we store a one way hash of the IP, the browser user agent and the date, combined. It cannot be reversed, and because the date is part of it, the same person produces a different value tomorrow.
Content you create. Code names, destination URLs, hosted page content, and any files you upload. Uploaded files are stored privately and are served only through an access-checked route.
Feedback left by scanners. If you use a feedback code, we store the rating and comment. We do not ask the scanner for their identity.
Security and abuse data. To rate limit sign ins, password resets and other sensitive actions we briefly store a counter keyed to an IP address. These rows are deleted within 24 hours. Server error logs may incidentally contain an IP address.
Payments. Card details never reach our servers. Our payment provider acts as Merchant of Record and handles the transaction; we receive only the plan, its status, and billing period dates.
What we do not collect
- Raw IP addresses attached to scan records.
- Card numbers or bank details.
- Advertising or cross site tracking identifiers of our own.
- Any special category data. Please do not put it in code names, page content or feedback prompts.
Cookies
We set only strictly necessary cookies. There is no advertising or profiling cookie set by us, which is why you are not asked to consent to one.
qrf_session— keeps you signed in. Stored as a hash server side, expires after 30 days.qrf_ws— remembers which team workspace you are viewing.qrf_unlock_<code>— proves you entered the password for a protected code. Expires after one hour.qrf_admin,qrf_admin_setup— operator sign in for our own staff console.
Separately: if a paid customer enables Google Analytics or a Meta pixel on their own hosted page, that page will set the third party cookies those tools use. That is the customer's choice and their responsibility to disclose to visitors.
Why we are allowed to process it (UK/EU GDPR)
- Contract. Running your account, serving your redirects, and taking payment.
- Legitimate interests. Keeping the service secure, preventing abuse and fraud, and understanding aggregate usage. We balanced this against the privacy design above, which is why scan records carry no raw IP.
- Legal obligation. Tax and accounting records, and responding to lawful requests.
Who else processes it
We use a small number of subprocessors. Each is bound by contract and may use the data only to provide their service to us.
- Hosting. Our application, database and file storage run on infrastructure providers, so your account and content are stored there.
- Email delivery. Your address and the message are passed to an email provider to send verification, password reset and expiry notices.
- Payments. Handled by a Merchant of Record who is the seller for the transaction and processes card details. We never receive them.
Other services we use, such as scheduled task execution and URL safety checking, receive no personal data.
Some providers operate outside the UK and EEA. Where they do, transfers rely on the UK IDTA or EU Standard Contractual Clauses as applicable. Business customers who need each provider named for a due-diligence review or a data processing agreement can ask us for the current list.
How long we keep it
- Account and content: until you delete the account.
- Dynamic codes: a code stops redirecting at the end of its active window, which is 12 months from creation on the free plan, or the life of a paid plan plus 30 days. The record remains in your dashboard until you delete it.
- Scan records: retained while the code exists, and deleted with it. Aggregated daily counts are kept for reporting.
- Rate limit counters: under 24 hours.
- Queued jobs and webhook delivery logs: 30 days.
- Billing records: as long as tax law requires.
Your rights
You can access, correct, export, delete, restrict or object to our use of your data, and complain to a regulator. Two of these do not need to go through us at all:
- Export: https://qrvora.com/dashboard/settings/export returns your data as JSON, immediately.
- Deletion: deleting your account from Settings removes your codes, scans, files, API keys and webhooks. It cannot be undone, and every code you created stops redirecting at once.
For anything else, get in touch. We answer within 30 days. If you are in the UK you may complain to the ICO; in the EEA, to your local supervisory authority.
Security
Passwords are hashed with scrypt and a per user salt. Sessions are stored as hashes, not as readable tokens. Uploaded files are private and pass an access check on every request. Operator access is separated from customer accounts and requires a second factor. No system is perfectly secure, and we will tell you and the relevant regulator about a breach affecting your data within the timeframes the law sets.
Children
The service is not for children under 16, and we do not knowingly collect their data. Tell us if you believe a child has an account and we will remove it.
Changes
We will update this page when what we do changes, and we will change the date at the top. If a change materially affects your rights we will email you rather than rely on you noticing.