Privacy Policy

Last updated: May 18, 2026

1. Introduction

QR Node (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, which includes dynamic and static QR code creation, URL shortlinks, hosted landing pages, digital vCards, link-in-bio pages, and file hosting (collectively, the “Service”).

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, password, and billing information.
  • QR Code Content: Target URLs, custom names, descriptions, and design preferences.
  • Shortlinks: Short codes, original URLs, expiry settings, and metadata.
  • Landing Page Content: Text, images, CTAs, and configuration you enter when building hosted landing pages.
  • Digital vCard Data: Name, job title, company, phone numbers, email addresses, social media profiles, bio, and profile photo that you add to a vCard.
  • Link-in-Bio Configuration: Profile information, link titles, URLs, and layout preferences for link-in-bio pages.
  • Uploaded Files: Documents, images, audio, and video files you upload to the file-hosting feature, together with any title or description you provide.
  • Organization Data: Folder names, tags, and organizational structures.
  • Payment Information: Billing details are processed securely by our payment processor (Paddle). We do not store card numbers on our servers.

2.2 Automatically Collected Information

  • Scan Analytics: Timestamp, geographic location (city/country), device type, operating system, and browser information
  • Usage Data: Features accessed, pages viewed, time spent, and interaction patterns
  • Technical Information: IP address, browser type, device identifiers, and referring URLs
  • Cookies and Tracking: Session data, preferences, and authentication tokens

2.3 End-User Interaction Data

When a third party scans a QR code, visits a shortlink, views a landing page, vCard, or link-in-bio page, or downloads a hosted file created through our Service, we collect:

  • Date and time of the interaction.
  • Approximate geographic location (country and city, derived from IP address — raw IPs are not stored).
  • Device type, operating system, and browser (user-agent string).
  • Referrer information.
  • The specific resource accessed (QR code ID, shortlink code, page slug, or file ID).

This data is provided to you (the content creator) as analytics. We do not use it to personally identify the end-user and do not persist raw IP addresses.

3. How We Use Your Information

We use the collected information for the following purposes:

  • Service Provision: Create, manage, and redirect QR codes and shortlinks; host landing pages, digital vCards, link-in-bio pages, and uploaded files; and serve all associated content to end-users.
  • Analytics: Provide scan and interaction statistics, geographic data, and usage insights across all tools.
  • Account Management: Authenticate users, manage subscriptions, and process payments.
  • Communication: Send service updates, billing notifications, and support responses
  • Improvement: Analyze usage patterns to enhance features and performance
  • Security: Detect fraud, abuse, and unauthorized access
  • Legal Compliance: Comply with legal obligations and enforce our Terms of Service

4. Data Sharing and Disclosure

4.1 We Do Not Sell Your Data: We never sell your personal information to third parties.

4.2 Service Providers: We may share data with trusted third-party service providers who assist us in:

  • Payment processing (Paddle)
  • Cloud hosting and file storage (Hetzner Cloud)
  • Email delivery
  • Analytics and monitoring

4.3 Legal Requirements: We may disclose information if required by law, court order, or governmental request, or to protect our rights and safety.

4.4 Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.

5. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption: Data transmitted over HTTPS/TLS and stored using AES-256 encryption at rest.
  • Access Controls: Role-based access and authentication requirements.
  • Regular Audits: Security assessments and vulnerability testing.
  • Secure Infrastructure: Hosted on secure, monitored cloud platforms.
  • File Upload Security: Uploaded files are validated for type and size before storage. Executable and script file types are rejected. Stored files are served over HTTPS only.

However, no method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

6. Data Retention

6.1 Active Accounts: We retain your data for as long as your account is active or as needed to provide services.

6.2 Canceled Accounts: After account cancellation or deletion, we retain your data for up to 90 days for backup and recovery purposes, then permanently delete it.

6.3 Uploaded Files: Files you upload are stored for as long as your account is active. Deleting a file from your dashboard permanently removes it from our servers. Upon account cancellation, all uploaded files are deleted within the 90-day retention window above.

6.4 Analytics Data: Aggregated, anonymized analytics data may be retained indefinitely for service improvement.

6.5 Legal Obligations: We may retain data longer if required by law or for legitimate business purposes (e.g., dispute resolution).

7. Your Rights and Choices

7.1 Access and Update: You can access and update your account information through your dashboard settings.

7.2 Data Export: Request a copy of your data by contacting support@qrnode.net.

7.3 Deletion: You may delete your account and data through account settings or by contacting us. Some data may be retained as described in Section 6.

7.4 Marketing Communications: Unsubscribe from promotional emails using the link in each email or through account settings.

7.5 Cookies: Manage cookie preferences through your browser settings, though this may affect Service functionality.

8. Cookies and Tracking Technologies

We use cookies and similar technologies for:

  • Essential Cookies: Required for authentication and core functionality
  • Functional Cookies: Remember your preferences and settings
  • Analytics Cookies: Understand how users interact with the Service
  • Security Cookies: Detect fraudulent activity and abuse

9. Third-Party Links

Our Service allows you to create QR codes, shortlinks, and landing pages that redirect to or embed content from third-party websites. We are not responsible for the privacy practices of those external sites or services. We encourage you to review their privacy policies before linking to them.

vCard “Save Contact” feature: When a visitor taps “Save Contact” on a vCard page, their device downloads a .vcf file. This download is handled entirely by the visitor’s device and operating system. We do not collect or receive the visitor’s contact-app data.

10. Children's Privacy

Our Service is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, please contact us immediately.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your own, including countries outside the European Economic Area (EEA) that may not provide the same level of data protection as your home country.

Where we transfer personal data from the EEA to third countries, we rely on appropriate safeguards including: Standard Contractual Clauses (SCCs) approved by the European Commission (2021/914/EU), or transfers to countries that benefit from an EU adequacy decision. Copies of applicable SCCs are available on request at privacy@qrnode.net.

11a. Sub-processors

We engage the following third-party service providers (sub-processors) to help us deliver the Service. Each has been assessed for adequate data-protection measures.

ProviderPurposeLocationSafeguard
PaddlePayment processing & subscription managementUK / EUUK GDPR adequacy + SCCs
Hetzner Online GmbHCloud hosting & file storageeu-central network zone, Nuremberg, GermanyEU processing + Hetzner DPA
Google AnalyticsAggregated website analytics (with Consent Mode v2)USASCCs + Google DPA
Mailu (self-hosted)Transactional email deliverySame server as appSelf-hosted, no third-party transfer
CloudflareDDoS protection & CDNGlobal (EU nodes used)SCCs + Cloudflare DPA

We will notify you of any material changes to this sub-processor list by updating this Privacy Policy and, where required, by email. The current list is always available at qrnode.net/privacy#sub-processors.

12. GDPR Compliance (European Users)

If you are located in the European Economic Area (EEA), you have additional rights under GDPR:

  • Right to access your personal data
  • Right to rectification of inaccurate data
  • Right to erasure (“right to be forgotten”)
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent

To exercise these rights, contact us at support@qrnode.net.

13. CCPA Compliance (California Users)

California residents have the right to:

  • Know what personal information is collected, used, shared, or sold
  • Delete personal information
  • Opt-out of the sale of personal information (we do not sell your data)
  • Non-discrimination for exercising CCPA rights

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be notified via email or through the Service. The “Last updated” date at the top indicates when the policy was last revised.

15. Contact Us

For questions about this Privacy Policy or our data practices, contact us at: