QRForge ("we", "us", "our") operates the QRForge platform available at qrforge.link. For the purposes of the GDPR, QRForge acts as the data controller for personal data collected from registered users and visitors to our website.
For questions about this policy or your personal data, contact us at privacy@qrforge.link.
| Category | Examples | When collected |
|---|---|---|
| Account data | Name, email address, password (hashed) | At registration |
| Billing data | Subscription plan, billing country, last 4 digits of card (via LemonSqueezy) | On subscription |
| Content data | QR code configurations, landing page content, project names, custom domain names | During use of Service |
| Communications | Support messages, feedback submissions | When you contact us |
| Category | Examples | Purpose |
|---|---|---|
| Usage data | Pages visited, features used, timestamps | Service improvement |
| Device & technical data | Browser type, operating system, screen resolution, IP address | Security, compatibility |
| QR scan analytics | Scan timestamp, approximate geolocation (country/city), device type, operating system, referrer | Analytics for QR code owners |
| Log data | Server logs, error reports, performance metrics | Diagnostics, security |
When a person scans a QR code created with QRForge, we may collect limited technical data about that scan (e.g. approximate location derived from IP address, device type, scan time). QRForge acts as a data processor for this data on behalf of the QR code owner (who is the data controller). QR code owners are responsible for ensuring they have a lawful basis for collecting this data and for providing appropriate disclosures to their end-users.
| Processing activity | Legal basis |
|---|---|
| Providing the Service (account management, QR code delivery) | Performance of a contract (Art. 6(1)(b)) |
| Billing and payment processing | Performance of a contract (Art. 6(1)(b)) |
| Security monitoring and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Service improvement and analytics | Legitimate interests (Art. 6(1)(f)) |
| Sending transactional emails (verification, billing alerts) | Performance of a contract (Art. 6(1)(b)) |
| Marketing communications (where applicable) | Consent (Art. 6(1)(a)) |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
We use the data we collect to:
We will not sell your personal data to third parties, nor will we use it for targeted advertising without your explicit consent.
We retain your personal data for as long as your account is active or as needed to provide you with the Service. Specifically:
When data is no longer required, we securely delete or anonymise it.
Depending on your jurisdiction, you may have the following rights regarding your personal data:
To exercise any of these rights, contact us at privacy@qrforge.link. We will respond within 30 days. We may ask you to verify your identity before processing your request.
California residents have additional rights under the California Consumer Privacy Act, including the right to know what personal information we collect, the right to delete personal information, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise CCPA rights, contact us at privacy@qrforge.link.
We implement industry-standard technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. These include:
Despite these measures, no transmission over the internet is completely secure. In the event of a personal data breach, we will notify affected users and the relevant supervisory authority in accordance with applicable law.
Our primary infrastructure is hosted in the EU (Google Cloud europe-west1). Some sub-processors are located outside the European Economic Area (EEA). Where we transfer data outside the EEA, we ensure appropriate safeguards are in place, including:
You may request further information about the specific transfer mechanisms we rely on by contacting privacy@qrforge.link.
The Service is not directed to children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected data from a child, please contact us immediately at privacy@qrforge.link and we will delete it promptly.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the revised policy on this page and, where appropriate, by email to your registered address. The "Last updated" date at the top indicates when this policy was last revised.
We encourage you to review this policy periodically. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
For privacy-related enquiries, data subject requests, or concerns, please contact us:
We aim to respond to all privacy requests within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.