Legal
Privacy Policy
Last updated: March 22, 2026. This policy describes how qrqr.fyi ("we", "us") handles information when you use our website and services.
1. Overview
We built qrqr.fyi to help you create and manage QR codes. We collect only what we need to run the product, bill subscribers, and keep accounts secure. We do not sell your personal information.
If you use static QR codes without an account, we do not create a customer record for that activity. If you sign in or subscribe, we process account and billing data as described below.
2. What we collect
Depending on how you use the service, we may process:
- Anonymous static use. When you generate a static QR code in the browser without an account, the encoded content stays in your session. We do not require personal data for that flow.
- Account data. If you create an account, we store your email address and authentication identifiers through our auth provider. We use this to sign you in and communicate about your account.
- Content you save. If you save dynamic QR codes, vCards, or related settings to your dashboard, we store that content and configuration so the product works as you expect.
- Usage tied to dynamic codes. For dynamic QR codes, we may process scan events and related metadata (such as timestamps and coarse technical data) to provide analytics features.
- Billing data. If you subscribe to Pro, payment details are collected and processed by Stripe. We do not store full payment card numbers on our servers.
- Support and messages. If you contact us, we keep the information you provide so we can respond.
3. How we use data
We use personal information to:
- Provide, operate, and improve qrqr.fyi.
- Authenticate users and secure accounts.
- Process subscriptions and send billing-related notices.
- Deliver transactional email (for example, magic links and receipts).
- Detect abuse, fraud, and technical issues.
- Comply with law and enforce our terms.
5. Third-party services
We rely on service providers who process data on our behalf. They only receive what they need to perform their function. Examples include:
- Supabase for authentication and application data storage.
- Stripe for payments and subscription management.
- Resend for transactional email.
- Vercel for hosting and analytics.
- Google for AdSense where enabled.
Each provider has its own privacy policy. We encourage you to review those documents if you want vendor-specific detail.
6. Retention
We keep personal information only as long as needed for the purposes above, including legal, accounting, and security requirements. When you delete your account or ask us to remove data where applicable, we delete or anonymize it unless we must retain a limited record to meet legal obligations.
7. Security
We use administrative, technical, and organizational measures designed to protect your information. No online service can guarantee perfect security. If you believe your account has been compromised, contact us promptly.
8. Your rights and contact
Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to or restrict certain processing. To exercise rights connected to your account, use your dashboard where available or email support@qrqr.fyi. We will respond in line with applicable law.
If you are in the European Economic Area or the United Kingdom, you may also lodge a complaint with your local data protection authority.
9. Children
qrqr.fyi is not directed at children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided us personal data, please contact us and we will take appropriate steps.
10. Changes
We may update this policy from time to time. We will post the new version on this page and revise the "Last updated" date. If changes are material, we will provide additional notice where appropriate, such as by email for registered users.