Privacy policy
Last updated: 24 August 2026
Template — needs legal review. This is a starting point drafted to match how the product actually works. Have a qualified professional review it before you launch or apply to AdSense.
This policy explains what QRFable collects, why, and what we do with it. We've written it to describe how the product actually behaves rather than to cover every hypothetical.
What we collect
Account data: your email address and a hashed password. Passwords are hashed with bcrypt and are never stored or logged in readable form.
QR code data: the content you encode, styling choices, and — for dynamic codes — the destination URL and its short slug.
Scan data: when someone scans a dynamic code, we record a timestamp, a coarse country derived from the IP address, and the device operating system parsed from the browser's user-agent string.
What we deliberately do not collect
Static QR codes are generated entirely in your browser. Their content is never transmitted to our servers.
We do not store full IP addresses against scan events, and we do not build advertising profiles of the people who scan your codes.
Cookies and local storage
We store your login token in your browser's local storage so you stay signed in. This is required for the service to work and is cleared when you log out.
If advertising is enabled on free-tier redirect pages, the ad provider may set its own cookies. See our cookie notice for details.
Sharing
We do not sell personal data. Data is shared only with infrastructure providers necessary to run the service (hosting, database, and — where enabled — the advertising provider).
Your rights and retention
You can delete any QR code from your dashboard, which permanently removes it and its scan history. To delete your entire account and associated data, contact us.
Depending on where you live, you may have rights to access, correct, or export your data. We'll honour those requests.