QR Code GenieWish it, scan it
HomePricingDocsDashboard
QR Code Genie

Create beautifully styled QR codes for any purpose — from Wi-Fi and contact cards to dynamic links, analytics, bulk generation, and API-powered campaigns.

QR Code Generators

Profile Business Card QR CodevCard QR CodePhoto Gallery QR CodeWi-Fi QR CodeMenu QR CodeFile QR CodeAudio QR CodeVideo QR CodeCrypto QR CodeSocial Media QR CodeSMS QR CodeLocation QR CodeEmail QR CodeText QR CodePhone QR CodeMeCard QR CodePet QR CodeEvent QR CodeApp QR Code

Product

  • QR Code Generator
  • Pricing
  • Dynamic Links
  • Bulk Generation
  • API Documentation

Company

  • About QR Code Genie
  • Contact Us

Legal

  • Privacy Policy
  • Terms of Service
© 2026 QR Code Genie. All rights reserved.
“QR Code” is a registered trademark of DENSO WAVE INCORPORATED.

Legal

Privacy Policy

Last updated: July 23, 2026

1. Scope of This Policy

This Policy explains how QR Code Genie ("we," "us," or "our") collects, uses, and shares information through our website, dashboard, and API (the "Service"). It applies both to (a) people who create an account with us ("Account Holders"), and (b) people who scan a QR code or dynamic link created by an Account Holder ("Scanning Visitors") — these are different groups of people, and this Policy covers both.

2. Information We Collect from Account Holders

We process personal data belonging to Account Holders to manage their subscriptions and platform settings:

  • Account information: Name, email address, and profile image received from your chosen identity provider (e.g., Google, GitHub, X).
  • Billing information: Processed exclusively and securely by Stripe. We do not receive or store your credit card numbers.
  • Content you create: QR code configuration parameters, target destination URLs, asset tags, titles, and uploaded dashboard logos.
  • Usage statistics: API call volumes, background bulk generation task logs, and system health performance data.

3. Information Processed from Scanning Visitors (De-Identified)

When a Scanning Visitor interacts with a dynamic link or QR code, the network routing layer is handled securely by our edge infrastructure provider (Cloudflare). To protect user privacy, **we do not collect, log, or store personal identifiers or raw IP addresses on our network backend.**

Our edge infrastructure strips and anonymizes the visitor’s network data in real-time, delivering only **fully de-identified, non-personal metadata** to our origin database to populate tracking metrics for Account Holders:

  • Approximate geographical location aggregated at the country and city level;
  • Approximate network coordinates (rough latitude and longitude estimations provided by Cloudflare based on the visitor's ISP routing hub, which do not pinpoint precise physical addresses or individual devices);
  • Generic hardware classifications (device type, operating system, and browser engine flavor);
  • Inbound navigation referrer strings and real-time execution timestamps;
  • Anonymized internet service provider (ISP) network names.

Because raw network IP paths are discarded immediately at the edge and never saved to persistent storage, the metric data made available to Account Holders across all tiers contains **zero personally identifiable information (PII).**

4. How We Use Information

  • To provide, operate, and maintain the Service, including generating QR codes and processing dynamic link redirects;
  • To process payments and manage subscriptions;
  • To provide scan analytics to Account Holders;
  • To detect, prevent, and investigate fraud, abuse, and security incidents;
  • To communicate with you about the Service, including support and service-related notices;
  • To comply with legal obligations.

5. Cookies & Local Storage

We use cookies, pixels, local storage, and similar technologies to provide our Service, analyze performance, and support monetization:

  • Essential Operations: We use strictly necessary cookies to manage your secure session and keep you signed in to your account dashboard.
  • Advertising & Analytics: For users on ad-supported plans, we work with third-party networks to display ads (such as Google Adsense). Depending on your choice via our consent controls, these networks may use cookies to serve personalized ads based on your browser history, or contextual ads when consent is absent. These third parties may drop operational identifiers to manage frequency caps, run aggregate reporting, and protect against fraudulent traffic.
  • Local Storage: Certain interactive tools (such as our API documentation request tools) store settings or tokens locally in your browser to save you from re-typing them. This data remains stored persistently only on your physical device. While these tokens are securely transmitted to our servers in the header of your active requests so we can execute your API commands, they are processed entirely in real-time and are never permanently saved, logged, or harvested by our backend.

Disclaimer: Third-party advertising networks operate independently under their own privacy policies. We do not control and are not liable for the data collection, processing, or privacy practices of these third-party partners.

6. Data Retention

We retain Account Holder account data for as long as the account is active, and for a reasonable period afterward to comply with legal, tax, and accounting obligations, after which it is deleted or anonymized. Individual scan-level records for Scanning Visitors are retained according to the Account Holder's subscription plan's retention window (currently ranging from 1 day up to 365 days); aggregated daily totals derived from scan activity may be retained for longer periods to support historical analytics, and are not currently subject to automatic deletion, though this may change.

Account Holders have the ability to delete their account and all its associated data, including all related scan records and history. This can be executed directly within the user dashboard by navigating to Settings and selecting "Delete account".

7. How We Share Information

We share information with the following categories of service providers, only as needed to operate the Service:

  • Payment processing: Stripe, to process subscription payments;
  • Infrastructure: our hosting provider and Cloudflare, for edge routing, DNS, custom domain support, and security;
  • Authentication providers: Google, GitHub, X, and other supported identity providers, limited to the sign-in process;
  • Marketplace partners: if you access the Service through a third-party marketplace such as RapidAPI, that marketplace processes your usage in accordance with its own terms.

We do not sell personal information. We may disclose information if required by law, to protect the rights, property, or safety of QR Code Genie or others, or in connection with a merger, acquisition, or sale of assets, subject to this Policy or a successor policy applying to the transferred data.

8. Your Rights

Depending on your location, you may have rights to access, correct, delete, or export your personal information, or to object to or restrict certain processing. Account Holders can access and update most account information directly from the dashboard, and can delete dynamic links and account data as described there. To exercise other rights, contact us at [email protected]. Scanning Visitors seeking to exercise rights over scan data should also contact us; because we generally act as a service provider to the Account Holder for this data, we may direct you to the relevant Account Holder or assist them in fulfilling your request.

9. International Data Transfers

We may process and store information in countries other than your own. Where required by applicable law, we take steps intended to ensure an adequate level of protection for information transferred internationally.

10. Data Security

We use reasonable technical and organizational measures designed to protect information against unauthorized access, loss, or misuse, including encryption in transit and access controls on production systems. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Children's Privacy

The Service is not directed to, and is not intended for use by, anyone under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will take steps to delete it.

12. Additional Disclosures for European Union Residents (GDPR)

If you reside within the European Economic Area (EEA), the processing of your personal data is governed strictly by the General Data Protection Regulation (GDPR).

A. Data Controller vs. Data Processor Roles

  • Account Holder Information: We act as a Data Controller for the personal identifiers (names, emails, billing metrics) collected to manage your workspace subscription profile.
  • Scanning Visitor Information: Because raw network IP addresses are discarded instantly at the network edge by our proxy infrastructure and are never written to persistent databases, **we do not process, store, or control the personal data of Scanning Visitors under the definition of the GDPR.** All stored analytical metrics represent fully anonymous, aggregate hardware and regional metadata.

B. Legal Basis for Processing

We process Account Holder personal data under the following lawful conditions:

  • Contractual Necessity: To manage billing portals, render custom templates, and execute the core software services you purchase.
  • Legitimate Interests: To detect security exploits, prevent brute-force network abuse, and track server system health performance.
  • Legal Compliance: To meet mandatory corporate tax, accounting, and anti-fraud regulatory obligations.

C. Your GDPR Privacy Rights

EU residents possess the structural right to request access to, rectification of, portability of, or absolute erasure of the personal data we hold within our systems. To exercise these controls, transmit a request to [email protected].

Note: Because our system strips individual scanner IP tracking metrics in real-time, we hold no technical capacity to match anonymous scan events back to individual human entities. We are legally exempt from fulfilling access requests for scanning metrics where the data cannot be re-identified.

13. Additional Disclosures for California Residents (CCPA/CPRA)

This section applies exclusively to California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the "CCPA").

A. Categories of Personal Information Collected and Disclosed

In the preceding 12 months, we have collected and disclosed for operational business purposes the following categories of personal information belonging to Account Holders:

  • Identifiers: Real name, email address, profile image, and unique account tokens.
  • Commercial Information: Transaction histories, billing tier selections, and payment status indicators (processed via Stripe).
  • Internet or Network Activity: Dashboard interaction logs, API usage metrics, and system performance analytics.

We do **not** collect or store personal information, identifiers, or raw IP addresses from Scanning Visitors. All traffic data processed at our edge routing layer is immediately de-identified before storage.

B. No Sale or Sharing of Personal Information

QR Code Genie does **not sell** your personal information, nor do we **share** your personal information with third parties for cross-context behavioral advertising purposes. We only transmit your details to trusted service providers (like Stripe or Cloudflare) to perform necessary, core business operations.

C. Your California Privacy Rights

As a California resident, you possess the right to request deletion of your data, access the specific pieces of information we have collected about you, opt-out of potential automated profiling, and receive non-discriminatory service for exercising your privacy choices.

Account Holders may exercise their data rights directly through their account settings panel or by emailing [email protected].

14. Third-Party Destinations

Dynamic links and QR codes created through the Service may redirect to third-party websites or content chosen by the Account Holder who created them. We are not responsible for the privacy practices or content of those third-party destinations. Review the privacy policy of any site you visit after scanning a code.

15. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will provide notice (such as posting an updated date on this page or notifying Account Holders by email). Continued use of the Service after changes take effect constitutes acceptance of the revised Policy.

Questions or requests?

Contact us at [email protected] to review your data, request deletion, or ask about our privacy practices.