Privacy Policy
Last updated: 2026-10-01
Editable policy template. The operator must review its legal details, business practices, and local requirements before launch. This is not jurisdiction-specific legal advice.
This policy explains how PrintOnceQR handles information when you use PrintOnceQR or visit a managed QR link.
Account and service data
We store account names, email addresses, verification status, encrypted password hashes where password login is used, authentication records, QR names, destinations, customization settings, and subscription identifiers. We use this information to provide the account, operate your links, enforce plans, secure the service, and communicate about your account.
Scan analytics
For QR visits we maintain aggregate scan counts and, within the account’s allowance, time, broad device category, browser, operating system, country when available, and the referring hostname. We do not store raw scan IP addresses, full referrer URLs, or persistent visitor identifiers in scan events. These counts describe visits and do not identify unique people.
Security and technical information
Hosting and payment providers process technical information needed to deliver and secure their services. Our application uses temporary request limits for abuse prevention. General application limit keys are HMAC-derived from an IP address; authentication rate-limit records may temporarily contain an IP address. Maintenance removes expired limit records and expired authentication sessions. Session records do not retain raw IP addresses.
Product measurement and cookies
We record simple product events such as page views, QR creation, downloads, and subscription changes. Public events do not contain a user identifier or a persistent analytics cookie. Some authenticated events are associated with an account. Essential authentication cookies support login and request security. No advertising provider or third-party analytics script is enabled by default.
Service providers and legal bases
Vercel hosts the application, Neon provides the PostgreSQL database, Stripe processes billing, Resend delivers transactional email when configured, and Google handles optional Google sign-in when configured. We use account information to perform the service agreement, maintain service security, prevent abuse, and meet applicable legal obligations. Where a separate activity requires consent, it must be requested before that activity is enabled. Contact us for information about current data locations and applicable transfer safeguards.
Retention
Detailed scan events and internal product events are scheduled for removal after 90 days. Daily and monthly aggregate counts are retained for the account’s operational history. QR deletion removes that QR’s daily and detailed scan history. Account deletion removes account-linked service data; anonymous product event records may remain until their scheduled deletion. Sent email jobs are removed after 90 days. Accounting records held by Stripe and provider backups follow their applicable legal and retention requirements.
Your choices and rights
You can update your profile, export Pro scan analytics, cancel a subscription, and delete your account in Settings. Contact support@printonceqr.com for access, correction, export, deletion, objection, or other privacy requests relating to your personal information. We will assess requests under the law that applies to you. You may also contact your relevant data protection authority. No paid plan is required to make a personal-data rights request.
International transfers and complaints
Some providers may process information outside your country under contractual or other lawful transfer safeguards. Contact support@printonceqr.com to ask about safeguards or complain about our handling of personal data. You may also complain to the Romanian National Supervisory Authority for Personal Data Processing or the supervisory authority in your habitual residence or workplace.
Contact
PrintOnceQR. Email support@printonceqr.com.