This document must be reviewed by a lawyer before publication. Items in brackets must be completed.
A cookie is a small file a website stores in your browser. Browser local storage follows the same rules. Under EU rules (ePrivacy Directive, article 82 of the French Data Protection Act and CNIL guidelines), trackers that are strictly necessary for the Service do not require consent; all others do.
1. What QRTada does not use
- No advertising cookies, no social media pixels, no retargeting trackers.
- No audience-measurement cookies: website traffic statistics are produced by Umami, hosted on our servers in Germany, which works without cookies or local storage, does not store IP addresses and performs no geolocation.
- No cookies when a QR code is scanned: redirects and hosted pages set no trackers.
2. The consent banner
On your first visit, a banner is shown to every visitor. It offers three choices:
- "Accept all" and "Reject all", equally prominent and each one click away;
- "Customize", to accept or reject each purpose separately.
Until you choose, no tracker requiring consent is set. Rejecting has no effect on your access to the website, the Service or the price.
Your choice is remembered for 6 months, after which the banner is shown again. You can change or withdraw your consent at any time, as easily as you gave it, with the "Manage cookies" link in the footer of every page.
QRTada keeps a record of your choice (date, banner version, choice for each purpose), with no IP address in clear, so it can demonstrate that consent was obtained.
3. Strictly necessary trackers (no consent required)
| Name | Type | Purpose | Duration | |---|---|---|---| | qrtada.session_token (__Secure-qrtada.session_token over HTTPS) | cookie | keep you signed in | 30 days, extended while you use the Service | | qrtada.session_data | cookie | cache your session to avoid a database read on every page | 5 minutes | | qrtada.two_factor | cookie | link the two steps of a sign-in with two-step verification | a few minutes, the time to enter the code | | qrt_imp | cookie (HttpOnly) | support team only: view your account at your request, always shown by a banner and logged; it only works with the administrator's session | the length of the intervention, at most 1 hour | | NEXT_LOCALE | cookie | remember your language (English or French) | until you close the browser | | qrt_consent | cookie | remember your choices in the consent banner | 6 months | | qrt_ws | cookie | remember the workspace picked in the workspace switcher | 12 months | | qrt_sidebar | cookie | remember whether the sidebar is collapsed or expanded | 12 months | | qrtada.draft.v1 | local storage | keep the QR code you are customizing before sign-up, so it is not lost | until sign-up or 30 days | | qrtada.device.v1 | local storage | random device identifier that limits the free trial to one per device (abuse prevention); never used for tracking | until you clear the browser's storage | | qrtada.firstDownload | local storage | show the help that follows your first download only once | until you clear the browser's storage | | theme | local storage | remember your theme (light, dark or system) | until you clear the browser's storage | | qrt_tada_shown | session storage | show the announcement of your first scan only once during your visit | until you close the tab |
Protection against forged requests uses a header added to each request, with no cookie.
At checkout you are redirected to Stripe's secure page, which sets its own cookies required for payment security and fraud prevention. When you sign in with Google, Google sets its own cookies on its domain. These are governed by Stripe's and Google's policies.
4. Trackers requiring your consent
| Purpose | Name | Type | Role | Duration | |---|---|---|---|---| | Affiliate attribution | qrt_aff | first-party cookie | credit your sign-up to the partner whose link you followed, so they can be paid their commission | 60 days |
This is currently the only purpose requiring consent. Any new non-essential purpose would be added to the banner and to this table before being used, and would only apply after you agree.
5. Managing cookies in your browser
You can also block or delete cookies in your browser settings. Blocking strictly necessary cookies prevents you from signing in.
6. More information
How we process your data is described in the privacy policy. Questions: [TO COMPLETE: privacy email].