This document must be reviewed by a lawyer before publication. Items in brackets must be completed.
This policy explains what personal data QRTada processes, why, for how long, who it is shared with and how to exercise your rights. It follows the EU General Data Protection Regulation (GDPR) and the French Data Protection Act, and includes a section for US residents.
In short: everything is hosted in the European Union (Germany); IP addresses are never stored in clear for scan analytics; no audience-measurement cookies; your data is never sold or used for advertising.
1. Controller
[TO COMPLETE: first and last name], EI, trading as QRTada, [TO COMPLETE: postal address], France, SIRET [TO COMPLETE: SIRET].
Privacy contact: [TO COMPLETE: privacy email].
[TO COMPLETE: data protection officer, if appointed; otherwise remove this line]
2. Who this policy covers
- visitors to qrtada.com;
- users who create an account, and members invited to a workspace;
- customers who subscribe;
- people who scan a QR code created with QRTada;
- people whose data appears in content uploaded by our customers (for example on a business card);
- affiliates, people who report content and people who contact us.
3. Data, purposes and legal bases
| Purpose | Data | Legal basis (GDPR) | |---|---|---| | Create and manage your account, sign you in | email, name, hashed password, Google identifier (if you sign in with Google), language, time zone, preferences, two-factor secret | performance of contract | | Provide the Service (codes, hosted pages, exports, teams) | uploaded content, destinations, files, version history, roles | performance of contract | | Manage the trial, subscription and billing | plan, status, payment history, country, business or personal use, company name, registration and VAT numbers, billing address, Stripe identifiers | performance of contract; legal accounting and tax obligations | | Prevent trial fraud and abuse | card fingerprint provided by Stripe (never the card number), hashed fingerprints of email, device and sign-up IP address | legitimate interest (preventing repeated trials and abuse) | | Secure the Service | sessions (IP address, browser), security and activity logs | legitimate interest; legal obligation to retain connection data | | Send service emails (verification, trial reminder, invoices, alerts, security) | email, language, email content, delivery status | performance of contract; legal information obligations | | Send the newsletter and marketing emails | email, language | consent (unticked by default), or legitimate interest for similar services to existing customers, with opt-out at any time | | Produce scan analytics | see section 4 | see section 4 | | Measure website audience and improve the sign-up flow | page views, referrer, device type, sign-up funnel events linked to an internal identifier | legitimate interest (cookie-free tool, see section 11) | | Credit a sign-up to an affiliate partner | partner code, click date | consent (cookie banner) | | Keep proof of your cookie choices | date, banner version, choice per purpose, no IP address in clear | legal obligation to demonstrate consent | | Handle reports and moderation | reported code address, reason, reporter email (optional), hashed fingerprint of reporter IP | legitimate interest; EU Digital Services Act obligations | | Run the affiliate program | identity, payout details (IBAN or PayPal), attributed clicks and conversions | performance of the affiliate agreement; consent for the attribution cookie | | Answer your requests | email, message, current plan | legitimate interest or performance of contract |
We make no fully automated decisions with legal effects on you, except automatically refusing a destination identified as dangerous, which you can appeal to a person.
4. Scan analytics: what is collected when someone scans a QR code
When someone scans a dynamic QR code, QRTada records:
- the date and time of the scan;
- device type, operating system, browser and language, derived from the technical information sent by the browser;
- the referring site, if any;
- the country, only if provided by our network infrastructure; QRTada does not use any IP geolocation database for scans;
- a technical fingerprint computed from the truncated IP address and browser, hashed with a key that changes every day, used only to count unique scans over 24 hours. The IP address is never stored in clear and the fingerprint cannot be used to follow a person from one day to the next.
No cookie is set when a code redirects.
Roles: the customer who created the QR code decides the purpose of its analytics; QRTada produces them on the customer's behalf as a processor (see the data processing agreement). QRTada is controller for bot detection, security, abuse prevention and aggregated, anonymous statistics (for example a yearly study on QR code usage that identifies neither individuals nor customers).
5. Recipients and service providers
Data is accessible only to authorized QRTada personnel and to the following providers, to the extent they need it:
| Provider | Role | Data location | |---|---|---| | Contabo GmbH | hosting of the website, application, database, files and audience-measurement tool | Germany (EU) | | Stripe Payments Europe, Ltd. | payments, subscriptions, invoices, fraud prevention | Ireland (EU), with possible transfers to the United States (see section 6) | | [TO COMPLETE: Brevo (Sendinblue SAS) or SMTP provider name] | sending emails | [TO COMPLETE: location, EU expected] | | Google Ireland Limited | Google sign-in, only if you choose it | Ireland (EU), with possible transfers to the United States | | [TO COMPLETE: encrypted off-site backup provider] | off-site backup copy | [TO COMPLETE: location, EU expected] | | [TO COMPLETE: uptime monitoring service] | availability monitoring (no personal data sent) | [TO COMPLETE] | | Have I Been Pwned (Troy Hunt's service, via Cloudflare) | check that a new password does not appear in a known public breach; only the first 5 characters of its SHA-1 hash are sent (k-anonymity), never the password, the email or any personal data | outside the EU (global network); no personal data sent |
Data may also be disclosed to administrative or judicial authorities where required by law. Workspace members see that workspace's codes and analytics according to their role. We do not sell or rent personal data.
6. Transfers outside the European Union
The Service is hosted in the EU. Some providers (Stripe, Google) may transfer data to the United States. These transfers rely on the EU-US Data Privacy Framework adequacy decision where the recipient is certified, and otherwise on the European Commission's standard contractual clauses. You can request a copy of these safeguards.
7. Retention periods
These periods are enforced by automated tasks.
| Data | Retention | |---|---| | Unverified account | 30 days after sign-up | | Active account | for as long as you use the Service | | Account with no subscription and no sign-in | 3 years after last activity, then deletion after email notice; the minimum data needed for codes covered by the lifetime guarantee (email, codes, destinations) is kept as long as those codes exist | | Codes created during an unconverted trial and never scanned | 24 months, then deletion after 30 days' notice | | Account deletion requested | deleted 14 days after the request unless cancelled; backups are overwritten within 30 days | | Invoices and accounting records | 10 years (French Commercial Code, article L123-22) | | Trial anti-abuse fingerprints | 3 years after the trial | | Detailed scan events | 13 months, then kept as daily aggregates according to your plan's analytics history | | Analytics of a cancelled account | aggregated for 12 months in case of reactivation, then deleted | | Sessions | until they expire or are signed out | | Security and connection logs | 12 months | | Sent email log | 12 months | | Cookie choices | 6 months in your browser; proof of consent kept 5 years | | Sign-up funnel events | 25 months | | Prospects and newsletter subscribers | 3 years after last contact, or until you unsubscribe | | Reports and moderation decisions | 3 years after closure | | Affiliate data | duration of the partnership, then 5 years (limitation period); accounting data 10 years | | Contact messages | 3 years after the last exchange | | Data export archives | 7 days after creation |
8. Security
Encrypted connections (HTTPS), passwords hashed with a strong algorithm (argon2), passwords found in known public breaches refused at sign-up and on change, optional two-factor authentication, secrets encrypted at rest, restricted and logged access, encrypted daily backups stored off the main server, checked uploads (real file type, SVG sanitizing, image metadata removal). In case of a data breach presenting a risk, the French data protection authority (CNIL) and, where required, affected people are notified within legal deadlines.
9. Your rights
Depending on where you live, you have the right to access, correct, delete, restrict and port your data, to object (in particular to marketing, at any time and without reason), to withdraw consent at any time, and, under French law, to set instructions for your data after your death.
- Self-service: from your settings you can edit your information, export your data (JSON and CSV), manage email preferences and request deletion of your account (effective after 14 days, can be cancelled). Every marketing email contains an unsubscribe link.
- By email: [TO COMPLETE: privacy email]. We reply within one month, extendable by two months for complex requests. We may ask for proof of identity in case of reasonable doubt.
- People who scan a QR code: analytics contain neither your name nor your IP address; the daily fingerprint cannot be used to find your scans. For a question about a hosted page or QR code, you can contact the customer who created it or write to us.
You can lodge a complaint with the CNIL (3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, cnil.fr) or with the supervisory authority of your country of residence.
10. US residents
This section applies to residents of US states with consumer privacy laws, to the extent those laws apply to QRTada.
- Categories collected: identifiers (email, name, account identifiers), commercial information (plan, payment history), internet or network activity (sessions, service usage, scan analytics as described above), and inferences we do not make for profiling.
- Sources: you directly, your browser or device, our payment provider and, if you choose it, Google sign-in.
- Purposes: those listed in section 3.
- No sale or sharing: we do not sell personal information and do not share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes other than providing the Service.
- Your rights: to know, access, correct and delete your personal information, and not to be discriminated against for exercising these rights. Submit requests through your settings or at [TO COMPLETE: privacy email]; an authorized agent may submit a request on your behalf with proof of authorization. If we deny your request, you may appeal by replying to our decision.
11. Cookies and audience measurement
A consent banner is shown on your first visit: non-essential trackers (currently only affiliate attribution) are set only with your consent, which you can withdraw at any time via "Manage cookies" in the footer. Details are in the cookie policy.
Website audience measurement uses Umami, hosted on our servers in Germany, without cookies or local storage, without storing IP addresses and with geolocation disabled: no location is derived from your IP address.
12. Children
The Service is intended for adults. It is not directed to children under 13 (or under 16 in the EU), and we do not knowingly collect their personal data. A minor may only create an account with a legal guardian's permission.
13. Changes
This policy may change, in particular when we add a service provider. The update date is shown at the top of the page. For significant changes, you will be informed by email or in the application.