QRsvg

Legal

Privacy Policy

What we collect, why, how long we keep it, and the choices you have.

Last updated: 7 September 2026

1. Who we are

qrsvg.app (“QRsvg”, “we”, “us”) is an independent website operated from Romania, in the European Union. It provides a free QR code generator, optional user accounts, dynamic QR codes with scan statistics, bulk generation and a public API. For any privacy matter you can reach us at hello@qrsvg.app.

2. The short version

  • Static QR codes are generated entirely in your browser. The text you encode is never sent to our servers.
  • You can use the generator without an account and without giving us any personal data.
  • If you create an account, we store your email address and the QR codes you choose to save.
  • Dynamic QR codes log each scan with coarse location (country, region, city), device type, operating system and browser. We never store raw IP addresses.
  • We use privacy-friendly Vercel Analytics, optionally Google Analytics 4, and Google AdSense to show ads.
  • In the EEA, UK and Switzerland, advertising and analytics cookies are only set after you consent through the Google consent message shown on your first visit. You can change your choice at any time.

3. Data we process and why

3.1 Using the generator (no account)

Encoding, styling and exporting a static QR code happens in JavaScript on your device. The content of your code, uploaded logo images and design settings stay in your browser’s memory and, if you use the “remember my settings” behaviour, in your browser’s local storage. We do not receive them. Our web server sees the ordinary technical request data any website receives (IP address, user agent, requested page, referrer), which our hosting provider retains in short-lived logs for security and operations.

3.2 Accounts

Accounts are optional and free. When you sign in with a Google account or an email magic link, our authentication provider (Supabase) stores your email address, a user identifier, sign-in timestamps and, for Google sign-in, the profile name and avatar URL Google shares. We store the QR codes you save: their name, content type, payload, design settings, folder and timestamps. Legal basis: performance of a contract (providing the account features you requested).

3.3 Dynamic QR codes and scan statistics

A dynamic QR code encodes a short link on our domain (qrsvg.app/r/…) that redirects to the destination you configured. When someone scans it, we record: time of scan, country, region and city (derived from the IP address by our hosting provider and passed to us as headers), device type, operating system, browser, and the HTTP referrer if present. To detect repeated scans without keeping identifiers we store a one-way hash of the user agent combined with the current day. We do not store the scanner’s IP address, exact location or any persistent identifier, and we do not set cookies on redirect. Legal basis: legitimate interest of the code owner in measuring campaign performance, balanced against the minimal, non-identifying nature of the data. If you are the code owner, you are responsible for making sure your use of these statistics complies with laws applicable to you.

3.4 Public API

Requests to /api/qr are rate-limited per IP address. IP addresses are held in memory only for the duration of the rate-limit window (one minute) and are not written to a database. The data you pass to the API is used only to render the requested image and is not stored.

3.5 Contact

If you email us, we keep the correspondence for as long as needed to handle your request and for up to 24 months afterwards for reference. Legal basis: legitimate interest in responding to enquiries.

4. Cookies, analytics and advertising

4.1 Strictly necessary

Signed-in users receive authentication cookies from Supabase to keep the session alive. A theme preference (light/dark) is stored in local storage. These do not require consent.

4.2 Vercel Analytics and Speed Insights

Our host, Vercel, provides aggregate page-view and performance metrics. It uses no cookies and no persistent identifiers; visitors are counted by a hash that changes daily and cannot be traced back to a person.

4.3 Google Analytics 4

When enabled, Google Analytics helps us understand which pages and features are used. In consent-required regions it runs in Google Consent Mode with all storage denied until you accept, and IP anonymisation is applied by Google. Data is retained by Google for 14 months. You can opt out with Google’s browser add-on or by declining in the consent message.

4.4 Google AdSense

The site is funded by advertising served by Google AdSense (publisher ID pub-2120575686162310). Google and its certified partners may use cookies and similar technologies, including the DoubleClick cookie, to serve ads based on your visits to this and other websites, to measure ad performance and to prevent fraud. In the EEA, UK and Switzerland, personalised ads are shown only if you consent; otherwise ads are non-personalised and rely on contextual information such as the page content and coarse location. Learn how Google uses data at policies.google.com/technologies/partner-sites and manage personalised advertising at adssettings.google.com.

4.5 Consent management

We use Google’s consent management platform (part of AdSense “Privacy & messaging”), which is certified under the IAB Transparency & Consent Framework. It shows a consent message to visitors in regions where it is required, records your choice, and signals it to Google and other ad technology vendors via Consent Mode v2 and the TCF string. To review or withdraw your consent, use the button below (it reopens the same message), or clear your cookies for qrsvg.app to be asked again.

The consent manager is still loading (or is blocked by your browser).

5. Processors and recipients

  • Vercel Inc. (USA) — hosting, CDN, edge network, Vercel Analytics and Speed Insights. Data may be processed in the USA under the EU–US Data Privacy Framework and standard contractual clauses.
  • Supabase Inc. — authentication and database for accounts, saved codes and scan statistics. Our project is hosted in an EU region.
  • Google LLC / Google Ireland Ltd. — Google Analytics 4 (when enabled), Google AdSense, Google consent management, Google sign-in (if you choose it).

We do not sell personal data, and we do not share it with anyone else except when the law requires it.

6. Retention

  • Account data and saved codes: until you delete them or delete your account.
  • Scan statistics: for the life of the dynamic code, deleted with it (at the latest 30 days after account deletion).
  • Server request logs (hosting provider): typically up to 30 days.
  • Google Analytics: 14 months. Advertising cookies: per Google’s published cookie lifetimes (generally up to 13 months).
  • Email correspondence: up to 24 months after the matter is closed.

7. Your rights

If you are in the EEA, UK or Switzerland you have the right under the GDPR and equivalent laws to access, rectify, erase and port your personal data, to restrict or object to its processing, and to withdraw consent at any time without affecting processing that happened before withdrawal. You also have the right to lodge a complaint with a supervisory authority; in Romania this is the ANSPDCP (dataprotection.ro).

If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we collect, to delete it, to correct it, and to opt out of the “sale” or “sharing” of personal information for cross-context behavioural advertising. We honour the Global Privacy Control signal, and you can exercise the opt out through the consent settings button in section 4.5 or by emailing us. We do not discriminate against you for exercising these rights.

Signed-in users can delete individual codes or their whole account from the dashboard. For any other request, email hello@qrsvg.app from the address associated with your account; we respond within 30 days.

8. Children

The service is not directed at children under 16 and we do not knowingly collect personal data from them. If you believe a child has created an account, contact us and we will remove it.

9. Security

All traffic is encrypted with TLS. Database access is protected by row-level security so that users can only read and modify their own records. Service credentials are never shipped to the browser. No system is perfectly secure; if you discover a vulnerability please report it to hello@qrsvg.app.

10. Changes

We will update this policy when the service or the law changes and note the date at the top. Material changes affecting signed-in users will be announced by email or a notice in the dashboard.

See also the Terms of Service.