How GetQRFree collects, uses, and protects your personal information
2026/05/27
This Privacy Policy explains how GetQRFree ("we," "us," or "our") collects, uses, discloses, and protects your personal information when you use our QR code generation and management services (the "Service").
GetQRFree offers two types of services with different privacy implications:
By using our Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use our Service.
When you use our free static QR code generator without an account:
When you create an account and use our paid services, we collect the following categories of information:
| Data | Source | Purpose |
|---|---|---|
| Name | Google Account | Account identification |
| Email address | Google Account | Account management, notifications |
| Profile picture | Google Account | Account personalization |
| Account preferences | Your settings | Service customization |
| Data | Processor | Purpose |
|---|---|---|
| Credit/debit card details | Stripe (not stored by us) | Payment processing |
| Billing address | Stripe | Payment verification, invoicing |
| Transaction history | Our servers | Billing records, support |
| Subscription status | Our servers | Service delivery |
Note: We do not store complete credit card numbers. All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor.
| Data | Retention | Purpose |
|---|---|---|
| Refund request details | 2 years | Processing refund requests |
| Supporting documentation | 2 years | Verifying refund eligibility |
| Communication records | 2 years | Customer support and dispute resolution |
When you submit a refund request, we collect your account email, order/invoice numbers, reason for refund, and any supporting documentation you provide. For malicious traffic claims, we may analyze scan logs including IP address patterns, geographic distribution, and temporal patterns to verify your claim.
| Data | Retention | Purpose |
|---|---|---|
| Target URLs | Account lifetime | QR code functionality |
| LinkPage content | Account lifetime | Multi-link pages |
| vCard information | Account lifetime | Contact QR codes |
| WiFi credentials | Account lifetime | WiFi QR codes |
| Uploaded files (logos, PDFs, images) | Account lifetime | QR code customization |
When someone scans your dynamic QR codes, we collect:
| Data | Processing | Purpose |
|---|---|---|
| IP address | Hashed for anonymization | Unique visitor counting |
| Geographic location | City-level only | Location analytics |
| Country and region | Stored | Geographic distribution |
| Device type | Stored | Device analytics |
| Operating system | Stored | Technical analytics |
| Browser | Stored | Technical analytics |
| Timestamp | Stored | Time-based analytics |
| Referrer URL | Stored | Traffic source analytics |
Important: Scan analytics are collected from individuals who scan your QR codes (third parties), not just account holders. We do not attempt to identify individual scanners and use IP hashing to prevent identification.
| Data | Retention | Purpose |
|---|---|---|
| Login records | 90 days | Security |
| Product analytics events | Aggregated in Google Analytics | Service improvement, activation analysis, conversion measurement |
| Error logs | 90 days | Technical support |
Product analytics events may include actions such as sign up, login, QR type selection, QR creation, QR download, link copy, analytics view, media actions, custom domain actions, checkout, purchase, subscription changes, settings updates, and marketing form submissions. We use low-cardinality parameters such as QR type, plan name, billing interval, locale, source, status, and normalized error codes. We do not intentionally send Google Analytics email addresses, phone numbers, QR code contents, target URLs, WiFi passwords, file names, raw domain names, Stripe customer or subscription IDs, or account User-ID values. We currently do not enable the GA4 User-ID feature.
We use collected information for the following purposes:
For users in the European Economic Area (EEA), UK, and Switzerland, we process your personal data based on the following legal grounds:
| Processing Activity | Legal Basis |
|---|---|
| Account management | Contract performance |
| Payment processing | Contract performance |
| QR code hosting | Contract performance |
| Refund request processing | Contract performance |
| Website and product analytics | Legitimate interests |
| Scan analytics | Legitimate interests |
| Security measures | Legitimate interests |
| Billing dispute investigation | Legitimate interests |
| Marketing emails | Consent |
| Legal compliance | Legal obligation |
Legitimate Interests: We have conducted balancing tests to ensure our legitimate interests do not override your fundamental rights. You may object to processing based on legitimate interests by contacting us.
We retain your information for the following periods:
| Data Type | Retention Period | Trigger for Deletion |
|---|---|---|
| Account information | Account lifetime + 30 days | Account deletion |
| QR codes and content | Account lifetime | User deletion or account closure |
| Uploaded files | Account lifetime | User deletion or account closure |
| Plan | Retention Period |
|---|---|
| Free | 7 days |
| Solo | 3 months |
| Micro | 12 months |
| Pro | 24 months |
Analytics data older than your plan's retention period is automatically and permanently deleted.
| Data Type | Retention Period |
|---|---|
| Payment records | 7 years (tax compliance) |
| Server logs | 90 days |
| Support communications | 2 years |
When you delete your account:
We share your information only in the following circumstances:
We use trusted third-party service providers to operate our Service:
| Provider | Data Shared | Purpose | Privacy Policy |
|---|---|---|---|
| OAuth authentication data | User authentication | Google Privacy Policy | |
| Google Analytics | Page views, session identifiers, product event names, low-cardinality event parameters | Website and product analytics | Google Privacy Policy |
| Stripe | Payment information | Payment processing | Stripe Privacy Policy |
| Cloudflare | IP addresses, request data | CDN, security, DNS | Cloudflare Privacy Policy |
| Resend | Email addresses | Transactional emails | Resend Privacy Policy |
| Database provider | All stored data | Data hosting | Available upon request |
All service providers are contractually bound to protect your data and use it only for the specified purposes.
We may disclose your information if required to:
In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your information becomes subject to a different privacy policy.
We may share your information for other purposes with your explicit consent.
We do not sell your personal information. We do not share your personal information with third parties for their direct marketing purposes.
Regardless of your location, you have the right to:
If you are located in the EEA or UK, you also have the right to:
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
Categories of Personal Information Collected (per CCPA):
Sensitive Personal Information: We collect precise geolocation data only at the city level for scan analytics purposes.
Do Not Sell or Share: We do not sell or share your personal information as defined under CCPA/CPRA.
To exercise any of these rights:
We will respond to valid requests within 30 days (or 45 days for complex requests, with notice).
We implement appropriate technical and organizational measures to protect your information:
In the event of a data breach affecting your personal information, we will:
GetQRFree is based in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States.
We transfer data from the EEA/UK to the United States using:
By using our Service, you consent to the transfer of your information to the United States.
The free static QR code generator does not require registration and does not store QR content on our servers. Limited website analytics may still be collected as described above.
The paid service requires account registration and is intended for users who are at least 18 years old. We do not knowingly collect personal information from children under 18 for paid services.
If we learn that we have collected personal information from a child under 18 for paid services, we will promptly delete that information. If you believe we have collected information from a child, please contact us at privacy@getqrfree.com.
We use essential cookies for:
We use Google Analytics for website and product analytics. Google Analytics may store a client ID in first-party cookies such as _ga to distinguish users and sessions. We use analytics to measure page views, QR creation and usage funnels, checkout and purchase events, subscription changes, and other product interactions.
We do not currently enable GA4 User-ID, and we do not send account User-ID values to Google Analytics. We also do not intentionally send personal contact details, QR contents, target URLs, WiFi passwords, file names, raw domain names, or Stripe customer/subscription IDs as analytics event parameters.
Third-party services (Google Analytics, Google OAuth, Stripe) may set or read their own cookies or related identifiers. Please refer to their respective privacy policies.
For more details, please see our Cookie Policy.
Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these websites. We encourage you to read the privacy policies of any third-party sites you visit.
We may update this Privacy Policy from time to time. When we make material changes:
Changes take effect when posted unless otherwise specified. Your continued use of the Service after changes constitutes acceptance of the updated policy.
We encourage you to review this Privacy Policy periodically.
If you have questions about this Privacy Policy or our data practices, please contact us:
For General Privacy Inquiries:
For Data Subject Rights Requests:
For EEA Users: While we do not have a physical presence in the EEA, you may contact us at the above addresses for any GDPR-related inquiries.
| Topic | Key Information |
|---|---|
| Data Controller | GetQRFree |
| Free Service | No account data or QR content collected; limited website analytics may be collected |
| Paid Service | Account, payment, content, scan analytics, and product analytics collected |
| Data Sharing | Service providers only, no selling |
| Retention | Varies by data type and plan (7 days - 7 years) |
| Your Rights | Access, correction, deletion, portability |
| Security | Encryption, access controls, hashing |
| International | US-based with appropriate safeguards |
Last Updated: May 27, 2026
Previous Version: November 30, 2025