Privacy Notice
Last updated 28 August 2026
QR Signal, trading as QRSignal, is the data controller for personal data processed through the QRSignal platform and website. This notice explains what we collect, why, who we share it with, and the rights you have. Contact us at privacy@qrsignal.co.
Data we collect and why
- Account data - name, work email, job title, company name and domain, login credentials and role. Used to create and secure your account and enforce workspace access. Legal basis: performance of a contract.
- Workspace content - campaigns, QR codes, destination URLs, budgets, brand assets. Used to provide the Service. Legal basis: performance of a contract.
- Scan and analytics data - timestamp, device type, operating system, browser, referrer, approximate location (country, region, city, timezone) derived from the request, and a hashed IP address. Used to produce the attribution and ROI analytics you have asked for. Legal basis: legitimate interests of our customers in measuring their campaigns; we minimise this data by hashing IP addresses rather than storing them.
- Support messages - the content of enquiries you send us. Used to answer you. Legal basis: legitimate interests.
- Security and telemetry - logs, device identifiers and error reports. Used to detect abuse, prevent fraud and keep the Service reliable. Legal basis: legitimate interests and legal obligation.
- Marketing - where you have opted in, your email may be used for product updates. Legal basis: consent, withdrawable at any time.
Who we share data with
- Service providers and subprocessors: cloud hosting, database, email delivery and error monitoring providers.
- Paddle.com, our Merchant of Record, for sale of the product, subscription management, payments, tax compliance and invoicing.
- Professional advisers such as legal and accounting firms, where necessary.
- Authorities or regulators where we are required to do so by law.
We do not sell personal data.
International transfers
Some of our providers process data outside the UK and EEA. Where that happens we rely on UK/EU adequacy decisions or Standard Contractual Clauses together with appropriate supplementary safeguards.
Retention
Account and workspace data is kept while your account is active and for up to 90 days after closure, after which it is deleted or anonymised. Scan events are retained according to your plan's retention window and then aggregated or deleted. Billing records are retained for as long as tax law requires (typically 6-7 years) by Paddle as Merchant of Record.
Your rights
Subject to applicable law you have the right to access your data, correct it, request erasure, restrict or object to processing, request portability, and withdraw consent where processing relies on it. Email privacy@qrsignal.co and we will respond within one month. If you are in the UK or EEA you also have the right to complain to your supervisory authority (in the UK, the Information Commissioner's Office).
Security
We apply appropriate technical and organisational measures, including encryption in transit and at rest, row-level database isolation between organisations, role-based access controls and least privilege access for our staff.
Cookies
We use essential cookies for authentication and session security; these are required for the Service to work. Where we use analytics cookies to understand product usage, they are set only with your consent and you can change your preference at any time through your browser settings.
Changes
We may update this notice; the effective date at the top will change and material updates will be communicated. See also our Terms & Conditions.