Qraftlink

Privacy Policy

Last updated: draft, not yet reviewed by counsel.

This draft describes what the product actually collects today, as a starting point. Have it checked against applicable law (e.g. GDPR/CCPA) before a public launch, and update it if data handling changes.

1. What we collect

Account data: your email address and, if provided, a display name, used to create and secure your account.

QR content: the destinations, designs, and settings you configure for your QR codes.

Scan analytics: when someone scans one of your QR codes, we log the timestamp, approximate location (country/city, derived from IP — not the raw IP itself), device/browser, and referrer, so you can see campaign performance. We do not track scanners across sites or build advertising profiles from this data.

2. Cookies

We use a session cookie to keep you signed in, and, if you password-protect a QR code, a scoped unlock cookie for that specific code. We do not use third-party advertising or tracking cookies.

3. Service providers

We use third-party infrastructure to run the service: hosting, a managed Postgres database, object storage for uploaded logos and rendered images, email delivery for account and notification emails, and rate-limiting infrastructure. These providers process data only as needed to provide the service.

4. Your choices

You can rename, edit, or delete your QR codes at any time from the dashboard. To request a full account data export or deletion, contact us (see below).

5. Data retention

Account and QR data is kept while your account is active. Deleting a QR code archives it rather than immediately erasing it, to protect against accidental loss; it stops resolving for scanners but is not immediately purged from storage.

6. Contact

Questions about this policy, or a data request: see Contact.