Privacy Policy
GDPR & CCPA Compliance Standards • Updated September 2026
1. Information We Collect
When end-users scan a dynamic QR code hosted on our infrastructure, we collect technical telemetry required to deliver the destination and generate aggregate analytics. This includes non-reversible salted cryptographic hashes of the visitor IP address, User-Agent strings (to determine operating system and browser family), and approximate geographic coordinates at the city or country level.
2. Privacy by Design & IP Anonymization
In strict adherence to international privacy standards (including GDPR and CCPA regulations), raw IP addresses are processed in volatile memory only for geolocation lookup and immediately discarded. Our persistent database stores only irreversible SHA-256 hashes used solely to calculate unique visitor metrics.
3. Account & Operational Data
For registered tenant account holders, we store business email addresses, salted password hashes (via bcrypt), tenant configuration profiles, and billing transaction references. We never sell or license customer data to third-party brokers.
4. Data Retention & Erasure
Tenants may request complete deletion of their account records, historical telemetry logs, and dynamic QR routing entries at any time via the admin settings panel or by contacting our data protection officer.