This Privacy Policy explains how CamRadCo, the operator of EasyQR ("EasyQR," "we," "us," or "our"), collects, uses, discloses, and protects information when you visit easy-qr.co or use EasyQR's QR code tools, account dashboard, dynamic redirects, analytics, Blog, SEO Pages, contact form, and related services (collectively, the "Service").
This policy applies to account holders, website visitors, people who contact us, and people whose devices request an EasyQR dynamic QR redirect. It does not govern the destination websites selected by EasyQR customers.
1. Information you provide
Account and organization information
When you create or use an account, we may receive your name, email address, password-based authentication information, optional business or workspace name, organization membership and role, and account preferences such as default campaign parameters. Organization owners and administrators can create or manage team member access, subject to the seat limit of the organization's plan.
QR code and campaign information
We store information needed to create and manage dynamic QR codes, including QR names and descriptions, destination URLs, permanent short codes, status, color, folders, campaign parameters, creation and update dates, and aggregate scan totals. You are responsible for the destinations and content you configure.
Files and other assets
Most logo customization in EasyQR's free sign tools is processed in your browser and is not uploaded to EasyQR. If you use the signed-in PDF upload option, EasyQR stores the PDF so it can be opened through the link encoded in your QR code. Anyone with that link may be able to access the PDF, so you should not upload confidential documents. If you attach a file to a support conversation, EasyQR stores that file privately and provides time-limited access to authorized administrators.
Support and contact information
The public contact form collects your name, email address, and message. Messages are stored in the EasyQR Admin Inbox. Support conversations may also include subjects, replies, attachments, delivery status, and related account context. To help prevent form abuse, EasyQR stores a shortened hash derived from the submitter's IP address and applies submission timing and rate checks. New-message alerts may include message details and are delivered to an administrator-designated Google mailbox.
2. Authentication and account security
EasyQR supports email-and-password authentication and Google sign-in. EasyQR's hosted backend processes authentication records and session data used to create accounts, sign users in, keep sessions active, secure protected pages, and recover access. Google processes information when you choose Google sign-in.
Password reset links are sent to the account email address. EasyQR does not display passwords to users or administrators. Session information may be stored in browser storage or cookies used by the authentication system.
3. Payment and subscription information
Stripe processes payments for Pro and Business subscriptions. Stripe receives the payment method and transaction information needed to complete a purchase and manage recurring billing. EasyQR does not receive or store complete payment-card numbers.
EasyQR receives and stores limited billing records needed to provide plan access, such as a Stripe customer and subscription reference, plan, billing interval, subscription status, current period end, cancellation setting, billing environment, and payment-failure or grace-period status. Stripe's handling of payment data is governed by its own privacy policy.
4. Dynamic QR scans and analytics
When a device requests an EasyQR dynamic short link, EasyQR resolves the saved destination and may record the following information to operate redirects and provide account analytics:
- Date and time of the request
- QR code requested and aggregate scan totals
- Approximate country, region, and city when supplied by network infrastructure
- Device type, operating system, and browser derived from the user-agent string
- Referring page information, when the requesting device supplies it
- A truncated user-agent value and an indicator of likely automated or bot traffic
- A shortened hash derived from the IP address, rather than the full IP address
- A daily rotating hashed visitor indicator used to estimate unique scans
EasyQR does not request precise GPS location for QR scans. Approximate location can be unavailable or inaccurate. The unique-scan indicator estimates distinct devices for a QR code on a given day and is not intended to identify a scanner by name.
5. Website analytics
EasyQR uses Google Tag Manager on pages that render the public site and application. It is not loaded by the direct dynamic QR redirect response. Tags configured through Google Tag Manager may measure page views, device and browser information, traffic source, interactions, and approximate location. The exact tags active in the Google Tag Manager container are managed outside the EasyQR application code.
EasyQR also records product-level events such as opening or using a free tool, generating or downloading a QR code, selecting a template, and starting or completing account creation. These events are designed to use event names and coarse product properties rather than direct personal identifiers.
7. Service email
EasyQR uses Lovable's managed transactional email service and the verified notify.easy-qr.co sending domain for account, login, password recovery, security, billing, signup, contact notification, and support-reply messages where applicable. Support replies use hello@easy-qr.co as the reply address.
These operational messages are distinct from marketing email. EasyQR may need to send essential account, security, billing, or support messages even when a user does not receive promotional communications.
8. How we use information
- Provide, operate, maintain, and troubleshoot the Service
- Create accounts, authenticate users, maintain sessions, and recover access
- Create and manage QR codes, resolve dynamic redirects, and maintain dashboards
- Provide scan totals, reports, and analytics where offered
- Process subscriptions, enforce plan limits, and communicate billing status
- Respond to contact and support requests
- Send transactional account, security, billing, and support communications
- Detect, investigate, and prevent fraud, spam, malicious redirects, and technical abuse
- Understand product usage and improve EasyQR
- Comply with law, enforce our Terms, and protect users and the Service
10. Data retention
We retain information for as long as reasonably necessary to provide the Service, maintain accounts and QR redirects, preserve subscription and transaction records, support historical analytics, prevent fraud and abuse, resolve disputes, enforce agreements, and comply with legal obligations. Retention depends on the type of record and the reason it is held. Removing a person from an organization does not by itself delete that person's authentication account or every related record. We may delete or anonymize information when it is no longer reasonably needed. No fixed retention period is promised in this policy.
11. Your choices and privacy rights
Account holders can update their name and certain profile, organization, and campaign preferences in EasyQR. Owners and administrators have additional organization and team controls. The application does not currently provide a self-service control that deletes an entire authentication account and all related records.
Depending on where you live and applicable law, you may have rights to request access, correction, deletion, portability, or restriction of personal information, or to object to certain processing. These rights may be subject to verification and legal exceptions. Submit a request through the contact form or to camradcompany@gmail.com.
12. U.S. state privacy rights
Depending on where you live and applicable law, you may have additional state privacy rights. This section does not state that any particular law applies to EasyQR. We will evaluate verified requests under the laws applicable to the request and will not unlawfully discriminate against a person for exercising an applicable privacy right.
13. International users
EasyQR and its service providers may process information in the United States and in other locations where those providers operate. Those locations may have data-protection laws different from the laws where you live. Where required, transfers are handled under mechanisms recognized by applicable law.
14. Children’s privacy
EasyQR is a general business and productivity service and is not directed to children. We do not knowingly seek personal information from children in violation of applicable law. If you believe a child has provided personal information through the Service, contact us so the circumstances can be reviewed and appropriate action taken.
15. Security
EasyQR uses reasonable administrative, technical, and organizational safeguards, including encrypted connections, authenticated access, role-based controls, private storage for designated files, and database authorization rules. No internet service, transmission method, or storage system is completely secure, and EasyQR cannot guarantee absolute security.
16. Third-party sites and QR destinations
EasyQR customers choose the external websites and resources reached through their QR codes. EasyQR does not control those destinations and this policy does not apply to them. Review the destination's privacy notice before providing information there.
17. Changes to this policy
We may update this Privacy Policy as the Service or applicable requirements change. The Last Updated date will identify the latest revision. When appropriate, we may also provide notice through the Service or by transactional email.
18. Contact
CamRadCo
Email: camradcompany@gmail.com
Mailing Address: [MAILING ADDRESS]