Legal document

Privacy policy

This policy explains what information we collect, why we collect it, and how we handle it.

Effective date: February 24, 2026

Contact: [email protected]

1. Information we collect

We collect account details such as name and email, plus organization membership and role information.

We also collect QR code metadata, scan activity events, and operational telemetry required to run and secure the platform.

2. How we use data

We use data to provide authentication, billing, QR management, analytics, collaboration, and abuse prevention.

We do not sell your personal data.

3. Data sharing

We share data with service providers required to operate the platform, including hosting, authentication, and payments providers.

These providers process data under contractual and security requirements.

4. Data retention

Data retention follows subscription limits, legal requirements, and account lifecycle state.

Deleted organizations and accounts are removed from active systems, then from backups on a rolling schedule.

5. Security

We use role-based access controls, encryption in transit, and least-privilege service configuration.

No transmission or storage method is fully risk-free, but security controls are continuously reviewed and updated.

6. Your choices

You can manage organization members, rotate or revoke API keys, and request deletion of your account.

For privacy requests, contact [email protected].