Privacy policy

What we collect, why we collect it, and what you can do about it — in plain language.

Last updated: 13 July 2026

⚠ This page is not ready to be published.

The following details are still missing from apps/web/src/lib/legal/company.ts. Fill them in and this banner disappears on its own.

  • EU representative — address in an EU member state (GDPR Art. 27)
The short version
  • Your data is stored in the EU. Our servers run at Hetzner Online GmbH, HEL1 — Helsinki, Finland (EU).
  • We show no ads and we sell nothing to anyone. Your data is not a product.
  • No cookie banner, because we set no tracking cookies. The only cookies we use keep you signed in and remember your language.
  • Our analytics are cookieless. We use Swetrix, which does not profile you or follow you across sites.
  • You can delete everything. Delete your account and your codes, scans and uploads go with it.

This summary is here to be readable. The sections below are the binding detail.

Who is responsible

The controller for the processing described here is Blue White Water Pte. Ltd., 2 Venture Drive, #19-18 Vision Exchange, Singapore 608526, Singapore. You can reach us about anything on this page at contact@qrvik.com, or through the contact form.

We are established in Singapore. Because we offer our services to people in the European Union, the GDPR applies to us under Art. 3(2), and Art. 27 requires us to designate a representative in the Union. That representative has not yet been designated.

Two different roles

It matters which hat we are wearing, because it changes who decides what happens to your data.

  • For your account, your content and your billing, we are the controller. We decide how that data is handled, and this notice explains how.
  • For scan data, we are a processor acting for our customer. When you scan somebody's QR code, the person or company that created that code decides why the scan is recorded — we merely record it on their instructions. If you want to know why a particular code is tracking you, or you want that data erased, the code's owner is the right party to ask; we will help you reach them.

Business customers who need a data processing agreement (Auftragsverarbeitungsvertrag) covering the second case can request one from us at any time.

What we collect, and why

What happens when a QR code is scanned

This is the part people most want to understand, so here it is plainly.

QRvik supports two kinds of code, and the person creating the code chooses which one they want:

  • Static codes encode the destination directly into the QR image. Scanning one does not touch QRvik at all. We learn nothing, and we record nothing.
  • Dynamic codes encode a short link that passes through our servers before forwarding you to the destination. This is what allows the owner to change the destination after the code is printed, and it is what produces scan statistics.

When a dynamic code is scanned, we record the time, an approximate location (country, region, city), the device type, operating system and browser, the referring page if there is one, and a hashed form of the IP address. We do not store the IP address itself, and we do not place a cookie on the scanning device.

We want to be precise rather than flattering about that hash. It is a one-way hash, so it is not readable — but because the space of possible IP addresses is small, a hash of an IP address is not truly anonymous. We therefore treat it as pseudonymised personal data and give it the full protection of this notice, rather than claiming it falls outside the GDPR. Its only purposes are to estimate how many distinct people scanned a code, and to detect abuse.

Cookies

We use two cookies, both strictly necessary, and neither of which tracks you:

  • session — keeps you signed in. Set only when you log in.
  • locale — remembers which language you chose.

We set no advertising, profiling or cross-site tracking cookies, which is why you have not been asked to consent to any. Strictly necessary cookies do not require consent under the ePrivacy Directive.

Analytics

We measure how our website is used with Swetrix, a privacy-first analytics tool that works without cookies and without a persistent identifier. It does not build a profile of you, does not follow you to other websites, and does not collect data that can identify you personally. We use it only to see which pages people find useful.

Who else touches your data

We keep the list of third parties deliberately short. These are all of them:

We do not sell your data, and we do not share it with advertisers. There is no such business here to be in.

Transfers outside the EEA

Your data is stored in the European Union. But we should be straight with you about one thing that a great many privacy policies quietly skip: QRvik is a Singapore company, and our staff administer the service from outside the EEA. Singapore is not covered by an EU adequacy decision. That access is therefore a transfer to a third country, and we rely on the European Commission's Standard Contractual Clauses, together with technical and organisational measures — encryption in transit, access limited to the few people who need it, and an append-only audit log of every administrative action — to protect it.

The individual transfers made by Stripe, Cloudflare and Google are listed in the table above. You may request a copy of the safeguards we rely on by writing to us.

How we protect it

  • All traffic is encrypted in transit with TLS.
  • Passwords are stored only as Argon2 hashes. Even we cannot read them.
  • Uploaded files and rendered images are stored in a private bucket that permits no anonymous access.
  • Administrative access is limited to staff who need it, and every sensitive administrative action — including any support access to an account — is written to an append-only audit log.

Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you (Art. 15).
  • Correct it if it is wrong (Art. 16).
  • Erase it (Art. 17). Deleting your account removes your codes, scan data and uploads.
  • Restrict or object to processing based on our legitimate interests (Art. 18, 21) — including scan analytics.
  • Take your data with you in a portable format (Art. 20).
  • Withdraw consent at any time, where we relied on it.

Write to contact@qrvik.com and we will answer within one month. We do not charge for this.

You also have the right to lodge a complaint with a supervisory authority, in the EU member state where you live, work, or where you believe the problem occurred. You do not have to come to us first, though we would rather you did — it is usually faster.

Children

QRvik is a tool for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16.

Changes to this notice

If we change how we handle personal data, we will update this page and move the date at the top. If a change is significant, we will tell account holders by email rather than hoping they notice.