Privacy policy
What we collect, why we collect it, and what you can do about it — in plain language.
Last updated: 13 July 2026
The following details are still missing from apps/web/src/lib/legal/company.ts.
Fill them in and this banner disappears on its own.
- EU representative — address in an EU member state (GDPR Art. 27)
- Your data is stored in the EU. Our servers run at Hetzner Online GmbH, HEL1 — Helsinki, Finland (EU).
- We show no ads and we sell nothing to anyone. Your data is not a product.
- No cookie banner, because we set no tracking cookies. The only cookies we use keep you signed in and remember your language.
- Our analytics are cookieless. We use Swetrix, which does not profile you or follow you across sites.
- You can delete everything. Delete your account and your codes, scans and uploads go with it.
This summary is here to be readable. The sections below are the binding detail.
Who is responsible
The controller for the processing described here is Blue White Water Pte. Ltd., 2 Venture Drive, #19-18 Vision Exchange, Singapore 608526, Singapore. You can reach us about anything on this page at contact@qrvik.com, or through the contact form.
We are established in Singapore. Because we offer our services to people in the European Union, the GDPR applies to us under Art. 3(2), and Art. 27 requires us to designate a representative in the Union. That representative has not yet been designated.
Two different roles
It matters which hat we are wearing, because it changes who decides what happens to your data.
- For your account, your content and your billing, we are the controller. We decide how that data is handled, and this notice explains how.
- For scan data, we are a processor acting for our customer. When you scan somebody's QR code, the person or company that created that code decides why the scan is recorded — we merely record it on their instructions. If you want to know why a particular code is tracking you, or you want that data erased, the code's owner is the right party to ask; we will help you reach them.
Business customers who need a data processing agreement (Auftragsverarbeitungsvertrag) covering the second case can request one from us at any time.
What we collect, and why
| Data | What it is | Why | Legal basis | How long |
|---|---|---|---|---|
| Account | Email address, name (optional), password (stored only as an Argon2 hash — we never see or store the password itself), or your Google account identifier if you sign in with Google | To create and secure your account and to let you sign in | Art. 6(1)(b) — performance of a contract | Until you delete your account |
| Session | A hashed session token and its expiry, stored in a cookie on your device | To keep you signed in between page loads | Art. 6(1)(b) — strictly necessary to provide the service you asked for | Until the session expires or you sign out |
| Content you create | QR code names, destination URLs, and any content you type into a code — which may include contact details in a vCard code or a Wi-Fi password in a Wi-Fi code — plus link-page profiles, images you upload, and the rendered QR images | To store, render and serve the codes you build | Art. 6(1)(b) — performance of a contract | Until you delete the code, or your account |
| Billing | Your Stripe customer identifier, plan, subscription status, and invoices (amount, date, PDF). Card numbers are entered on Stripe's own checkout page and never reach our servers | To take payment for paid plans and issue invoices | Art. 6(1)(b) — contract; Art. 6(1)(c) — statutory retention of accounting records | Invoices are retained for the statutory accounting period, even after you close your account |
| Scan events | A pseudonymised (hashed) IP address, approximate location derived from it (country, region, city), device type, operating system, browser, referring page, and the time of the scan | To give the owner of a QR code the scan statistics they signed up for, and to protect against abuse | Art. 6(1)(f) — legitimate interests of the code owner in understanding how their code performs | Until the QR code or the account that owns it is deleted |
| Messages you send us | Your name, email address, subject and message, plus a hashed IP address | To answer you, and to stop the contact form being abused for spam | Art. 6(1)(f) — our legitimate interest in responding to enquiries | As long as needed to deal with your enquiry, then deleted |
What happens when a QR code is scanned
This is the part people most want to understand, so here it is plainly.
QRvik supports two kinds of code, and the person creating the code chooses which one they want:
- Static codes encode the destination directly into the QR image. Scanning one does not touch QRvik at all. We learn nothing, and we record nothing.
- Dynamic codes encode a short link that passes through our servers before forwarding you to the destination. This is what allows the owner to change the destination after the code is printed, and it is what produces scan statistics.
When a dynamic code is scanned, we record the time, an approximate location (country, region, city), the device type, operating system and browser, the referring page if there is one, and a hashed form of the IP address. We do not store the IP address itself, and we do not place a cookie on the scanning device.
We want to be precise rather than flattering about that hash. It is a one-way hash, so it is not readable — but because the space of possible IP addresses is small, a hash of an IP address is not truly anonymous. We therefore treat it as pseudonymised personal data and give it the full protection of this notice, rather than claiming it falls outside the GDPR. Its only purposes are to estimate how many distinct people scanned a code, and to detect abuse.
Cookies
We use two cookies, both strictly necessary, and neither of which tracks you:
session— keeps you signed in. Set only when you log in.locale— remembers which language you chose.
We set no advertising, profiling or cross-site tracking cookies, which is why you have not been asked to consent to any. Strictly necessary cookies do not require consent under the ePrivacy Directive.
Analytics
We measure how our website is used with Swetrix, a privacy-first analytics tool that works without cookies and without a persistent identifier. It does not build a profile of you, does not follow you to other websites, and does not collect data that can identify you personally. We use it only to see which pages people find useful.
Who else touches your data
We keep the list of third parties deliberately short. These are all of them:
| Provider | What for | Where | Transfers outside the EEA |
|---|---|---|---|
| Hetzner Online GmbH | Hosting of the application, database and file storage | Helsinki, Finland (EU) | None — data stays in the EU |
| Stripe, Inc. / Stripe Payments Europe Ltd. | Payment processing and invoicing for paid plans | Ireland (EU) and United States | EU Standard Contractual Clauses; Stripe is certified under the EU–US Data Privacy Framework |
| Cloudflare, Inc. | Edge network that serves the /s short-link redirect and forwards scan events | Global edge network, incl. United States | EU Standard Contractual Clauses; Cloudflare is certified under the EU–US Data Privacy Framework |
| Google Ireland Ltd. | Optional "Sign in with Google" — only if you choose that login method | Ireland (EU) and United States | EU Standard Contractual Clauses; Google is certified under the EU–US Data Privacy Framework |
| Swetrix | Cookieless, privacy-first website analytics (aggregate page views — no cross-site tracking, no profiling) | European Union | None — data stays in the EU |
We do not sell your data, and we do not share it with advertisers. There is no such business here to be in.
Transfers outside the EEA
Your data is stored in the European Union. But we should be straight with you about one thing that a great many privacy policies quietly skip: QRvik is a Singapore company, and our staff administer the service from outside the EEA. Singapore is not covered by an EU adequacy decision. That access is therefore a transfer to a third country, and we rely on the European Commission's Standard Contractual Clauses, together with technical and organisational measures — encryption in transit, access limited to the few people who need it, and an append-only audit log of every administrative action — to protect it.
The individual transfers made by Stripe, Cloudflare and Google are listed in the table above. You may request a copy of the safeguards we rely on by writing to us.
How we protect it
- All traffic is encrypted in transit with TLS.
- Passwords are stored only as Argon2 hashes. Even we cannot read them.
- Uploaded files and rendered images are stored in a private bucket that permits no anonymous access.
- Administrative access is limited to staff who need it, and every sensitive administrative action — including any support access to an account — is written to an append-only audit log.
Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you (Art. 15).
- Correct it if it is wrong (Art. 16).
- Erase it (Art. 17). Deleting your account removes your codes, scan data and uploads.
- Restrict or object to processing based on our legitimate interests (Art. 18, 21) — including scan analytics.
- Take your data with you in a portable format (Art. 20).
- Withdraw consent at any time, where we relied on it.
Write to contact@qrvik.com and we will answer within one month. We do not charge for this.
You also have the right to lodge a complaint with a supervisory authority, in the EU member state where you live, work, or where you believe the problem occurred. You do not have to come to us first, though we would rather you did — it is usually faster.
Children
QRvik is a tool for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16.
Changes to this notice
If we change how we handle personal data, we will update this page and move the date at the top. If a change is significant, we will tell account holders by email rather than hoping they notice.