Legal
Privacy Policy
Last updated: July 15, 2026
This Privacy Policy explains how AcreateQR (“AcreateQR”, “we”, “us”) collects, uses, and shares information when you use acreateqr.com and the AcreateQR service (the “Service”). It also covers the limited information we record when someone scans a QR code you create.
1. Information We Collect
Account information
When you create an account we store your email address and name. We do not use passwords for accounts — you sign in with a one-time code (OTP) sent to your email. We store only a cryptographic hash of that code, never the code itself, and it expires after 10 minutes.
QR code content you create
We store the QR codes you build, including their name, type, destination or content, and visual customization. Depending on the QR type you choose, this content may itself contain personal data that you enter — for example a contact card’s name, phone number, email, or address; a phone number for WhatsApp or SMS; a Wi-Fi network name and password; or a map location. Uploaded images, videos, and PDFs are embedded directly into the QR code record. You control this content and can edit or delete it at any time.
Payment information
Subscriptions are handled by Stripe using Stripe-hosted checkout and billing pages. Your card details are entered on Stripe’s pages and are never seen or stored by us. We retain only your Stripe customer and subscription identifiers, your subscription status, and its renewal date.
Scan data (from people who scan your codes)
When someone scans one of your QR codes, we record only the country the scan came from and the date and time. The country is derived from the visitor’s IP address using an offline lookup — the IP address itself is not stored, and we do not record city, device details, browser fingerprints, or set any cookie on people who scan codes.
Usage analytics
We use Mixpanel to understand how the product is used (for example, when a QR code is created or a signup completes). For signed-in users, these events are associated with your internal account identifier; we do not send your email or name to Mixpanel. Mixpanel respects your browser’s “Do Not Track” setting and stores its state in your browser’s local storage rather than in cookies.
Cookies
We use a single, strictly necessary session cookie (connect.sid) to keep you signed in. It contains only an opaque session identifier; the session data lives on our server. We do not use advertising or third-party tracking cookies.
2. How We Use Information
- To provide the Service — creating, hosting, and redirecting your QR codes.
- To authenticate you via one-time email codes and keep you signed in.
- To process subscriptions, trials, and billing through Stripe.
- To show you aggregate scan analytics for the codes you own.
- To operate, secure, debug, and improve the Service.
- To send you transactional email (such as sign-in and email-change codes).
3. How We Share Information
We do not sell your personal data. We share information only with the service providers that help us run AcreateQR (“sub-processors”):
- Stripe — payment processing. Receives your email, name, and account identifier to manage your subscription.
- Brevo — transactional email delivery. Receives your email address and the message content (such as your one-time sign-in code).
- Mixpanel — product analytics, as described above.
We may also disclose information if required by law, to enforce our Terms of Service, or to protect the rights, safety, and security of our users and the Service.
4. Data Retention
We keep your account and QR code data for as long as your account is active. One-time codes expire within minutes. Scan records are retained to provide your analytics. If you delete a QR code, its scan history is deleted with it. When your account is deleted, your associated data — QR codes, scans, subscription records, and sign-in codes — is removed.
5. Security
Traffic is served over HTTPS. Sign-in codes are stored as HMAC-SHA256 hashes and optional per-QR passwords are stored using bcrypt. Sessions are stored server-side and session cookies are HTTP-only. No method of transmission or storage is completely secure, but we take reasonable measures to protect your information.
6. Your Rights and Choices
You can, from within the Service:
- Update your name and email address (email changes are verified with a one-time code).
- Edit or delete any QR code you have created.
- Cancel your subscription at any time through the Stripe billing portal.
Depending on where you live, you may have additional rights to access, correct, export, or delete your personal data, or to object to or restrict its processing. Account deletion and data export are not yet self-service — to request either, or to exercise any of these rights, contact us at privacy@acreateqr.com.
7. International Data Transfers
We and our sub-processors may process your information in countries other than your own. Where we transfer personal data internationally, we rely on appropriate safeguards as required by applicable law.
8. Children
The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us data, contact us and we will delete it.
9. Changes to This Policy
We may update this Policy from time to time. When we do, we will revise the “Last updated” date above and, where appropriate, notify you.
10. Contact Us
Questions about this Policy or your data? Contact AcreateQR at privacy@acreateqr.com. This Policy is governed by the laws of Armenia.