Privacy Policy
Last updated: September 2026 • Effective immediately
Our Core Privacy Principle: Zero PII Collection
HoldQR is engineered from the ground up to respect end-user privacy. We never log, store, or sell the IP addresses, device identifiers, or GPS coordinates of people who scan your QR codes.
1. Information We Collect
When you use HoldQR as a customer creating dynamic QR codes, we collect only the minimal data necessary to provide the service:
- Account Information: Your email address and encrypted authentication credentials (managed via Supabase Auth).
- Dynamic QR Configurations: Destination URLs, QR code names, colors, and embedded logos.
- Payment Information: Transaction ID, plan tier, and payment timestamp (handled securely by Dodo Payments as our Merchant of Record; we never store your credit card or banking details).
2. Scanner Privacy & Scan Analytics
When an end user scans a HoldQR dynamic QR code, our edge redirect layer processes the request instantaneously. The scan event records only coarse, non-identifying aggregate metrics:
- Timestamp: Date and time the redirect occurred.
- Coarse Country: 2-letter ISO country code derived from CDN edge headers (e.g. "IN", "US"). No city, postal code, or exact coordinates are ever recorded.
- Device Category: Coarse classification (Desktop, Mobile, Tablet).
- Operating System & Browser: Browser family (e.g. Chrome, Safari) and OS family (e.g. iOS, Android).
- Sanitized Referrer: Origin domain and path only. All sensitive search query strings, tokens, and email addresses are automatically stripped before storage.
3. Data Portability & GDPR / CCPA Compliance
We uphold your complete rights under global data protection laws, including GDPR and CCPA:
- Right to Access & Export: You can download all your account data, QR codes, and analytics anytime in both CSV and JSON formats from your Account Settings.
- Right to Erasure (Right to be Forgotten): You can permanently delete your account at any time. Account deletion immediately cascades to purge all your dynamic QR codes, scan logs, and billing references.
4. Third-Party Service Providers
We partner strictly with industry-standard, compliant infrastructure providers:
- Supabase: For encrypted authentication and PostgreSQL database hosting.
- Dodo Payments: Merchant of Record for secure, PCI-DSS compliant global payment processing and automated tax compliance.
- Edge Cloud Infrastructure: For global edge routing, SSL termination, and high-availability redirection.
5. Contact Our Privacy Team
If you have questions or concerns regarding our privacy practices or wish to exercise your data rights, please contact us at:
Email: privacy@holdqr.com