Privacy & Telemetry Principles: QRnaly is designed with applicable privacy and data-protection requirements in mind. We do not sell personal data or profile individual QR code scanners.
Back to Legal Hub
Data Protection & Telemetry Disclosures

Privacy Policy

Last Updated: September 10, 2026 • Effective for all global website visitors and account holders

1. Scope & Commitment

This Privacy Policy explains how QRnaly (qrnaly.com) collects, processes, stores, and safeguards data when you visit our website, generate static QR codes, register an account, manage team workspaces, upload files, or scan a QRnaly-routed dynamic shortlink.

2. Information Provided by Users

When creating an account, subscribing to a plan, or contacting support, you may provide your name, email address, password hash, workspace name, and billing details. For anonymous static generation, no user registration data is collected.

3. Account & Authentication Data

Passwords are cryptographically hashed with strong one-way algorithms before storage. Authentication sessions utilize secure HTTP-only cookies to prevent cross-site scripting (XSS) extraction.

4. Workspace & QR Campaign Data

We store your QR code names, design styling configurations (colors, corner styles, embedded logo URLs), campaign folders, templates, and destination history. All QR records are scoped to your authenticated workspace.

5. QR Destinations & URL Validation

Target destination URLs provided by users are validated and normalized to ensure valid protocol formatting (https://, http://) and checked against automated safety filters to prevent phishing and malicious redirects.

6. Hosted Documents, Images & Media

When you upload a PDF brochure, restaurant menu, or brand image, the file is validated via magic-byte inspection, stored in isolated object storage, and served over encrypted HTTPS when users scan the associated QR code.

7. Billing & Payment Information

All payment transactions are handled directly by our certified payment processor, Razorpay Software Private Limited. QRnaly never receives, processes, or stores raw credit/debit card numbers, CVVs, or net banking credentials. We receive only transaction identifiers, subscription status, and payment receipts.

8. Developer API & Security Credentials

When a Business workspace generates a REST API key, the secret key is displayed exactly once. The database stores only a cryptographic SHA-256 hash and a masked display suffix (e.g. ...8a9f) for verification.

9. QR Scan Telemetry & Scanner Privacy

9.1 Aggregate Technical Metrics: Scan analytics are designed to provide aggregate technical information about QR campaign performance (e.g. total scans, unique daily scans, device categories, operating systems, browsers, referrers, and approximate cities) rather than identify individual human scanners.

9.2 Cryptographic IP Hashing: IP addresses processed during redirection are immediately passed through a salted cryptographic hash function before storage. Raw IP addresses are not stored in our scan analytics database.

9.3 No Scanner Profiling: We do not deploy cross-site tracking cookies on QR scan redirection landing pages, build advertising profiles on scanners, or sell scan telemetry to data brokers.

10. Security & Infrastructure Logs

Standard server logs (timestamps, request methods, response status codes, and edge IP information) are retained for a limited operational window for DDoS mitigation, intrusion detection, and performance optimization.

11. Cookies & Local Browser Storage

We use strictly necessary cookies for user authentication, CSRF security tokens, and payment processing. Where enabled, aggregated web performance analytics (Google Analytics 4 with IP anonymization under Google Consent Mode v2) operate strictly based on user cookie preferences. Full details are in our Cookie Policy.

12. Third-Party Service Providers

We share data with third-party service providers solely to the extent necessary to deliver the service, including payment processing (Razorpay), managed cloud database infrastructure (Neon PostgreSQL), and edge distribution. See our Authorized Subprocessors directory.

13. Data Retention Lifecycles

Account data, workspace configurations, and paid Dynamic QR records are retained while your account remains active. Free trial hosted documents are subject to a 30-day retention window. Scan telemetry records are aggregated and retained to support historical dashboard reporting.

14. Data Deletion Requests

Users may request account deletion or data removal by contacting privacy@qrnaly.com. QRnaly handles deletion requests according to its data-retention practices and applicable statutory, accounting, or security compliance obligations.

15. Data Access & Export

Account owners may download their QR code assets in vector SVG and PNG formats at any time and export scan analytics data in standard CSV format from the analytics dashboard.

16. International Data Transfers

Where technical infrastructure involves cloud service providers operating across global data centers, data transfers are safeguarded with standard contractual clauses and encryption in transit and at rest.

17. Children's Privacy

QRnaly is a business productivity tool not directed toward children under 18 years of age. We do not knowingly collect personal data from minors.

18. User Rights & Data Protection Inquiries

Subject to applicable local data protection legislation, you may have the right to access, rectify, or request the restriction of processing of your personal data. Inquiries should be directed to our Privacy Team at privacy@qrnaly.com.

19. Technical & Organizational Safeguards

We implement industry-standard security safeguards including TLS 1.3 encryption in transit, AES-256 encrypted database storage, salted IP telemetry hashing, HTTP-only authentication cookies, and role-based access controls. Details are available in our Security Policy.

20. Changes to this Privacy Policy

We may update this Privacy Policy periodically to reflect technological, operational, or legal developments. Changes will be posted on this page with an updated revision date.

21. Contact Information & Grievance Officer

For privacy queries, data protection inquiries, or statutory notices:

Privacy Team: privacy@qrnaly.com • Grievance Officer: Grievance Redressal Mechanism