Privacy Policy
Last Updated: September 10, 2026 • Effective for all global website visitors and account holders
1. Scope & Commitment
This Privacy Policy explains how QRnaly (qrnaly.com) collects, processes, stores, and safeguards data when you visit our website, generate static QR codes, register an account, manage team workspaces, upload files, or scan a QRnaly-routed dynamic shortlink.
2. Information Provided by Users
When creating an account, subscribing to a plan, or contacting support, you may provide your name, email address, password hash, workspace name, and billing details. For anonymous static generation, no user registration data is collected.
3. Account & Authentication Data
Passwords are cryptographically hashed with strong one-way algorithms before storage. Authentication sessions utilize secure HTTP-only cookies to prevent cross-site scripting (XSS) extraction.
4. Workspace & QR Campaign Data
We store your QR code names, design styling configurations (colors, corner styles, embedded logo URLs), campaign folders, templates, and destination history. All QR records are scoped to your authenticated workspace.
5. QR Destinations & URL Validation
Target destination URLs provided by users are validated and normalized to ensure valid protocol formatting (https://, http://) and checked against automated safety filters to prevent phishing and malicious redirects.
6. Hosted Documents, Images & Media
When you upload a PDF brochure, restaurant menu, or brand image, the file is validated via magic-byte inspection, stored in isolated object storage, and served over encrypted HTTPS when users scan the associated QR code.
7. Billing & Payment Information
All payment transactions are handled directly by our certified payment processor, Razorpay Software Private Limited. QRnaly never receives, processes, or stores raw credit/debit card numbers, CVVs, or net banking credentials. We receive only transaction identifiers, subscription status, and payment receipts.
8. Developer API & Security Credentials
When a Business workspace generates a REST API key, the secret key is displayed exactly once. The database stores only a cryptographic SHA-256 hash and a masked display suffix (e.g. ...8a9f) for verification.
9. QR Scan Telemetry & Scanner Privacy
9.1 Aggregate Technical Metrics: Scan analytics are designed to provide aggregate technical information about QR campaign performance (e.g. total scans, unique daily scans, device categories, operating systems, browsers, referrers, and approximate cities) rather than identify individual human scanners.
9.2 Cryptographic IP Hashing: IP addresses processed during redirection are immediately passed through a salted cryptographic hash function before storage. Raw IP addresses are not stored in our scan analytics database.
9.3 No Scanner Profiling: We do not deploy cross-site tracking cookies on QR scan redirection landing pages, build advertising profiles on scanners, or sell scan telemetry to data brokers.
10. Security & Infrastructure Logs
Standard server logs (timestamps, request methods, response status codes, and edge IP information) are retained for a limited operational window for DDoS mitigation, intrusion detection, and performance optimization.
11. Cookies & Local Browser Storage
We use strictly necessary cookies for user authentication, CSRF security tokens, and payment processing. Where enabled, aggregated web performance analytics (Google Analytics 4 with IP anonymization under Google Consent Mode v2) operate strictly based on user cookie preferences. Full details are in our Cookie Policy.
12. Third-Party Service Providers
We share data with third-party service providers solely to the extent necessary to deliver the service, including payment processing (Razorpay), managed cloud database infrastructure (Neon PostgreSQL), and edge distribution. See our Authorized Subprocessors directory.
13. Data Retention Lifecycles
Account data, workspace configurations, and paid Dynamic QR records are retained while your account remains active. Free trial hosted documents are subject to a 30-day retention window. Scan telemetry records are aggregated and retained to support historical dashboard reporting.
14. Data Deletion Requests
Users may request account deletion or data removal by contacting privacy@qrnaly.com. QRnaly handles deletion requests according to its data-retention practices and applicable statutory, accounting, or security compliance obligations.
15. Data Access & Export
Account owners may download their QR code assets in vector SVG and PNG formats at any time and export scan analytics data in standard CSV format from the analytics dashboard.
16. International Data Transfers
Where technical infrastructure involves cloud service providers operating across global data centers, data transfers are safeguarded with standard contractual clauses and encryption in transit and at rest.
17. Children's Privacy
QRnaly is a business productivity tool not directed toward children under 18 years of age. We do not knowingly collect personal data from minors.
18. User Rights & Data Protection Inquiries
Subject to applicable local data protection legislation, you may have the right to access, rectify, or request the restriction of processing of your personal data. Inquiries should be directed to our Privacy Team at privacy@qrnaly.com.
19. Technical & Organizational Safeguards
We implement industry-standard security safeguards including TLS 1.3 encryption in transit, AES-256 encrypted database storage, salted IP telemetry hashing, HTTP-only authentication cookies, and role-based access controls. Details are available in our Security Policy.
20. Changes to this Privacy Policy
We may update this Privacy Policy periodically to reflect technological, operational, or legal developments. Changes will be posted on this page with an updated revision date.
21. Contact Information & Grievance Officer
For privacy queries, data protection inquiries, or statutory notices:
Privacy Team: privacy@qrnaly.com • Grievance Officer: Grievance Redressal Mechanism