Privacy Policy — WebQR.io
Last updated: July 11, 2026
WebQR.io is operated by Roman Sadoev as a sole trader.
1. Introduction
This Privacy Policy describes what personal data WebQR.io collects, for what purposes, and how it is stored and protected, as well as the rights you have regarding your data. By using the Service, you confirm your agreement to this Policy. If you do not agree, please stop using the Service.
2. Definitions
3. Data We Collect
We collect only the data necessary for the operation of the Service:
- Account data: email address, name (upon registration).
- Social login data: if you register or log in via a third-party provider (Google, Facebook, or Apple), we receive your name, email address, and profile identifier from that provider.
- Payment data: when paying for a paid plan — data is processed directly by the payment provider; we retain only the fact and date of the transaction.
- Technical data: IP address, browser type, operating system, referring page, time of visit.
- Usage data: history of QR codes created, selected parameters and formats.
- Location data: if GPS tracking is enabled by the QR code owner, precise coordinates may be collected from individuals who scan the QR code — only with their explicit browser consent.
- Cookies: session identifiers, interface preferences, analytics identifiers.
We do not collect biometric data or special categories of personal data.
4. Purposes and Legal Bases for Processing
We process your data on the following legal bases (Article 6 GDPR):
- Performance of a contract — providing access to the Service, processing payments, sending account notifications.
- Legitimate interests — ensuring security, detecting abuse, improving the technical operation of the Service.
- Consent — marketing updates, optional analytics cookies. Consent may be withdrawn at any time.
- Legal obligation — retaining data in cases required by Georgian law.
5. Data Retention Periods
- Account data — retained while the account is active.
- After account deletion — data is deleted within 30 days, except where we are legally required to retain it.
- Technical logs — no longer than 90 days.
- Anonymous web analytics (Matomo) — raw visit logs up to 180 days; aggregated reports up to 12 months.
- Payment records — in accordance with Georgian tax law requirements (generally 6 years).
6. Sharing Data with Third Parties
We do not sell your personal data. Data may be shared with third parties only in the following cases:
- Payment providers (Paddle) — to process payments for paid plans. Paddle may collect payment card details directly; we do not store card numbers.
- Analytics services — Matomo, which we run on our own infrastructure (data is not shared with a third party), and, only where a QR code owner has configured it on their own dynamic page, Google Analytics / Google Tag Manager.
- Cloud storage providers (Cloudflare) — for hosting user-uploaded files and generated QR code images.
- Advertising technologies (for example Meta Pixel) — may appear on dynamic QR pages only when configured by the page owner. They are never used by WebQR as a platform ad network and never in the account dashboard. They load only after advertising consent is given and respect the Global Privacy Control signal.
- Authentication providers (Google, Facebook, Apple) — to verify your identity if you choose to log in via a social account.
- As required by law — upon request from authorised Georgian state authorities.
Where data is transferred outside Georgia, we ensure an adequate level of protection in accordance with GDPR requirements (standard contractual clauses or adequacy decisions).
7. Cookies and Tracking Technologies
- Essential — necessary for the Service to function (session, authentication, security, language and theme preference, load balancing). Cannot be disabled.
- Analytical cookies — optional first-party analytics cookies (Matomo) and, on some dynamic QR pages, Google Analytics/Tag Manager configured by the page owner. This category controls whether analytics cookies are set; it does not control our cookieless web statistics (see below). Outside the EU/EEA/UK analytics cookies are on by default; inside the EU/EEA/UK they stay off until you actively consent.
- Advertising — Meta Pixel when configured by a dynamic QR page owner. WebQR does not run platform ads on public tool pages or in the account dashboard. Off by default and activated only with the visitor's explicit consent.
- Regional defaults — visitors from the EU, EEA and UK see a cookie banner before any non-essential cookie is set; analytics and advertising cookies stay off until you actively accept them (opt-in). Visitors from other regions see a notice with analytics cookies on by default, which you can switch off in one click (opt-out). Basic cookieless web statistics may still be collected as described below, regardless of region.
- Global Privacy Control (GPC) — if your browser or a browser extension sends the GPC signal, we automatically treat this as a request to opt out of advertising cookies and never activate the Advertising category, regardless of any other setting.
- Do Not Track (DNT) — if your browser sends a Do Not Track signal and you have not given analytics consent, our Matomo instance does not record your visit.
Web analytics (Matomo). We use a self-hosted Matomo instance on our own infrastructure (stat.webqr.io) on our public website and on dynamic QR landing pages. Without analytics consent (or with analytics cookies disabled): we collect only aggregated, cookieless statistics — page views, approximate country/region (from an anonymised IP address with at least two bytes masked), browser and device type, and referrer domain. We do not set Matomo visitor-ID cookies and do not recognise returning visitors across sessions. With analytics consent: Matomo may set first-party analytics cookies (such as _pk_id) to recognise returning visitors, measure sessions, and provide fuller reports. If you withdraw analytics consent, Matomo cookies are removed and tracking reverts to cookieless mode; basic anonymous page-view statistics continue on public pages. You can opt out via our cookie settings or Matomo's opt-out page: https://stat.webqr.io/index.php?module=CoreAdminHome&action=optOut
Account dashboard (cabinet) analytics. When you are logged in and have given analytics consent, our Matomo desk tracker may associate your visits with an internal pseudonymous identifier (user:{account id}, not your email) to help us find UX issues and errors. This applies only in the account dashboard, not on public marketing pages. When you delete your account, we remove this link in Matomo: your past page views remain as anonymous statistics and can no longer be attributed to you.
You can manage cookie preferences at any time via the consent banner, the "Cookie settings" link in the website footer, or (if you are logged in) the Cookies section of your account Settings. Disabling analytics cookies removes Matomo visitor-ID cookies and reverts to cookieless statistics on public pages; it does not stop basic anonymous page-view counting there. In your account dashboard, Matomo loads only after analytics consent. We keep a server-side record of each consent decision (region, categories, method, timestamp) as evidence of compliance. Disabling optional cookies does not affect the core functionality of the Service.
8. Data Security
We implement technical and organisational measures to protect your data:
- encryption of data in transit (HTTPS/TLS);
- storage of passwords in hashed form;
- restricted database access (only necessary personnel);
- regular backups.
We cannot guarantee the absolute security of data transmitted over the internet. In the event of a data breach affecting your rights, we will notify you within the timeframes required by applicable law.
9. Your Rights under GDPR
If you are located in the European Economic Area, you have the following rights:
- Right of access — to receive a copy of your personal data.
- Right to rectification — to request correction of inaccurate data.
- Right to erasure — to request deletion of data ("right to be forgotten").
- Right to restriction of processing — to limit how your data is used.
- Right to data portability — to receive your data in a machine-readable format.
- Right to object — to object to processing based on legitimate interests.
- Right to withdraw consent — at any time, without affecting the lawfulness of processing prior to withdrawal.
- Right to lodge a complaint — with the data protection supervisory authority in your country.
To exercise any right, contact us at [email protected]. We will respond within 30 days. You may also export your data at any time via the account settings page; data is provided in JSON format.
California Privacy Rights (CCPA/CPRA)
If you are a California resident, the CCPA/CPRA gives you the following rights in addition to those above:
- Right to know — what personal information we collect, use, and disclose, and for what purpose.
- Right to delete — request deletion of personal information we hold about you, subject to certain legal exceptions.
- Right to correct — request correction of inaccurate personal information.
- Right to opt out of sale or sharing — we do not sell your personal information. Where a page owner uses advertising cookies (for example Meta Pixel) on a dynamic QR page, this may be considered "sharing" under the CPRA; we do not activate them without consent and automatically honour the Global Privacy Control (GPC) signal as a valid opt-out request.
- Right to limit use of sensitive personal information — we do not use sensitive personal information for purposes beyond providing the Service.
- Right to non-discrimination — exercising any of these rights will not result in denial of service, a different price, or a different level of quality.
To exercise any of these rights, contact us at [email protected]. We will not discriminate against you (e.g. by denying service or charging a different price) for exercising any of these rights.
10. Age of Users
The Service is intended for individuals aged 16 or over. We do not knowingly collect data from persons under 16. If you become aware that a child under 16 has provided us with personal data, please notify us at [email protected] — we will delete that data without delay.
11. Links to Third-Party Sites
The Service may contain links to third-party websites. We are not responsible for their privacy policies or data processing practices. We recommend reviewing the privacy policy of each third-party resource before using it.
12. Changes to This Policy
We reserve the right to amend this Privacy Policy. We will notify you by email at least 30 days before any changes take effect. The current version is always available at webqr.io/privacy.
13. Data Collected from QR Code Scanners
When an individual scans a QR code or follows a short link generated through the Service, certain data may be collected even if that individual is not a registered User:
- IP address and approximate geographic location derived from it;
- device type, browser, and operating system;
- date and time of the scan or click;
- precise GPS coordinates — only if the QR code owner has enabled GPS tracking and the user scanning the QR code grants explicit browser permission. GPS data is never collected without active consent.
This data is used to provide scan analytics to the QR code owner. It is processed on the legal basis of the legitimate interests of the QR code owner (Article 6(1)(f) GDPR). We do not use this data for our own marketing purposes.
Scan analytics data is retained for the same period as the associated QR code. If the QR code is deleted, scan data is removed within 30 days.
Contact
For all questions relating to the processing of personal data:
- Email: [email protected]
- Website: webqr.io
We aim to respond to all requests within 30 days.