Privacy Policy
Effective date: October 1, 2026.
Who we are and scope
Daniel Madar, doing business as OpticQR, operates opticqr.com. Contact support@opticqr.com for privacy questions, access, correction, export, or deletion requests. This policy covers account holders, collaborators, and people opening OpticQR-hosted links. Independent destinations reached through a QR code have their own policies.
Information we process
- Account information: your account identifier, verified email address, and name. You can sign up with an email and password, verify your email with a single-use link, or use Google sign-in. Passwords are stored as salted hashes, never plain text. Verification links expire after 24 hours and password reset links after 30 minutes. We do not receive your Google password or request access to Gmail or Drive.
- Content and settings: code names and destinations, contact-card and link-page content, design settings, uploaded logos, connected domains, workspace information, sharing invitations, company workspaces, project membership, group membership, and supported activity records.
- Analytics: aggregate visit counts by day or hour, approximate country/region/city, device category, operating system, browser, and language, when available. These are not unique-person counts. We do not store raw visitor IP addresses in scan-statistics tables. Our hosting provider processes network information, including IP addresses, to deliver and protect requests; this statement does not mean no provider processes an IP address.
- Security: session identifiers, sign-in nonces, password hashes for protected codes, and short-lived attempt counters based on a hash of network information and a time window. Hosting logs may contain operational request and error information.
- Billing, when enabled: Stripe customer and subscription identifiers, subscription status, and billing-period information. Stripe processes payment details directly; we do not store full card numbers.
- Support: information you choose to include when contacting us.
How we use information
We use information to authenticate users, create and deliver codes and hosted pages, provide analytics, manage sharing and custom domains, administer paid access, answer support requests, prevent abuse, and maintain the service. We do not sell account or scan data or use scan analytics for advertising profiles. Sharing invitations are emailed when the sharer requests email notification and sending is enabled. Optional scheduled reports or alerts are not yet available and are not enabled by visiting a QR link.
Sharing and service providers
Cloudflare provides hosting, database, file storage, and network/security services. Google provides account sign-in. Stripe provides payments when enabled. During the hosting migration, the legacy ChatGPT Sites address may still use OpenAI’s hosting to serve or forward existing links. We will update this policy when that dependency is removed. Cloudflare Email Routing forwards support mail. When outgoing email is configured, Resend processes recipient addresses and message contents to deliver requested sign-in codes and sharing invitations.
Code owners, authorized viewers, editors, workspace members, and people in groups with project access can access data allowed by their roles. Group membership may grant access to all codes in a shared project, including codes added later. A hosted page’s content is public to people who can open its URL, unless applicable protections are enabled. We may disclose information when required by law or reasonably necessary to protect the service or people, and to a successor in a business transfer subject to appropriate notice and protections.
Necessary cookies and local processing
We use a secure sign-in session cookie lasting up to seven days, a sign-in nonce and email-verification challenge cookie lasting up to ten minutes, and, after unlocking a protected code, a necessary unlock cookie lasting up to one hour. We do not use advertising cookies in OpticQR. Google’s sign-in component is provided by Google and its use is subject to Google’s privacy information. Blocking necessary cookies may prevent sign-in or protected-code access. Downloaded static QR codes operate without sending a scan to OpticQR unless their encoded destination itself uses OpticQR.
Retention and choices
Saved codes and aggregate analytics do not have a scheduled automatic expiry merely because they become old. Access to reports can depend on your plan and available reporting controls. You can export supported code lists and reports and delete individual codes with their associated scan statistics. Contact us to request broader account access, correction, export, or deletion. We may verify your identity and authority before acting. Records needed for legitimate legal, payment, fraud-prevention, and security purposes, or in backups awaiting normal replacement, may remain for the period reasonably needed for those purposes. We do not promise immediate removal from every backup.
International processing and rights
Providers may process information in countries other than yours. Where applicable, we use required safeguards for those transfers. Depending on your location, you may have rights to access, correct, delete, or receive your information, restrict or object to processing, or complain to a relevant regulator. Where consent is the basis for processing, you can withdraw it without affecting earlier lawful processing. Where applicable, processing supports providing the requested service, legitimate interests in security and operation, and legal obligations. We will assess requests under the law that applies to you.
Children, security, and updates
OpticQR accounts are intended for adults, not children. Do not upload children’s personal information unless you have the necessary authority and safeguards. Contact us if you believe a child has provided account information. We use access controls and secure connections, but no service can guarantee absolute security. This policy will show an updated date when it changes, and material changes will receive additional notice where required.