Privacy Policy

What we collect, why, who else sees it, and how to get a copy or have it removed.

Last updated: 13 September 2026

1. Who we are

MyPersonalQR lets you create QR codes, host the pages they open, and see how often they are scanned. This page explains what we do with personal information.

The company behind the service is MyPersonalQR, registered at [Registered address]. For anything on this page, write to privacy@mypersonalqr.com.

2. Our role when handling your information

Who you should contact about personal information depends on how it was collected.

Your account and your own use of the service

When you create an account and use MyPersonalQR, we decide how your account, billing, support and QR code information is handled. In data protection law we are the controller for that information, and you can contact us about it directly.

QR codes created by another business

Businesses use MyPersonalQR to create their own codes. Where a business decides why scan information is collected and what it is used for, that business is normally the controller, and we handle the information on its behalf as the processor.

If your request relates to a code created by a business, we suggest contacting that business first. It will usually be able to explain the purpose more fully and act on your request directly. If you cannot identify or reach them, write to us at privacy@mypersonalqr.com and we will help where we can.

Separately, we handle limited technical information such as server logs, IP addresses and security events in order to run and protect the service. We are the controller for that, and our role is assessed separately for each purpose.

3. What we collect

When you create an account

  • Your email address, and your password stored as a one way hash. We never see the password itself.
  • Optionally your name, a phone number, and a second email or phone if you add one.
  • If you sign in with Google or LinkedIn, we receive your email address, your name, and the account id they give us. We never receive your password.

What you put in your codes

  • Whatever you enter: a web address, a menu, contact details, opening hours, a property listing, an offer. If any of it relates to a real person, you are responsible for having the right to publish it.
  • Images you upload, such as a logo or a photo.

If you invite someone to your team

Team plans let you invite colleagues by email. When you do, you are giving us that person's email address so we can send the invitation and set up their access. Please only invite people who are expecting it.

When someone scans a dynamic code

  • The date and time.
  • The IP address the scan came from.
  • An approximate country and city, worked out from that IP address.
  • The kind of device, the operating system, and the browser.
  • Which of your pages was served, if the code has a schedule on it.

Scanning a code does not create an account, and we do not follow anyone across other websites.

When someone fills in a form on a hosted page

Some page types include a form. Scanning alone never asks for personal details, but choosing to complete one of these forms does. What happens next depends on the form.

FormWhat it asks forWhat we do with it
Menu orderThe items chosen and any special requestsSent straight to the business. We keep no copy.
Menu feedbackRatings, a comment, and an email address if givenSent straight to the business. We keep no copy.
Property viewing requestA name, an email address or phone number, the time requested, an optional message, and a separate optional tick box for marketing updatesStored so the agent can manage the booking, and emailed to them. Deleted when the code is deleted.

For all of these, the business that created the code is the controller. It decides what the form is for and what it does with the replies, including any marketing consent you give it. Ask that business to see or remove what you sent, and see our role when handling your information above if you cannot reach them.

Payments

Card details go straight to Stripe and never reach our servers. We keep your plan, your subscription status, and your invoice history.

Running the service

  • Server logs, which include IP addresses, request paths and errors.
  • Emails we send you, such as sign in codes and receipts.
  • Messages you send us through the contact form or by email.

What we do not collect

We do not ask for special category information: health, race, religion, political views, trade union membership, sex life or sexual orientation, genetic or biometric data. We do not collect precise GPS location, and we never ask your browser for it. Please do not put any of that into a QR code page either.

4. IP addresses and scan analytics

An IP address counts as personal information in Europe and several other places, so it is worth being specific rather than general.

We use the IP address at the moment of a scan to check the request is not automated and to apply rate limits. Approximate country and city are worked out at that same moment from information our network provider supplies with the request, not from anything we store afterwards.

We do not keep the IP address itself. Before a scan is written down, the IP address is converted into a one way hash using a secret key. The same IP address always produces the same hash, which is all a visitor count needs, but the hash cannot be turned back into an IP address and means nothing to anyone who does not hold the key.

We keep that hash for one purpose: estimating how many separate people scanned a code. We do not use it to identify individual people, we do not sell it, and we do not share it with advertisers. Because we hold the key, we treat the hash as personal information rather than claiming it is fully anonymous.

Estimated visitor counts are statistical figures based on technical signals such as IP address, device type and time of access. They are not a reliable way to identify a particular person, and are not intended to be. The business that owns a code sees totals, approximate regions and device categories. It does not see a scanner's name, email address or full IP address.

5. Why we use it, and what allows us to

Under European rules we need a legal basis for each use. These are ours.

What we doWhy we are allowed to
Run your account and your codesTo do what we agreed when you signed up (contract)
Serve your pages and count scansTo do what we agreed when you signed up (contract)
Pass on orders, feedback and booking requests from your pagesTo do what we agreed when you signed up (contract)
Take payment for a paid planTo do what we agreed (contract)
Send sign in codes and service emailsTo do what we agreed (contract)
Block bots, fraud and abuseOur legitimate interest in keeping the service working and safe
Keep invoices and tax recordsA legal duty we have
Send you marketing emailOnly if you said yes, and you can withdraw that at any time (consent)

We do not sell your personal information, and we never have. We do not share it with advertisers, and we do not use your content or your scan data to train AI models.

Automated decisions and profiling

We do not make automated decisions that have a legal or similarly significant effect on anyone, and we do not build profiles of the people who scan your codes. Automated systems are used for ordinary security work such as spotting suspicious traffic, and for nothing that affects a person's rights.

6. Where your information goes

We keep the number of outside companies small, and each one receives only what it needs to do its job. They are bound by contract to protect it and may not use it for their own purposes.

The kinds of companies involved are:

  • Our hosting provider, which runs the site, the database and uploaded images.
  • Our payment processor, which handles paid plans. Card details never reach our servers.
  • Our email provider, which sends sign in codes and service emails.
  • A sign in provider, but only if you choose to sign in with an existing account.
  • A bot protection service, which checks that sign ins and form submissions are coming from a person.

Ask us at privacy@mypersonalqr.com and we will tell you exactly who they are and what they hold.

Where a page you created forwards orders or feedback to an email address or webhook you configured, that destination is yours rather than ours. What happens to the message after we deliver it is under your control.

Countries

Our hosting runs on a global network, so information may be handled outside the country you live in, including in the United States.

Where information leaves the European Economic Area, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses, with the UK Addendum where the UK is involved, or on an adequacy decision when one covers the country. Ask us and we will tell you which applies.

Other times information may be shared

We disclose information if the law genuinely requires it, such as under a valid court order. Where we are permitted to tell you, we will.

If the business is ever sold or merged, your information may transfer with it. You would be told beforehand, and this policy continues to apply until it is replaced.

7. Business customers and data processing agreements

If you use MyPersonalQRfor a business and other people's details pass through your codes or pages, you are usually the controller for that information and we act for you. See our role when handling your information above for what the split means in practice.

If you need it in writing, ask at legal@mypersonalqr.com and we will send a data processing agreement. It covers:

  • That we act only on your instructions.
  • Confidentiality, and the security we keep in place.
  • The suppliers we use underneath, and how you hear about a new one.
  • Where information goes between countries, and on what legal basis.
  • The help you get when someone asks you for their data, or asks you to delete it.
  • What we do if there is a security incident, and when we tell you.
  • What happens to the information when you stop using us.

We can also send you the current list of suppliers that handle personal information on our behalf. Ask at the same address.

8. How long we keep it

WhatHow long
Your accountUntil you delete it. Removed from live systems within 30 days after that.
Your codes, pages and imagesUntil you delete it.
Scan historyAs long as the code exists. Delete the code and its scan history goes with it.
Menu orders and feedbackNot stored. Passed to the business and discarded once sent.
Property viewing requestsAs long as the code exists. Delete the code and the requests go with it.
Invoices and tax records7 years from the invoice date, because tax law requires it.
Server logs30 days.
Messages you send usWhile we deal with your message, and for a reasonable period afterwards in case you follow up.
BackupsBackups roll over on a 30 day cycle, so deleted data can persist in them for up to 30 days.

9. Your rights

We offer everyone the same rights, wherever you live. It is simpler for us and fairer to you than deciding what you get based on your address.

  • Ask what we hold about you, and receive a copy.
  • Have anything inaccurate corrected.
  • Have your information deleted.
  • Receive your data in a portable file.
  • Object to a particular use, or ask us to pause it.
  • Withdraw consent you previously gave, at any time.
  • Not be treated differently for asking. We will never charge you for it.

Write to privacy@mypersonalqr.com. We respond within 30 days. We may first need to confirm your identity, which protects your information from being disclosed to someone else.

Europe, the UK and Switzerland

These rights come from the GDPR, the UK GDPR and the Swiss FADP. If you believe we have handled something incorrectly, you can complain to your national data protection authority, or to the UK Information Commissioner's Office. You are welcome to raise it with us first, though you are not required to.

California

You can ask what we collect and why, request a copy, ask us to correct or delete it, and tell us not to sell or share it. We do not sell or share personal information as the CCPA and CPRA define those terms, and we have not done so in the past 12 months, including for anyone under 16. We do not offer anything in return for your data, so there is no financial incentive to disclose. You may use an authorised agent, and you may appeal if we decline a request.

Other US states

If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, or another state with its own privacy law, you have the same rights listed above, including the right to opt out of targeted advertising and profiling. We do neither. Nevada residents can tell us not to sell covered information, though we do not sell it in any case.

Everywhere else

If you are covered by Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act, India's DPDP Act, Japan's APPI, or a similar law elsewhere, the same list applies to you, at the same address. Users in India can treat our privacy contact as the grievance officer for DPDP purposes.

10. Deleting your account

You can close your account from your dashboard, or by writing to privacy@mypersonalqr.com.

Deleting removes your codes and the pages behind them, so any printed dynamic code will stop working. That is worth considering before you proceed. Static codes you have already downloaded continue to work, because they never depended on us. We retain invoices, because tax law requires it.

11. Cookies and things stored in your browser

There is little to report here. We use no advertising cookies and no cross site tracking.

Cookies

NameWhat it does
mpqr_sessionKeeps you signed in. Scripts in your browser cannot read it. The service cannot work without it, so it does not require consent.
Cloudflare TurnstileA short lived token that checks you are not a bot when you sign in or submit a form.

Stored in your browser, never sent to us

These are local storage entries rather than cookies. They stay on your device and are not transmitted with your requests.

NameWhat it does
mpqr_cookie_consentRemembers that you dismissed the cookie notice.
mpqr-builderHolds the code you are part way through creating, so refreshing the page does not lose it. It remains on your device until you save.
last_login_methodRemembers whether you last signed in with Google, LinkedIn or a password, so we can mark it for you next time. It holds the name of the method and nothing else.
google_oauth_pending, linkedin_oauth_pendingOnly there while a sign in with that provider is in progress. Holds a random value used to check the reply came back from the attempt you started, and the page to return you to. Cleared as soon as sign in finishes, and when you close the tab.

Do Not Track and Global Privacy Control

There is no agreed standard for Do Not Track, so like most sites we do not act on it. We do honour Global Privacy Control. Since we do not sell or share personal information in any case, sending the signal does not change how we treat you.

12. How we protect it

  • Everything travels over an encrypted connection.
  • Passwords are hashed, so nobody at our end can read them.
  • The sign in cookie cannot be read by scripts in your browser.
  • Access is limited to the people who need it in order to run the service.

No service can guarantee perfect security. If something goes wrong and your information is at risk, we will notify the relevant authority within 72 hours where the law requires it, and tell you directly when the risk to you is high.

13. Links to other places

A QR code can point anywhere, and our own pages link out too. Once you arrive on someone else's site you are covered by their privacy policy rather than this one, and we have no control over what they collect. That applies to a destination a customer chose for their own code as much as to a link in our footer.

14. Children

This service is not intended for children. Please do not sign up if you are under 16, or under 13 in the United States. If we find that we are holding a child's information, we delete it. If you believe a child has signed up, tell us at privacy@mypersonalqr.com.

15. Changes to this policy

When we change this page we update the date at the top. If a change materially affects you, we email account holders before it takes effect rather than revising the page without notice.

16. Contact us

For anything on this page, including a request about your data, write to privacy@mypersonalqr.com, or by post to [Registered address].

Business customers who need a signed data processing agreement can ask and we will provide one. See also our Terms of Service and Refund Policy.