Privacy Policy

Last updated: February 1, 2026

QRMax ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our platform and services.

1. Information We Collect

We collect information you provide directly (name, email, company), information from your use of the Service (QR codes created, scan events with IP addresses, device types, and locations), payment information (processed by Stripe — we do not store card details), and analytics data from cookies and similar technologies.

2. How We Use Your Information

We use your information to: provide and improve the Service; send transactional emails (receipts, password resets); send product updates (with your consent); detect and prevent fraud; comply with legal obligations; and aggregate anonymized usage statistics for product development.

3. Data Sharing

We do not sell your personal data. We share data with: service providers (Stripe for payments, AWS for hosting, SendGrid for email) under data processing agreements; analytics partners (anonymized only); and when required by law or to protect our rights.

4. QR Code Scan Data

When someone scans your QR code, we collect their approximate location (country/city from IP), device type, OS, browser, and scan timestamp. IP addresses are stored for 90 days then masked to city-level. This data is shown in your analytics dashboard.

5. GDPR Rights

If you are in the European Economic Area (EEA), you have the right to: access your personal data; correct inaccurate data; erase your data ("right to be forgotten"); restrict processing; data portability; and object to processing. Exercise these rights by emailing privacy@qrmax.io or using the data export feature in Settings.

6. Data Retention

We retain your account data for as long as your account is active plus 30 days after deletion. Scan analytics data is retained for 2 years. Billing records are retained for 7 years as required by law. You can request earlier deletion of personal data subject to legal requirements.

7. Cookies

We use essential cookies (required for the Service to function), analytics cookies (to understand usage patterns — you can opt out), and preference cookies (to remember your settings). We do not use advertising/tracking cookies.

8. Security

We protect your data using: TLS 1.3 encryption in transit; AES-256 encryption at rest; SOC 2 Type II certified infrastructure; regular security audits; and access controls with principle of least privilege. No method of transmission is 100% secure, but we implement industry best practices.

9. Children's Privacy

QRMax is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe we have collected information from a child, please contact us immediately.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a prominent notice in the Service 30 days before the changes take effect.

Questions? Email privacy@qrmax.io · DPO: dpo@qrmax.io