Data Retention and Privacy
Learn how iloveQR handles, stores, and protects your data.
Data Collection
What We Collect:
- Account information (email, name)
- QR code content and settings
- Scan analytics (anonymized)
- Device and location data (aggregate)
- Payment information (via Stripe)
What We Don't Collect:
- Actual content scanned
- Personal identifiable information of scanners
- Passwords (hashed only)
- Unnecessary tracking data
Scan Data
Anonymized Collection:
- IP addresses (hashed)
- Device fingerprints (anonymized)
- Location (city-level only)
- Browser type
- Timestamp
NOT Collected:
- Scanner names
- Email addresses
- Phone numbers
- Personal content
Data Storage
Location:
- Primary: US data centers
- Backup: EU data centers
- Encrypted at rest and in transit
Security:
- AES-256 encryption
- TLS 1.3 for transmission
- Regular security audits
- SOC 2 compliance (Enterprise)
Data Retention Periods
Active Accounts:
- QR code data: Indefinite while active
- Scan analytics: 2 years rolling
- Account info: While account active
Cancelled Accounts:
- Grace period: 90 days
- Then permanently deleted
- Download backup before cancellation
GDPR Compliance:
- Right to access data
- Right to delete data
- Right to port data
- Contact privacy@iloveqr.com
User Rights
Access Your Data: Go to Settings > Privacy > Download Data
Delete Your Data: Settings > Account > Delete Account
Port Your Data: Export QR codes and analytics anytime
Object to Processing: Contact privacy team
Third-Party Services
Payment Processing:
- Stripe (PCI-DSS compliant)
- No card data stored on our servers
Email Delivery:
- SendGrid/Resend
- Only email addresses shared
- Unsubscribe anytime
Analytics:
- Anonymized data only
- Opt-out available
- GDPR compliant
Scanner Privacy
QR Code Scans:
- Minimal data collection
- No accounts required
- Anonymized analytics
- Opt-out via Do Not Track
Location Data:
- IP-based only
- City-level accuracy
- Not sold or shared
- Used for analytics only
Data Sharing
We Never:
- Sell your data
- Share with advertisers
- Give access to third parties
- Use for purposes not disclosed
We May Share:
- With your consent
- Legal requirements
- Service providers (processors)
- Business transfers (with notice)
Children's Privacy
COPPA Compliance:
- Not intended for under 13
- No knowing collection of children's data
- Parents can request deletion
International Users
GDPR (EU):
- Full compliance
- Data Protection Officer appointed
- EU representative designated
CCPA (California):
- California residents' rights honored
- Do Not Sell option
- Disclosure requirements met
Other Jurisdictions:
- Following local laws
- Adapting to new regulations
Security Measures
Technical:
- Encryption everywhere
- Secure authentication
- Regular penetration testing
- Vulnerability scanning
Organizational:
- Employee training
- Access controls
- Incident response plan
- Regular audits
Data Breach Protocol
In Event of Breach:
- Immediate investigation
- Contain and remediate
- Notify affected users within 72 hours
- Report to authorities as required
- Prevent future occurrences
Your Responsibilities
Keep Secure:
- Use strong passwords
- Enable 2FA
- Don't share credentials
- Log out on shared devices
QR Code Content:
- Don't include sensitive data
- Use password protection when needed
- Review before publishing
Transparency
Regular Updates:
- Privacy policy reviewed annually
- Users notified of changes
- Opt-in for material changes
Reports:
- Transparency reports published
- Security audits disclosed
- Compliance certifications listed
Contact Privacy Team
Questions or Concerns:
- Email: privacy@iloveqr.com
- Response within 48 hours
- Dedicated team
- Escalation process
Settings and Controls
Privacy Dashboard:
- Settings > Privacy
- Control data sharing
- Manage cookies
- Download your data
- Delete account