Last updated: 23 September 2026
This Privacy Policy explains how FLIPR GROUP LTD handles personal data when you use iloveQR, visit our website, communicate with us, or interact with a QR code supported by our service.
FLIPR GROUP LTD is a private limited company registered in Cyprus under company number HE 443704, with registered address at 23 Ploutonos, 3096 Limassol, Cyprus, and VAT number CY 60184306Q.
For privacy questions or requests, use https://www.iloveqr.com/contact or write to our registered address.
FLIPR GROUP LTD is the controller for account administration, billing, product security, our own communications, and our website analytics and advertising activities.
A customer is normally the controller for personal data they choose to place in QR content or collect through a QR destination. For processing performed on that customer's instructions to provide the service, FLIPR GROUP LTD acts as processor.
We receive data directly from you, automatically from your device or QR scans, from the customer that created a QR experience, and from service providers such as Stripe, authentication providers, analytics services, and advertising platforms.
Customers decide what their QR codes link to and what information they collect. Their own privacy notice should explain that processing. If you scanned a customer's QR code and want to exercise rights over information controlled by that customer, contact the customer first; we will assist them where required by our processor obligations.
We disclose only what is reasonably necessary to:
Some providers may process data outside Cyprus or the European Economic Area. Where required, we use an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism and assess appropriate safeguards.
We keep personal data only for as long as needed for the purposes described here. Retention depends on account status, customer instructions, product configuration, security needs, limitation periods, and legal accounting, tax, or regulatory requirements.
Account and QR data are generally retained while the account is active and for a limited period afterwards to support recovery, disputes, and secure deletion. Backup copies are removed on a rolling schedule. Payment, invoice, and tax records are kept for the period required by law. Consent records and support communications are retained as needed to demonstrate choices and resolve issues.
Customers can delete QR content and account data using available controls, subject to backups, legal holds, and mandatory records.
Necessary technologies support authentication, security, language, and core functionality. Where required, analytics and advertising technologies remain disabled until you consent through Cookiebot. You can change or withdraw consent at any time through the cookie settings control.
We use organisational and technical measures designed to protect personal data, including access controls, encryption in transit, monitoring, backups, and restricted provider access. No online service can guarantee absolute security, and you should protect your credentials and report suspected misuse promptly.
Depending on applicable law, you may have the right to:
Submit a request through https://www.iloveqr.com/contact and identify the account or interaction concerned. We may request information needed to verify identity and protect other people. We normally respond within one month; the period may be extended where legally permitted for a complex or numerous request, and we will explain any extension.
iloveQR is not intended for people under 18 and we do not knowingly create accounts for children. If you believe a child has provided personal data, contact us so we can investigate and take appropriate action.
We do not use personal data to make solely automated decisions that produce legal or similarly significant effects for users. Automated fraud and security signals may flag activity for restriction or human review.
We may update this Policy when our service or legal obligations change. The date above identifies the current version, and we will give appropriate notice of material changes.
Please contact us first if you have a concern. You may also complain to the Office of the Commissioner for Personal Data Protection in Cyprus or the competent authority where you live or work.