Privacy Policy
Last updated
Draft: company details marked in orange still need to be filled in before this page is final.
This explains what personal data BuildYourQR collects, from people with accounts and from people who scan codes, what we do with it, and the choices you have. We’ve tried to write it the way we’d want it explained to us.
01 Who we are
BuildYourQR is run by [legal company name: to be filled in], [registered address: to be filled in] (“we”, “us”). We’re responsible for the personal data described here. For anything to do with privacy, email hello@buildyourqr.com.
02 The short version
- We collect what we need to run your account and your codes, and to show you how your codes are used.
- When someone scans a code, we record the time, a rough location, and the kind of device. Scan statistics never include their IP address. (Like almost every website, our web server keeps short-lived access logs that do; see How long we keep it.)
- We don’t sell personal data, we don’t show ads, and we don’t use advertising or analytics cookies.
- Payments are handled by Polar. We never see your card number.
03 If you have an account
When you sign up and use BuildYourQR, we store:
- Account details: your name, email address and password. The password is stored only as a salted, one-way hash, never in plain text.
- What you create: your codes and their names, where they point, contact-card details (which can include a photo, phone numbers, email and postal addresses and social profiles), designs, your brand kit, and files you upload such as logos, photos, AR images, videos and 3D models.
- Plan and billing status: which plan you’re on, and the customer and subscription references Polar gives us, with the status and renewal date. We also keep the notifications Polar sends us about your subscription, which include your name and email, so we can show your plan correctly and fix problems.
- Security records: your login session is kept in a single cookie (see Cookies).
04 If you scan a code
QR codes made with BuildYourQR are created by our customers (a café, an estate agent, an event organiser). When you scan one, your phone opens a short link on our server, which forwards you to the page the customer chose. To give them scan statistics, we record:
- the date and time of the scan;
- a rough location (country and city) looked up from your IP address using an offline database on our own server. The IP address itself is not stored;
- the type of device, operating system and browser, taken from the information your browser sends with every request;
- the website that sent you, if any (only its domain name);
- a one-way hash made from your IP address and browser information, combined with a secret key, so repeat scans can be counted as one visitor. It can’t be turned back into your IP address.
Link-preview bots from chat apps and social networks are recognised and not counted. The customer who made the code sees these statistics as totals and charts. They don’t see anything that identifies you.
Web server logs. Separately from scan statistics, our web server writes an access log for every request (for anyone visiting our site, scanning a code or using the dashboard). Each line includes the IP address, time, requested address and browser information. We use these logs only to keep the service secure and fix problems.
AR codes open a viewer that uses your camera. The camera image is processed entirely on your phone to recognise the printed picture. No camera images are sent to us or stored.
Contact cards are public pages by design: anyone with the code can see the details the card’s owner chose to show. They’re marked so search engines don’t list them.
05 Why we use it (legal bases)
- To provide the service you signed up for (performance of a contract): your account, codes, uploads, plan and billing.
- Legitimate interests: producing scan statistics for the customers who made the codes, keeping the service secure, preventing abuse such as phishing links, and fixing problems. We keep this data minimal (no stored IP addresses) so it doesn’t override your rights.
- Legal obligations: keeping records we’re required to keep, for example for tax.
08 How long we keep it
- Account data and your content: for as long as your account is open. Delete a code and its scan history goes with it. Delete an AR ad and its uploaded files go too.
- Closing your account: email hello@buildyourqr.com from the address on the account. We delete your account, codes, uploads and scan history within 30 days, except records we must keep by law (such as billing records).
- Scan statistics: kept while the code they belong to exists, so you can see its history.
- Web server access logs (which include IP addresses): kept for a limited period for security and troubleshooting, then deleted automatically.
09 Your rights
Depending on where you live, you can ask to see the personal data we hold about you, correct it, delete it, receive a copy in a portable format, or object to or restrict how we use it. Email hello@buildyourqr.com and tell us what you’d like. We may need to check it’s really you first.
If you scanned a code, remember that we don’t store your IP address or anything that directly identifies you, so we usually can’t pick out your scans. We’ll still help if you contact us. You can also complain to your local data protection authority.
10 Security
Every page and short link is served over HTTPS. Passwords are hashed, login sessions are signed, the database account our app uses has only the permissions it needs, and payment details never touch our servers. No system is perfectly secure, but we work to protect your data and will tell affected users and authorities about a breach where the law requires it.
11 International transfers
Data is stored with our hosting provider (see Who we share it with). Polar may process data in other countries. Where data leaves your country, we rely on the safeguards the law provides for such transfers.
12 Children
BuildYourQR accounts are for people aged 16 and over. We don’t knowingly collect data from children. If you think a child has created an account, tell us and we’ll delete it.
13 Changes to this policy
If we change how we handle personal data, we’ll update this page and the date at the top. For significant changes we’ll also email account holders before they take effect. See also our Terms of Service.