QRCommand
PlatformGrowth systemsPricingSign inStart building

Legal policies

Privacy Policy

How QR Command handles account, workspace, and scan information.

legalPages.controls.effectiveDateLabel August 14, 2026.

legalPages.controls.sections

  1. Data categories
  2. How we use information
  3. Service providers and processors
  4. Scan analytics and session data
  5. Security and retention
  6. User choices and rights
  7. Children's privacy
  8. International processing
  9. Policy changes
  10. Contact
  11. Governing law

Data categories

We process account data, workspace metadata, campaign records, destinations, scan events, and support/administrative records.

  • Account and authentication details: email, secure authentication credentials handled by Supabase Auth.
  • Workspace and business profile: workspace names, locations, roles, invites, and plan state.
  • Campaign data: campaign names, short links, destination URLs, QR configuration, status, and edit history.
  • Scan and analytics signals: scan time, destination, browser/user-agent signals, referrer data where available, and approximate location.
  • Device and platform context used for security and reliability monitoring.
  • Subscriptions: customer identifiers and billing status from Stripe.
  • Team and collaboration: invites, roles, audit trails, and approvals.
  • Integrations and webhook metadata: encrypted secrets and endpoint status.
  • AI usage: prompts, outputs, drafts, recommendations, and approval outcomes where AI features are used.

How we use information

  • Authenticate and secure access to your workspace.
  • Deliver QR generation, redirection, scans, and dashboard analytics.
  • Run role-based controls, plan enforcement, and entitlement checks.
  • Deliver support, security monitoring, abuse detection, and incident response.
  • Provide optional AI insights from your workspace data and record recommendation history.

Service providers and processors

We use these providers only for platform operation:

  • Supabase for database storage and authentication.
  • Stripe for payment collection and subscription management.
  • Vercel for application hosting.
  • OpenAI for AI recommendation generation where enabled.

Scan analytics and session data

Scan events are used for operational analytics and campaign reporting. We process IP-derived information to support anti-abuse and regional reporting and do not falsely claim that raw IP addresses are always stored permanently; where hashed values are present, they are used for anti-abuse and security context.

Device, browser, and referrer indicators may be stored when available and relevant to scan analysis.

Security and retention

We use role-based access controls, audit logging, and server-side key handling.

Retention follows operational needs and legal requirements; paid account and workspace records are retained while a workspace exists and may remain in backup or compliance systems for a defined period.

User choices and rights

Contact support to request access summaries, account data corrections, or deletion requests. Some records may remain where required by legal or operational policy.

You can review and manage workspace users, connected integrations, destinations, and consent at any time.

Children's privacy

QR Command is not directed to children under 13.

International processing

Data may be processed in the United States and through cross-border infrastructure for reliable platform delivery. By using the service you consent to this processing model.

Policy changes

This policy may be updated when processing or legal needs change. Updated versions are published on this page and become effective on the date listed.

Contact

Questions or concerns about privacy practices: stogepit115@gmail.com.

Governing law

Florida law applies, and disputes are subject to the legal framework of the United States of America.

The English version of these policies is the controlling legal version. Any translation is provided for convenience. legalPages.controls.viewEnglish