Legal policies
Privacy Policy
How QR Command handles account, workspace, and scan information.
Data categories
We process account data, workspace metadata, campaign records, destinations, scan events, and support/administrative records.
- Account and authentication details: email, secure authentication credentials handled by Supabase Auth.
- Workspace and business profile: workspace names, locations, roles, invites, and plan state.
- Campaign data: campaign names, short links, destination URLs, QR configuration, status, and edit history.
- Scan and analytics signals: scan time, destination, browser/user-agent signals, referrer data where available, and approximate location.
- Device and platform context used for security and reliability monitoring.
- Subscriptions: customer identifiers and billing status from Stripe.
- Team and collaboration: invites, roles, audit trails, and approvals.
- Integrations and webhook metadata: encrypted secrets and endpoint status.
- AI usage: prompts, outputs, drafts, recommendations, and approval outcomes where AI features are used.
How we use information
- Authenticate and secure access to your workspace.
- Deliver QR generation, redirection, scans, and dashboard analytics.
- Run role-based controls, plan enforcement, and entitlement checks.
- Deliver support, security monitoring, abuse detection, and incident response.
- Provide optional AI insights from your workspace data and record recommendation history.
Service providers and processors
We use these providers only for platform operation:
- Supabase for database storage and authentication.
- Stripe for payment collection and subscription management.
- Vercel for application hosting.
- OpenAI for AI recommendation generation where enabled.
Scan analytics and session data
Scan events are used for operational analytics and campaign reporting. We process IP-derived information to support anti-abuse and regional reporting and do not falsely claim that raw IP addresses are always stored permanently; where hashed values are present, they are used for anti-abuse and security context.
Device, browser, and referrer indicators may be stored when available and relevant to scan analysis.
Security and retention
We use role-based access controls, audit logging, and server-side key handling.
Retention follows operational needs and legal requirements; paid account and workspace records are retained while a workspace exists and may remain in backup or compliance systems for a defined period.
User choices and rights
Contact support to request access summaries, account data corrections, or deletion requests. Some records may remain where required by legal or operational policy.
You can review and manage workspace users, connected integrations, destinations, and consent at any time.
Children's privacy
QR Command is not directed to children under 13.
International processing
Data may be processed in the United States and through cross-border infrastructure for reliable platform delivery. By using the service you consent to this processing model.
Policy changes
This policy may be updated when processing or legal needs change. Updated versions are published on this page and become effective on the date listed.
Contact
Questions or concerns about privacy practices: stogepit115@gmail.com.
Governing law
Florida law applies, and disputes are subject to the legal framework of the United States of America.
The English version of these policies is the controlling legal version. Any translation is provided for convenience. legalPages.controls.viewEnglish