Privacy Policy
Last updated: 1 October 2026
This policy explains how BITSTREAKS TECHNOLOGIES PVT LTD ("we", "us"), which operates QR For Life, handles personal data.
Summary
- We collect what we need to run editable QR codes and show you scan statistics.
- People who scan your codes: we never store their IP address and never set cookies on them.
- We do not sell personal data.
1. Data about people who scan a code
When someone scans an editable code, our server briefly sees their IP address and browser information in order to redirect them. We keep only:
- the time of the scan;
- approximate location (country, region, city) derived from the IP address, where available;
- device type, operating system and browser family;
- an anonymous visitor hash that changes every day, used only to count unique scans. It cannot be reversed to an IP address.
Raw scan records are kept for 13 months, after which only daily totals are kept. Codes generated on our free static generator pages are created in your browser and are not sent to us.
2. Data about our customers
- Account details: name, email, password (hashed), Google account ID if you sign in with Google.
- Your content: code names, destinations, designs, logos, folders and tags.
- Payments are handled by Paddle.com, our reseller and merchant of record, which collects your billing details and address to take payment and calculate tax. We never see or store card numbers. We keep a record of each payment (amount, date, Paddle reference) and your subscription status.
- Technical logs for security and troubleshooting.
3. How we use it, and why
To provide the service, keep it secure (including checking destinations with Google Web Risk to prevent phishing), provide support, send service emails, and — only if you opt in — weekly summaries.
Where EU or UK data protection law applies, we rely on: performance of our contract with you (running your account and plan); our legitimate interests (security, preventing fraud and abuse, and providing scan statistics to code owners); legal obligations (for example keeping billing records); and your consent (optional emails such as weekly summaries, which you can switch off at any time).
4. Service providers
We use these providers to run the service. They process data only on our instructions or, for Paddle, as merchant of record for your purchase:
- Hostinger (hosting, network and database)
- Paddle.com (payments, invoicing and tax, as merchant of record)
- Our email delivery provider (account and service emails)
- Google (Web Risk URL checks; Google sign-in if you use it)
- Sentry (error monitoring)
5. Cookies
The dashboard uses essential cookies for login sessions and security. We do not use analytics or advertising cookies, and we set no cookies on people who scan codes.
6. Your rights
Depending on where you live (for example GDPR, UK GDPR, CCPA/CPRA, the Australian Privacy Act, India's DPDP Act), you can ask to access, correct, export or delete your data, or object to how we use it. Email info@bitstreaks.com. You can export your codes yourself from the dashboard at any time. You may also complain to your local data protection authority.
7. International transfers and retention
Our providers may process data in countries other than yours. Where we transfer personal data from the EU or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
We keep account data while your account is open and delete it within 30 days after you close it, except records we must keep by law (such as billing records for tax purposes).
Contact
BITSTREAKS TECHNOLOGIES PVT LTD · info@bitstreaks.com. A data processing agreement (DPA) for business customers is available on request.