Privacy notice

1. Scope and summary

QR Yours is operated by VOVOS PANTRY trading as QR YOURS, a South African private company, registration 2026/404842/07. QR Yours is being prepared for international public use by individuals and businesses, including hosted PDF uploads at launch.

This notice explains how QR Yours handles information when you use the public website, create a static QR code, hold an account, manage dynamic QR codes, host PDFs, connect a domain, subscribe, ask for help or report abuse. New hosted-PDF uploads and replacements are currently unavailable; the PDF descriptions below apply only when that feature is enabled. It does not cover the privacy practices of destinations opened by a QR code.

We are responsible for our account administration, billing records, support and service security. Customers decide what their QR codes link to and why they measure usage. Where we handle their content or reporting on their instructions, we act as their operator or processor. Our own processing remains our responsibility. Customers must provide the notices and lawful permissions their use requires; this notice does not replace theirs.

2. Static QR codes

For static QR codes, the information you enter is not stored by us. The browser creates the QR image locally. QR Yours does not receive the link, text, Wi-Fi password or contact details entered in the static generator. The finished image is downloaded directly to your device. This describes the generator content, not all website traffic: loading the page still uses hosting and, when configured, authentication services. Anyone with the finished image may read its encoded content.

3. Website visits and cookies

Hosting infrastructure processes ordinary request information such as IP address, user-agent, requested URL, time and security signals to deliver the site and defend it from misuse. When account authentication is enabled, Clerk can use session cookies or similar browser storage to keep a user signed in. Turnstile can process browser and network signals when protecting support and abuse forms and enabled hosted-PDF uploads. QR Yours does not include advertising cookies in its application code. The production scan privacy-choice page stores a QR-specific allow/deny preference in a secure session cookie only after a choice; it is not a visitor identifier. The generator keeps its working content in browser memory, not application local storage. Payment checkout, when opened, also uses Paddle’s browser services. Provider cookies, storage and request logs are separate from our scan database; their own applicable notices describe those separate activities.

4. Account and dynamic QR information

Dynamic QR codes require us to store the destination so redirects can work. Optional scan analytics is separate and redirects work without it. Account records can include an authentication identity, email supplied through the authentication provider, plan and subscription state, QR names, immutable slugs, current and previous destinations, style settings and an audit history of important changes. Historical availability-monitoring settings and results may remain in existing accounts and exports; availability monitoring is not offered at launch. Enabled hosted-PDF processing stores document bytes, user-supplied document names, integrity hashes and validation/scan status. Custom-domain records contain the hostname, account-bound ownership proof and connection history.

5. Scan Privacy

Optional scan reporting is collected only when enabled and the scanner separately allows optional analytics for that QR. A QR link works without that choice. Reports include eligible, consented URL opens, not all traffic or proof of a camera scan. Known bots and previews are filtered. Analytics v1 records approximate country, region/province and city from Cloudflare, broad device, OS and browser families, UTC time and QR/placement association. Network geolocation may reflect an ISP or VPN, not a scanner’s neighbourhood. Placement labels describe where a business distributed material, not where an individual lives. IP addresses and user agents are processed transiently. Analytics v1 does not retain raw IPs, full user agents, headers, referrers, GPS, postal codes or coordinates. It sets no cross-site identifiers; the separate preference cookie records the QR-specific choice. Estimated daily unique scanners use a server-keyed HMAC of a truncated network prefix, broad device/browser class, QR and UTC day. The derived identifiers change daily and do not link scans across days or QRs. The server secret does not itself rotate daily. This is an estimate, not a count of identifiable people. The same daily identifier remains in retained observations until those observations are removed; a change of day does not erase them or make them anonymous.

Approximate locations and pseudonymous identifiers are treated as personal information under POPIA. Demographic groups need at least 5 valid scans; smaller groups show “Other / Not enough data”. Customer exports contain no event rows or pseudonymous keys. Overall counts and QR rankings can include fewer than five scans. No street-level maps or external analytics scripts are used in this scan path. Hosting providers can process request logs separately. Older analytics records may include referrer domains and identifiers calculated differently from Analytics v1.

Suggested printed disclosure

This QR works without optional analytics. If you allow it, QR Yours processes approximate area, device information and a pseudonymous daily identifier for this QR owner's reports. Add /privacy to this QR's link to choose or withdraw. Learn more at qryours.com/privacy#scan-privacy. The destination website has its own privacy notice.

Customers should place an appropriate notice beside their printed QR code or wherever they share the link, identifying themselves and their reporting purpose. A redirect does not display this notice before it opens. On production links, add /privacy to the QR URL to allow or decline optional analytics, or change an earlier choice. No choice means no optional collection; declining does not block the QR or PDF. Do Not Track and Global Privacy Control signals stop optional collection. The session preference applies to that QR on that website, not other QR codes or websites. Contact team@qryours.com to exercise your rights without an account; we may not be able to identify a particular past scan. Withdrawal stops future optional collection and does not itself identify or erase earlier observations.

6. Billing, support and safety records

When billing is enabled, including private Sandbox testing, QR Yours stores provider customer and subscription identifiers, plan state and webhook records. Payment card details are handled by Paddle and are not stored by QR Yours. Support requests and abuse reports can include contact details, the reported QR link, the report category, evidence, review notes and the action taken. Do not send passwords or unnecessary identity documents.

Support form submissions send your name, email address, subject and message to our Google Workspace support mailbox. The application keeps delivery receipts and, while an acknowledgement is pending, an encrypted reply address; it does not keep the support message body in its database. Google Web Risk receives the full managed destination URL, including query parameters and fragments, for reputation checks. Do not put passwords or confidential information in those URLs. Browser-only static QR content is not submitted for these checks.

7. Why information is used

Information is used to provide accounts and redirects, show analytics, enforce plan limits, process subscriptions, check managed destinations for known threats, prevent fraud and abuse, answer requests, maintain security and comply with legal duties. Depending on applicable law, account administration and requested support can be necessary for a contract or steps you request before it; security and abuse prevention can serve legitimate interests; and specified accounting or disclosure duties can require legal compliance. Customer-directed analytics needs its own purpose and lawful basis, including consideration of scanners’ interests and objections. A scanner is not assumed to have a contract with us. Our optional production collector requires a separate affirmative choice. Security measures use only information proportionate to their purpose; we consider less intrusive alternatives and objections. Reading or accepting this notice is not consent to optional analytics.

8. Service providers and transfers

The implementation can use Cloudflare for hosting, storage and edge processing; Clerk for authentication; Paddle as Merchant of Record; Google Web Risk for destination reputation checks; Google Workspace for support and operational email; and Turnstile for support, abuse and enabled upload protection. Hosted PDFs use a private Cloudflare-hosted structural validator and, when enabled, AWS S3 and GuardDuty for quarantine and malware scanning. Enabled PDF processing uses Northern Virginia, USA. A provider is used when its configured credentials and feature are enabled. These providers may process information in countries other than yours under their own safeguards and terms. Paddle also determines its own payment, tax and fraud-processing purposes. A provider’s published terms do not by themselves establish which agreement or transfer safeguard applies to our account; we must establish the relevant safeguard before restricted processing. Cloudflare's Western Europe placement hints are not EU-only guarantees: edge, support and onward processing are international. Workspace has no selected data-region restriction and no Clerk region restriction is promised. Where required, protections include binding processor agreements, POPIA section 72 conditions and applicable EU/UK transfer instruments and supplementary measures. Request details or a copy of relevant safeguards, subject to necessary redactions, from team@qryours.com. Service acceptance is not blanket transfer consent.

9. Retention

Static generator content is not retained. Analytics v1 deduplication tokens expire at the UTC day boundary and are removed by hourly maintenance. Compact observations default to 90 days, limited to 30 on Free; operators may configure a shorter period. Their daily pseudonymous keys remain for the same period. Daily/hourly totals are scheduled for removal after 365 days. Cleanup runs in bounded batches and may require retries. The plan’s visible reporting window is not a deletion deadline. Monthly usage counters and lifetime totals have no age-based expiry in the current implementation. Legacy analytics used separate salted tokens lasting up to 36 hours. Account, destination and audit records are kept while needed to operate the account. Billing, security and abuse records may be kept longer where required for fraud prevention, accounting, disputes or law. Detailed scan observations outside Analytics v1 are retained for 30 days. Application support and email delivery receipts are removed by scheduled maintenance after 30 days; this is not a promise about mailbox or provider backup retention. Account deletion pauses account access and Dynamic redirects immediately. You have exactly 14 days from the recorded UTC request time to cancel by signing in again. After that deadline, permanent erasure starts automatically; incomplete provider cleanup is retried and is not reported as complete. Minimum genuine financial records remain for seven years, extended only by a relevant unresolved legal hold. A minimal deletion/security audit expires after 90 days. Provider recovery copies and operator-held backups have separate schedules. The approved launch policy is 30 days for ordinary backups; new complete, unheld recovery copies follow that policy. Previously inventoried recovery and evidence copies are restricted and reviewed separately for controlled disposal; they have not all been deleted. This is not a blanket 30-day promise for financial records or holds. Backups are not used for ordinary processing, and completed deletions must be reapplied before a restored database is used.

Archiving a QR code does not erase its destination history. General audit history, abuse records and expired safety-cache records do not all have automatic age-based deletion. Their monthly manual review removes material no longer needed. Routine support messages and closed abuse evidence are ordinarily removed 12 months after closure. A minimum record supporting a continuing safety block is reviewed at least annually. Minimum rights-request and complaint decision records are kept for three years after closure; identity documents are removed once verification and any genuine challenge are complete. Relevant active-account history and monthly/lifetime totals remain with the account and are subject to account cleanup. Holds are specific, documented and reviewed at least every 90 days. These manual rules are not automatic mailbox or database purges. Seven-year financial retention is an implemented policy, not a claim that every field has the same statutory period. The minimum separate deletion ledger is kept while a recoverable copy could otherwise resurrect deleted data.

10. Your choices and rights

You can avoid account data by using only the static generator. Account users can edit or disable dynamic codes and download their personal-data JSON in Account settings. Self-service deletion becomes available once its database migration, provider cleanup and scheduled reconciliation are enabled. During the recovery period you may only cancel deletion, export your data or sign out. Cancellation restores the same Dynamic links and historical data; after the deadline QR Yours cannot recover the account. Browser-only Static codes are unaffected. Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy, withdraw consent, and complain to a data-protection authority. Identity verification may be required before a request is completed.

You do not need an account to make a privacy request. Email team@qryours.com with “Privacy request” or “Privacy complaint” and describe what you need. We may ask for proportionate evidence of identity or authority; do not send an identity document unless needed. Account exports and the 14-day account recovery option do not replace statutory rights or deadlines. We will explain any lawful limitation and the applicable complaint route. Withdrawing consent does not undo processing that was lawful before withdrawal.

Regional rights

In South Africa, POPIA provides rights including confirmation, access, correction and, where its conditions are met, deletion and objection. You can complain to the Information Regulator; its PAIA Guide and forms explain formal record-access requests. Our PAIA manual is available at www.qryours.com/paia on publication.

Where EU/EEA or UK data-protection law applies to our processing, its access, correction, erasure, restriction, objection, portability and complaint rights apply subject to their conditions. Applicable US state laws may provide access, correction, deletion and specified opt-out or appeal rights. If the Australian Privacy Act applies, its access, correction and complaint provisions apply. These laws do not all apply simply because a website is accessible in a country. Our planned international offering requires the applicable representatives, local notices and request mechanisms to be in place before the relevant processing begins. Contact the Information Officer for the arrangements applicable to your request. This notice does not claim an exemption from those requirements.

11. Security, children and changes

QR Yours uses access controls, destination validation, salted hashing and provider security controls, but no online service can guarantee absolute security. We do not ask scanners for their age. Customer destinations or documents can contain information about children or sensitive matters; that information is not automatically anonymous or permitted. Account holders must have legal capacity or act through a responsible authorized adult or organization. Customers must establish the specific legal permissions and safeguards for identifiable children's or sensitive information; a general permission to use this service is insufficient. Material changes to this notice will be dated and, where required, communicated in the product.

12. Contact

For support, privacy, access requests and complaints, contact VOVOS PANTRY at team@qryours.com or use our email contact. Address privacy and PAIA requests to the Information Officer, Michael Toaney Russell. This is a human contact route, not a promise of an automatic acknowledgement.