1. Information we collect

When you register for and use account-based features, we may process your name, email address, hashed password, session information, plan status and the QR code content you choose to create.

When a dynamic QR code is scanned, we may record the access time, browser or device identifiers, and referring page. We may also irreversibly hash IP addresses for analytics, abuse prevention and usage-limit calculations. We do not store plaintext IP addresses in scan records.

2. Uploaded files

File QR codes allow PDFs or images you upload to be downloaded by anyone who has the link or QR code. These links should be treated as publicly accessible links. Do not upload identity documents, financial records, medical information, passwords, secret keys or other content that should not be publicly distributed.

We may store the file name, type, size, upload time and owning account, and may process related logs for security, capacity management and troubleshooting.

3. Payments and plans

Paid plans are one-time purchases and do not automatically renew. Payments are processed by Creem as Merchant of Record. CraftMyQR does not store full payment card numbers or card security codes, but we may retain identifiers needed to fulfill purchases, including Creem customer and order references, plan status and plan expiration dates.

4. How we use information

  • Provide sign-in, QR code generation, redirects, file downloads, analytics and team features.
  • Manage plans, usage limits, billing status and customer support.
  • Prevent brute-force login attempts, spam registrations, malicious uploads, artificial scan traffic and API abuse.
  • Monitor service reliability, troubleshoot errors and improve the product.

5. Retention and deletion

Scan analytics are retained according to the history period associated with your plan. Expired sessions are cleared, while subscription and transaction records may be retained longer when needed for accounting, dispute resolution or legal compliance. Deleting a file QR code removes its service metadata and source file, although cached, backup or log copies may require a reasonable period to be fully cleared.

Signed-in users can verify their email address, manage recovery options and delete their account in Account settings. Account deletion removes dynamic QR codes, hosted files and workspace data associated with the account, subject to backup cycles and records that payment providers or applicable law may require us to retain. You may also contact us with a data request.

6. Cookies and security

We use HTTP-only session cookies to maintain authenticated sessions. We use measures such as password hashing, session protections, request rate limiting, file-type validation and Creem webhook signature verification. No internet-based service can guarantee absolute security.

7. Changes to this policy

We may update this Privacy Policy when our product capabilities, infrastructure or legal requirements change. We will provide reasonable notice of material changes through the service or another appropriate channel.