Privacy Policy
Last updated: July 21, 2026
QR Maker ("we", "us") takes your privacy seriously. This policy explains what data we collect, why, and your rights over it. It applies to all users globally and is designed to comply with the GDPR (EU), CCPA (California), and other applicable privacy laws.
Data controller: XANTICO CONSULTING SL (operating as QR Maker)
CIF: B26564195 · C/ Hermosilla 48, 1º Dcha., 28001 Madrid, Spain
1. What We Collect
Account data
Email address, name, and password (hashed) when you create an account. Collected to provide the Service and communicate with you.
Billing data
Payment is handled by Stripe. We store only your subscription status and plan tier — never your card number or banking details.
QR scan analytics
When someone scans your QR code we record: timestamp, approximate country (from IP, not stored), device type, and browser. We do not store the IP address of the scanner. This data is attributed to your account, not to the scanner.
Photo galleries (event hosts + guests)
When you create a photo gallery for a wedding or event, we store: gallery configuration, photos and short video clips uploaded by you or your guests, guest-uploaded email addresses if voluntarily provided, and shipping address if you purchase a printed Wedding Album. Photos and video files are stored on Supabase Storage in the EU region.
AI-derived features from photos
For printed albums we compute per-photo technical values on our own servers: a perceptual hash for near-duplicate grouping, image dimensions, and the EXIF capture time used to order the album. As of 22 August 2026 no photo is sent to any AI provider for this. See Section 4b.
Usage & logs
API requests, feature usage, and error logs for operating and improving the Service. Server logs are retained for 30 days.
Cookies & local storage
Essential cookies for authentication and session management. Analytics cookies only with your consent. See our Cookie Policy.
2. Legal Bases (GDPR)
- Contract: Account data and billing, to fulfil our subscription agreement.
- Legitimate interests: Usage logs, security, fraud prevention, and product improvement.
- Consent: Analytics cookies and marketing emails (opt-in only).
3. How We Use Your Data
- To provide and maintain the Service
- To process payments and manage your subscription
- To show you scan analytics dashboards
- To send transactional emails (password reset, invoices)
- To detect and prevent fraud and abuse
- To improve the Service based on aggregate usage patterns
We do not sell your data to third parties.
4. Third-Party Services (Subprocessors)
We share data with these processors to operate the Service. Each is contractually bound (Data Processing Agreements or equivalent terms) to use data only for the specified purpose and to maintain appropriate security.
- Supabase (EU region) — Postgres database + Storage for photos, videos, and generated PDFs.
- Stripe (global) — payment processing, checkout sessions, subscription management. Card details never touch our servers.
- Vercel (global) — web frontend hosting.
- DigitalOcean (EU region) — backend API hosting (Kubernetes).
- Bunny CDN (global) — CDN for public short-link redirects and gallery photo delivery. Cache TTL kept short (minutes to hours).
- Cloudflare — DNS only (grey-cloud / no proxying). We migrated away from CF proxying to Bunny CDN in mid-2026.
- OpenAI (US) — text only: AI chat assistant for landing-page authoring. Photos are no longer sent to OpenAI (removed 22 August 2026, see §4b). API zero-retention by default; inputs not used for training.
- Replicate (US) — hosted image models used only by the optional per-photo “AI Enhance” feature, which a host triggers explicitly on a photo they choose. No longer used for album building (removed 22 August 2026, see §4b).
- Gelato (Norway HQ, EU-US print centers) — physical fulfillment of Wedding Albums. Receives: shipping address, buyer name, buyer email, cover + interior PDF URLs.
- Resend (US) — transactional email delivery (order confirmations, magic links, notifications). Receives: recipient email + message content.
Transfers to US-based processors rely on Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework. A current subprocessor list is available on request at privacy@qr-maker.io.
4b. Photo Processing for Printed Albums
Updated 22 August 2026 — no photo is sent to any AI provider any more. Until this date, building a printed album sent each photo to OpenAI Vision and to Replicate for quality scoring and similarity embeddings. That pipeline has been removed. Nothing described below leaves our own infrastructure.
When a paid gallery host builds a printed album, each approved photo is processed on our own servers only:
- A perceptual hash is computed from the image so that near-identical photos (the same moment shot five times) can be grouped and offered as one choice.
- Width, height and the EXIF capture timestamp are read, so photos can be ordered by when they were actually taken and laid out at the right size for print.
- A check for letterboxing (black bands around screenshots of photos), so those bands are not faithfully printed.
These values are stored on our database and used to de-duplicate and order the album. There is no face detection, no quality or aesthetic scoring, no scene classification, no caption generation and no embedding of any kind.
Legal basis (GDPR): legitimate interests of the host (Art. 6(1)(f)). No special-category data is processed: without face detection the question of biometric data under Art. 9 does not arise.
Your rights: if you are a guest who does not want a photo you appear in to be used, email the host with a removal request, or contact privacy@qr-maker.io — we will remove specific photos or entire galleries on documented request. Deletion propagates: the photo is removed from our storage, and cached values are dropped.
5. Data Retention
- Account data: retained while your account is active, then 30 days after closure
- QR scan analytics: 2 years
- Billing records: 7 years (legal obligation)
- Server logs: 30 days
- Photo galleries (free tier): 7 days after gallery expiry
- Photo galleries (paid Memories tier): kept for the lifetime of your account or until you delete them
- Photo technical values (perceptual hash, dimensions, capture time): kept alongside the source photo — deleted when the photo is deleted. Legacy rows may still hold AI-derived features from before 22 August 2026; they are no longer produced or read.
- Wedding Album orders (physical): order + shipping details retained 7 years (accounting)
6. International Transfers
We are primarily based in the EU. Some processors operate in the US. Transfers from the EU to the US are covered by Standard Contractual Clauses (SCCs) and, where applicable, the EU-U.S. Data Privacy Framework.
7. Your Rights
Depending on your location, you may have the following rights:
EU/EEA (GDPR)
- Access — obtain a copy of your personal data
- Rectification — correct inaccurate data
- Erasure ("right to be forgotten")
- Restriction of processing
- Data portability
- Object to processing based on legitimate interests
- Withdraw consent at any time
- Lodge a complaint with your national supervisory authority
California (CCPA/CPRA)
- Know what personal information is collected and how it is used
- Delete your personal information
- Correct inaccurate information
- Opt out of sale/sharing (we do not sell data)
- Non-discrimination for exercising rights
To exercise any of these rights, email privacy@qr-maker.io. We will respond within 30 days.
8. Children's Privacy
The Service is not directed to children under 13. We do not knowingly collect data from children. If you believe a child has provided us data, contact privacy@qr-maker.io and we will delete it promptly.
9. Security
We use industry-standard measures including encryption in transit (TLS), encryption at rest, access controls, and regular security reviews. No system is perfectly secure — please use a strong, unique password and enable two-factor authentication where available.
10. Changes
We will notify you of material changes by email or by displaying a prominent notice on the Service before changes take effect.
11. Contact
Privacy questions or requests: privacy@qr-maker.io