Draft — not legal advice. This document is a starting template and must be reviewed by a qualified lawyer before launch. Bracketed items like [Company name] must be completed.
Privacy Policy
Last updated: October 5, 2026
This policy explains what personal data [Company legal name] ("we") processes when you use CtrlShiftQR, and when people scan QR codes or open short links created with it.
1. Data about account holders
- Account: name, email, password (stored only as a bcrypt hash), plan, email verification status.
- Content: QR code and link names, destinations, static QR contents (e.g. Wi-Fi or contact details you enter), styling and uploaded logos.
- Billing: handled by Stripe. We store your Stripe customer and subscription IDs and status — never card numbers.
- API keys: stored only as a SHA-256 hash.
2. Data about people who scan or click
For each scan or click we record a minimal, non-identifying event:
- time, which QR code or link was used;
- device class (mobile/tablet/desktop), browser name, operating system name;
- country (derived from the IP address by our hosting provider; the IP itself is not stored);
- referring website's domain only (not the full URL).
We do not store IP addresses or full user-agent strings for scans, and we don't set cookies on visitors who are redirected. IP addresses are processed transiently for rate limiting and abuse prevention; abuse reports store a keyed hash of the reporter's IP to prevent duplicate reports.
3. Why we process data (legal bases)
- To provide the Service you signed up for (contract).
- To keep the Service safe — screening destinations, rate limiting, handling abuse reports (legitimate interests).
- To provide scan analytics to link owners (legitimate interests; aggregate, non-identifying data).
- To send service emails such as verification and password reset (contract).
- To comply with tax and accounting obligations (legal obligation).
4. Processors we use
- Vercel (hosting, edge geolocation), Neon (PostgreSQL database), Upstash (Redis cache and rate limiting)
- Stripe (payments), Resend (email delivery), Sentry (error monitoring, if enabled)
- Google Web Risk / Safe Browsing (destination URLs are sent to Google to check for phishing and malware)
[List data-processing locations and transfer mechanisms, e.g. SCCs, after confirming each provider's region.]
5. Retention
- Account and content data: while your account exists; deleted when you delete the account or the item.
- Scan events: deleted with the QR code or link they belong to. [Define a maximum retention period.]
- Abuse reports: [24 months] for safety and legal purposes.
- Billing records: as required by tax law (typically [7–10] years, held by Stripe).
6. Your rights
Depending on where you live (e.g. GDPR, UK GDPR, CCPA), you may have rights to access, correct, delete, export or object to processing of your data. Contact [privacy@yourdomain.com]. You may also complain to your local data protection authority.
7. Cookies
We only use cookies that are strictly necessary to sign you in and keep the service secure. See the Cookie Notice.
8. Security
Data is encrypted in transit (HTTPS/HSTS). Passwords, API keys and one-time tokens are hashed. Access to production systems is restricted. [Describe incident response and breach notification commitments.]
9. Contact
[Company legal name], [address]. Email: [privacy@yourdomain.com]. [EU/UK representative, DPO if required.]