This English version is provided for convenience. In case of any discrepancy, the Spanish version prevails.
1. Controller
The data controller is Juan José Camacho, registered at 04005, Almería, Spain. Privacy contact: support@qr-branding.com.
2. Data we collect
The minimum needed to deliver the Service and meet our legal obligations:
- Account: email (used for receipts, refund link and affiliate payouts).
- Billing: handled entirely by our Merchant of Record — we receive a customer id and the order amount + currency. We never see card data.
- Usage: per-request metadata (timestamp, endpoint, credit balance delta, IP for rate-limiting, country code for currency detection).
- QR content: the text or URL you encode. Stored only for the duration of the request unless you explicitly save it in the builder; in that case it's stored in your account's history.
- AI prompts: kept for 30 days as a SHA-256 hash for the idempotency cache; the plaintext prompt is discarded after the request.
- Cookieless analytics: we measure aggregate traffic (page views, country, device and browser type, load times) with Cloudflare Web Analytics. It uses no cookies or persistent identifiers, does not store your IP and does not follow you across sites.
- First-party usage events: in our own database we record the key product steps: the landing visit and where it came from (a campaign tag or the referring domain, never the full URL), opening the editor, exporting a design (and its format), generating a design with AI, creating an account, starting and completing a purchase, refunds, and installing or opening the app. Each event stores the platform (desktop web, mobile web or installed app), the language, your IP pseudonymised with a secret key and, if you are signed in, your customer id. It contains neither your QR content nor the text of your prompts, and uses no cookies.
- Cookies:
NEXT_LOCALE,NEXT_CURRENCY,NEXT_COUNTRY(preferences),qr_ref(affiliate attribution, 90 days). No advertising or analytics cookies. - Local storage:
qrb_install_dismissedremembers for 30 days that you closed the install-the-app notice. It is never sent to our servers.
3. Legal bases
- Performance of contract — account + billing + usage data necessary to deliver the credits you paid for.
- Legal obligation — tax records (kept 5 years by our Merchant of Record).
- Legitimate interest — abuse prevention (IP, rate-limit counters).
- Legitimate interest — aggregate measurement of the audience and the product funnel to improve the service (cookieless analytics and first-party usage events).
4. Categories of processors
We rely on a small set of specialist processors. Each is bound by a written DPA and acts only on documented instructions. The categories below describe what each recipient does; the full named list of sub-processors (with legal entity and region) is published at /subprocessors and updated whenever a sub-processor changes.
- Our Merchant of Record (EU-registered payments provider) — billing, invoices, refunds.
- Our transactional email provider — delivery of receipts and account emails.
- Our CDN + edge runtime provider — frontend hosting, asset CDN and cookieless aggregate web analytics.
- Our managed Postgres database provider (USA region) — orders + credits ledger.
- Our managed cache + rate-limit counter provider — caching, rate limits, webhook idempotency.
- Our serverless function host (EU region) — backend API + rendering engine.
- Third-party LLM providers — only invoked when you explicitly opt in to AI generation; the specific provider used per request is logged for cost reconciliation. Only the prompt + parameters are transmitted; no email or billing data.
5. International transfers
Some processors are based in the United States. Transfers from the EEA/UK rely on the EU-US Data Privacy Framework or the EU Standard Contractual Clauses, as applicable. Copies of the relevant SCCs are available on request at support@qr-branding.com.
6. Retention
- Account email: as long as your account is active + 90 days.
- Orders, receipts and credits ledger: 5 years (tax obligation).
- Usage logs (IP, endpoint, timestamps): 30 days.
- AI prompt cache key: 30 days. Original prompt text: not retained beyond the request.
- First-party usage events: 13 months. When you close your account they are unlinked from it; the anonymous counts remain. Before deleting them we add them up into anonymous daily totals (number of events per day, platform and source, with no customer identifier or IP), which we keep indefinitely for statistical purposes.
7. Your rights
Under GDPR / UK GDPR / similar laws you may request access, rectification, deletion, portability, restriction and objection. Email support@qr-branding.com with the email associated to your account — we respond within 30 days. You may also lodge a complaint with the Agencia Española de Protección de Datos (AEPD).
8. Security
All traffic is HTTPS-only. Database connections are TLS. Secrets are stored as encrypted environment variables managed by our hosting providers. Backups are encrypted at rest. We disclose material data incidents within 72 hours of detection per our incident response procedure.
9. Children
The Service is not intended for users under 16. We do not knowingly collect data from children. Contact us if you believe we have.
10. Changes
Material changes are announced 30 days in advance via the email on file. The "Updated" date at the top of this page reflects the last change.