Privacy Policy
Last updated: 8 Oct 2026
Trackable QR Codes logs a scan when someone opens one of our redirect URLs. For each scan we store the time, a country code taken from the IP the request arrived from, a device class (iPhone, Android, Tablet, Desktop, or Other), the operating system and browser families, a base language, and a code-scoped deduplication key. When a scan includes them, we also store a normalized external referrer host and short-link UTM values. We do not store the IP address itself, a full user-agent, a full referrer URL, city, latitude, longitude, or any precise location.
Country, Continent, and Region are estimated from the visitor's network metadata supplied by Cloudflare. They are not GPS or precise location data, and a Region may be missing or inaccurate. We do not collect or store city-level location, latitude, or longitude.
The deduplication key is a one-way salted hash derived from the IP address and the code it belongs to. It exists so that we can count unique and returning visitors without keeping anything that identifies a person, it is scoped to a single code, and it is deleted along with the code. We never write down the value it was derived from. Bots and link previews are not counted.
We do not sell, rent, or share scan data. Scan records are kept for as long as the code they belong to exists; deleting a code deletes its scan records with it.
This site runs on Cloudflare (Workers and D1), which hosts the service and stores the data on our behalf as a processor.
UTM values are supplied by the QR link creator. Do not put email addresses, phone numbers, names, or other personal information in UTM parameters. We trim and limit these values before storing them.
We use two kinds of cookie, both set HttpOnly, Secure, and SameSite=Lax. tq_session remembers which codes you created without an account, so they are still yours when you come back. If you sign in, a session cookie remembers that. There is no third-party tracking, advertising, or analytics cookie on this site.
Signing in uses Google OAuth. From that we receive your email address and display name, which we use to identify your account and nothing else. We never see your Google password.
Payments are processed by Stripe. We send Stripe your account email and billing identifiers, and Stripe may collect billing address, tax and payment details to process subscriptions. We store subscription and invoice identifiers, payment status and paid-access periods, not full card numbers or card security codes. Stripe acts under its own privacy and service terms for payment processing.
You can write to privacy@trackableqrcodes.com to ask what we hold on a code you created, or to have it deleted.