Privacy Policy

Last updated: October 3, 2026

This Privacy Policy explains how ALTERNO Agency ("we", "us") collects, uses and shares personal data through QR Code + Pages ("QRP"). It covers two groups: customers who create accounts, and people who scan QR codes or visit pages hosted on QRP.

1. Data we collect from customers

Account data: name, email address, password (stored hashed), sign-in provider identifiers, workspace and role.

Content: QR codes, destinations, designs, folders, business-card details and files you upload.

Billing data: plan, invoices and payment status. Card details are handled directly by our payment provider; we do not store full card numbers.

Early-access and contact forms: name, email, company, business type, message and language.

Usage data: log-ins, actions in the dashboard and technical logs used for security and support.

2. Data we collect when someone scans a QR code

For dynamic codes and hosted pages we record: date and time, approximate location (country, region, city) derived from the IP address, device type, operating system, browser, language and referring app when available.

We do not use GPS, do not ask scanners to sign in and do not build advertising profiles of scanners. IP addresses are used to derive location and to detect bots and abuse; analytics shown to customers are aggregated and do not include full IP addresses.

Static QR codes contain their content directly and do not pass through our servers, so we collect nothing when they are scanned.

3. How we use data

To provide and secure the Service; to show scan analytics to the code owner; to process payments; to send transactional emails (verification, password reset, invitations, receipts); to provide support; to detect fraud and abuse; to comply with law; and, with your consent where required, to send product updates you can unsubscribe from at any time.

4. Legal bases

Where laws such as the GDPR apply, we rely on performance of a contract (operating your account), legitimate interests (security, analytics for code owners, service improvement), consent (optional marketing) and legal obligation.

5. Roles

For customer account data we are the controller. For scan data collected on behalf of a customer's QR codes, the customer decides why the code is used and we process that data on their behalf to provide analytics.

6. Sharing

We do not sell personal data. We share it only with service providers that help us run QRP (cloud hosting and database, payment processing, email delivery, sign-in providers such as Google), under contracts that limit their use of the data; with members of your workspace as you configure; and when required by law or to protect rights and safety.

7. Cookies and local storage

We use essential cookies and browser storage to keep you signed in, remember your language and workspace, and secure the Service. We do not use third-party advertising cookies. Public hosted pages do not set tracking cookies.

8. Retention

Account data and content are kept while your account is active and deleted within a reasonable period after closure, except where we must retain records (for example invoices) by law. Scan data is kept for the life of the code or as defined by your plan, and may be retained in aggregated, non-identifying form.

9. Security

We use encryption in transit, hashed passwords, workspace-level access controls that keep each customer's data isolated, private file storage with short-lived access links, and restricted administrative access. No system is perfectly secure; please use a strong, unique password.

10. Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, object to or restrict processing, and withdraw consent. California residents have rights under the CCPA/CPRA, including to know and delete; we do not sell or share personal information for cross-context advertising.

Customers can edit most data in the dashboard. For other requests, or if you scanned a code and want to exercise your rights, contact us; we may refer requests about a specific code to its owner.

11. International transfers

We are based in Puerto Rico (United States) and our providers may process data in the United States and other countries, using appropriate safeguards where required.

12. Children

The Service is not directed to children under 13, and we do not knowingly collect their personal data from accounts. Customers must not use QRP to collect children's data unlawfully.

13. Changes

We may update this policy. We will post the new version with an updated date and notify account owners of material changes.

14. Contact

Privacy questions or requests: legal@qrcodepages.com. ALTERNO Agency, Puerto Rico.

Terms of Service →