1. Data controller
The data controller for your personal data is RedQR. For any privacy-related enquiry you can write to us at hola@redqr.app.
2. What data we collect
We collect the data you provide when creating an account and using the service:
• Email and name (on sign-up) • Content of the QRs you create (destination URLs, internal names) • Scan analytics (date, time, device type) • Payment data (handled entirely by Stripe; we never store card details)
3. What we use your data for
We use your data to:
• Provide and maintain the service • Process payments and manage your subscription • Send transactional emails (account verification, password reset, receipts) • Improve the product using aggregated analytics
4. Third parties
To provide the service we share data with:
• Supabase (database hosting and authentication) • Stripe (payment processing) • Resend (transactional email) • Google (Sign in with Google, optional)
All of these providers are GDPR-compliant.
5. Data retention
We keep your personal data for as long as you maintain an active account. If you delete your account, all your personal data, QRs and analytics are permanently deleted within 30 days.
6. Your rights
If you are in the European Economic Area, you have the right to:
• Access your personal data • Rectify inaccurate data • Request its deletion • Object to its processing or request portability
To exercise these rights, write to hola@redqr.app.
7. Security
We apply reasonable technical and organisational measures to protect your data: HTTPS, encryption at rest in the database, authentication managed by a specialised provider (Supabase) and tokenised payments via Stripe.
8. Changes to this policy
If we modify this policy we will notify you by email at least 30 days before the changes take effect.