Legal information

Privacy Policy

Effective date: August 17, 2026

This Privacy Policy explains what data may be processed when using the qrwize.com website and the QRwize mobile application for Android, why it is used, how it is stored, who it may be shared with, and what rights users have.

This Policy applies to the QRwize website, the online static QR code generator, the QRwize mobile application, QR code and barcode creation and scanning features, the contact form, the waitlist form, and other QRwize features through which users may provide or process data.

1. Who is responsible for data processing

The website and mobile application are operated, and personal data is controlled, by Sole Proprietor Shvets Vadym Yuriiovych.

For privacy questions, access to data, correction, restriction of processing, or deletion, contact:

Email: info@qrwize.com

In this Policy, the terms “QRwize”, “we”, “us”, and “our” refer to the operator of the QRwize website and mobile application.

2. What data we process

The amount of data processed depends on how a user interacts with the website or mobile application.

2.1. Data entered into the QR code generator

The generator can work with links, text, contact details, Wi-Fi settings, events, phone numbers, email addresses, social profiles, payment details, and other information that a user chooses to encode.

All data entered into the generator is processed locally in the user's browser.

QRwize:

  • does not send the contents of generator fields to the server;
  • does not store entered data in its own database;
  • does not receive a copy of the created QR code;
  • does not receive or store a copy of the generated QR code image;
  • does not use generator data for analytics, advertising, or profiling.

Creating, previewing, and downloading a QR code in supported formats also takes place directly in the browser.

This means QRwize does not receive URLs, Wi-Fi passwords, contact details, IBANs, cryptocurrency addresses, or other information entered into the generator unless the user separately provides it through the contact form or another communication channel.

2.2. Mobile application data

The QRwize mobile application allows users to create and scan QR codes and supported barcode types.

Data entered by a user to create a QR code is processed locally on the user's device.

Scan results, saved records, notes, favorites, and application settings may be stored locally on the user's device.

QRwize does not send the contents of created QR codes or local scan history to its own server for storage.

Local data may be deleted by the user through application features, by clearing application data in Android, or by uninstalling the application.

2.3. Camera and scanning

To scan QR codes and barcodes, the mobile application may request access to the device camera.

Camera images are used to recognize codes. QRwize does not transmit the camera video stream to its own servers and does not store it in its own infrastructure.

The user can revoke camera permission in Android settings.

If the user selects an image from the device for code recognition, the selected image is used for this operation on the device and is not transmitted to QRwize servers.

2.4. Website theme settings

If the user manually changes the website's light or dark theme, the selected value is stored in the browser's localStorage.

This value:

  • is used only to display the selected theme;
  • is not sent to the server;
  • does not contain identifying or contact information;
  • is not used to track the user.

If the user does not change the theme, the corresponding value is not stored.

sessionStorage is not used to store user data. The website language is determined by the URL of the page being viewed and is not stored separately in the browser.

2.5. Waitlist data

When a user joins the waitlist, we store:

  • email address;
  • IP address;
  • browser type and version;
  • operating system and other user-agent data;
  • browser language;
  • approximate country and city;
  • approximate coordinates;
  • time zone;
  • date and time the form was submitted.

Country, city, coordinates, and time zone are estimated based on the IP address and technical headers provided by the network infrastructure. QRwize does not request the device's GPS location.

Email addresses are used only to:

  • notify users about the launch of QRwize Pro;
  • invite users to early access.

We do not use the waitlist to send third-party advertising and do not provide email addresses to other companies for their own marketing.

Joining the waitlist does not require additional email confirmation through a separate message.

To unsubscribe from notifications or request removal of an email address from the list, contact info@qrwize.com.

2.6. Contact form data

When the contact form is submitted, we receive and store:

  • name;
  • email address;
  • subject of the inquiry;
  • message text;
  • IP address;
  • user-agent;
  • browser language;
  • approximate geolocation;
  • date and time of submission.

This data is used to:

  • receive and review the inquiry;
  • respond to the user;
  • resolve technical or organizational issues;
  • protect the form from spam and abuse;
  • perform technical diagnostics.

Inquiry data is stored in QRwize's own database. A copy of the inquiry is also sent to the email system we use to process messages.

Copies of messages in the email system may be stored until manually deleted. A user may request deletion of an inquiry by writing to info@qrwize.com.

Do not send the following through the contact form:

  • passwords;
  • private keys;
  • verification codes;
  • full payment card details;
  • documents that are not required to review the inquiry;
  • other confidential information unrelated to the inquiry.

2.7. Technical data and logs

When pages are opened or requests are submitted, the server and network infrastructure may automatically process:

  • IP address;
  • page or request URL;
  • date and time;
  • HTTP method;
  • response status;
  • user-agent;
  • referrer URL;
  • URL parameters;
  • technical request data;
  • error message;
  • stack trace;
  • other information required to diagnose a problem.

In some cases, logs may contain request parameters or the HTTP request body if this is necessary to diagnose an error. We do not use logs for advertising or to create marketing profiles.

Logs in the application's file system are stored for up to 90 days. Only the QRwize operator has access to them.

2.8. Technical error monitoring

A specialized monitoring provider is used to detect and fix technical errors.

When an error occurs, such a provider may receive:

  • error message;
  • stack trace;
  • page URL;
  • IP address;
  • user-agent;
  • a sequence of technical events preceding the error;
  • request parameters;
  • technical context;
  • form data or an email address if it accidentally appears in the error context.

Monitoring data is stored for up to 90 days in the European Union region.

We recommend not submitting through forms any information that is not required for the relevant feature or for reviewing the inquiry.

2.9. Analytics data

QRwize uses third-party web analytics and website interaction analysis services.

They may automatically process:

  • pages visited;
  • date and time of the visit;
  • approximate region;
  • device type;
  • browser and operating system;
  • referral source;
  • visit duration;
  • interaction with page elements;
  • technical identifiers;
  • IP address or a derived value;
  • website performance parameters.

Form field masking is configured in one of the interaction analysis services. This reduces the risk that a name, email address, inquiry subject, or message text is included in interaction recordings.

On the QRwize website, we do not use advertising pixels, remarketing systems, or trackers to show personalized advertising. The mobile application may use Google Mobile Ads as described separately in this Policy.

As of the effective date of this Policy, analytics technologies may be activated when the website is opened. Users can limit their operation through browser settings, third-party cookie blocking, or specialized privacy protection tools.

The retention period for analytics data depends on the settings and policies of the relevant providers.

2.10. Purchase and subscription data

One-time purchases and subscriptions through Google Play may be available in the QRwize mobile application.

Payments are processed by Google Play. QRwize does not receive or store full payment card details.

The application may receive technical information from Google Play that is necessary to determine the status of a purchase or subscription and provide purchased features.

Payment methods, subscriptions, and purchase history are managed through Google Play.

QR codes for IBAN, EPC, UPI, or cryptocurrency addresses only contain details entered by the user. QRwize does not process such payments.

2.11. Advertising in the mobile application

The QRwize mobile application may display advertising using Google Mobile Ads (AdMob).

When Google's advertising SDK operates, Google may process technical device data and advertising interaction data, including an IP address, advertising or other technical identifiers, device information, and diagnostic data.

Such data is processed by Google in accordance with Google's privacy rules and the user's settings.

The contents of created QR codes and local scan history are not provided to Google Mobile Ads for advertising purposes.

3. How data is used

Depending on how a user interacts with the website or mobile application, data may be used for:

  • operation of the website and its technical features;
  • operation of the mobile application;
  • creating QR codes in the browser;
  • creating and scanning QR codes and barcodes in the mobile application;
  • local storage of application history, records, and settings;
  • determining the status of purchases and subscriptions;
  • providing features available after a purchase;
  • displaying advertising in the mobile application;
  • processing user inquiries;
  • maintaining the waitlist;
  • sending launch and early-access notifications;
  • protecting against spam, attacks, and abuse;
  • diagnosing and fixing errors;
  • analyzing website stability and usage;
  • understanding the audience's general geographic distribution;
  • complying with legal requirements;
  • protecting QRwize's rights and legitimate interests.

IP addresses, approximate geolocation, language, time zone, and user-agent information obtained through forms are not used to personalize emails or advertising or to create individual user profiles.

4. Legal bases for processing

Depending on the circumstances, we may process data on the following legal bases:

User consent

Consent is used for:

  • adding an email address to the waitlist;
  • sending launch and early-access notifications;
  • processing data submitted through the contact form;
  • other operations for which the user provides separate consent.

The user may withdraw consent by contacting info@qrwize.com.

Fulfilling a user request

Data may be processed to receive, review, and fulfill a request that the user has submitted through the contact form or by email.

Legitimate interest

A limited amount of technical data may be processed to:

  • ensure stable operation of the website and mobile application;
  • protect against abuse;
  • diagnose errors;
  • protect infrastructure;
  • understand general patterns of website usage.

Legal obligation

We may retain or disclose data when required by applicable law, a court decision, or a lawful request from an authorized authority.

5. Cookies and local storage

The QRwize website uses technically necessary cookies and browser local storage. The mobile application uses device local storage for certain features.

Technically necessary cookies

Name Purpose Retention period
XSRF-TOKEN Protects forms and requests from CSRF attacks 3 days
qrwize-site-session Technical operation of the website and forms 3 days

These cookies are not used for authentication, advertising profiling, or tracking users across different devices.

Local storage

If the user changes the website theme, the selection is stored in localStorage. Other generator data is not stored in localStorage.

Mobile application local storage

The mobile application may store settings, scan history, saved records, and other data required for local features on the user's device.

This data is stored in the Android application's local storage and is not a website cookie.

It may be deleted through application features, by clearing application data in Android, or by uninstalling the application.

Contact form protection

The contact form uses a third-party mechanism to protect against automated spam and bots. The provider of this mechanism may process technical information about the device, browser, network connection, and interaction with the page. This mechanism is used only on the contact form page.

Analytics technologies

Third-party analytics services may use cookies, local storage, or other technical identifiers. As of the effective date of this Policy, they may load when the website is opened.

Users can restrict or delete cookies in their browser settings. Blocking technically necessary cookies may affect the operation of forms or other website features.

6. Who data may be shared with

We do not sell, rent, or provide personal data to third parties for their own advertising or independent marketing purposes.

The following categories of providers may be used to operate the website and mobile application:

  • cloud hosting and database providers;
  • CDN and network infrastructure providers;
  • email service providers;
  • error monitoring providers;
  • form protection, bot prevention, and anti-spam providers;
  • web analytics providers;
  • providers of technical audits of public website pages;
  • advertising service providers;
  • the application store operator and purchase processing system.

Such providers may receive only the data necessary to perform the relevant technical function.

Google Mobile Ads (AdMob) may be used to display advertising in the mobile application, while Google Play may be used to distribute the application and handle purchases and subscriptions.

Data may also be disclosed to public authorities when required by law, a court decision, or a lawful request from an authorized authority.

7. Data location and international processing

The website's primary infrastructure and QRwize's own database are located in the European Union region. Error monitoring data is also stored in the European Union region. Data processed by third-party mobile application services may be processed in other regions according to the infrastructure and policies of the relevant providers.

Some third-party providers operate in multiple countries. Depending on their corporate and technical structure, certain data processing operations may take place outside the user's country or the European Economic Area.

Where international data transfers are subject to specific legal requirements, appropriate legal, contractual, and organizational safeguards should apply.

8. Data retention

We retain data no longer than necessary for the purpose for which it was collected, unless a longer retention period is required by law.

Category Retention period
QR code generator data Not transmitted to the server and not stored by QRwize
Local scan history and saved mobile application data Until deleted by the user, application data is cleared, or the application is uninstalled
Mobile application settings Until changed or deleted by the user, application data is cleared, or the application is uninstalled
Advertising service data According to the policies and settings of the relevant provider
Purchase and subscription data According to Google Play policies and for the period necessary to verify access to purchased features
Selected website theme Until the user deletes the relevant localStorage data
Technically necessary cookies 3 days
Application logs Up to 90 days
Error monitoring data Up to 90 days
Copies of inquiries in the email system Until manually deleted or until a verified user deletion request is received
Analytics data According to provider settings and policies

No exact calendar retention period is set for waitlist email addresses and inquiries stored in our own database. Such data is retained until the purpose of processing has been fulfilled, consent has been withdrawn, a verified deletion request has been received, or the relevant communication is no longer needed.

Data may be retained longer if required by law or if necessary to defend against a legitimate legal claim. Following a verified request, user data is deleted from QRwize's own database and email system where it is stored, unless there is a lawful basis for continued retention.

9. Data security

QRwize applies reasonable technical and organizational measures to protect data against:

  • unauthorized access;
  • unlawful use;
  • alteration;
  • disclosure;
  • loss;
  • accidental or intentional deletion.

Only the QRwize operator has access to QRwize's own database and server logs.

For security reasons, we do not publish detailed descriptions of internal architecture, server configurations, backups, or access control mechanisms.

No method of storing or transmitting data can guarantee absolute security.

10. Other people's data in QR codes

A user may create a QR code that contains contact details or other data relating to another person.

Because the website generator operates locally in the browser and the corresponding mobile application features operate locally on the device, QRwize does not receive this data. The user remains responsible for ensuring that its use and disclosure are lawful.

Users should not create or publish QR codes containing the following without an appropriate legal basis:

  • private contact information;
  • confidential financial details;
  • medical information;
  • documents or identifiers;
  • other personal data whose disclosure may violate a person's rights.

11. User rights

Depending on applicable law, a user may have the right to:

  • receive information about the processing of their data;
  • access their data;
  • correct inaccurate or incomplete data;
  • request deletion of data;
  • request restriction of processing;
  • object to certain types of processing;
  • withdraw previously given consent;
  • receive a copy of their data in a portable format where this right applies;
  • lodge a complaint with a competent data protection authority;
  • seek judicial or other remedies provided by law.

To exercise your rights, write to info@qrwize.com.

The request should include enough information for us to locate the relevant data and verify that the request is made by the appropriate person.

We will not request more information than is reasonably necessary to verify and fulfill the request.

12. Automated decisions and profiling

QRwize does not use personal data for automated decision-making that produces legal or similarly significant effects for the user.

QRwize does not create its own advertising or behavioral user profiles. Third-party advertising services used by the mobile application may process data in accordance with their own policies and user settings.

13. Children's data

QRwize is not specifically directed at children and does not knowingly request personal data from children.

If a parent or legal representative believes that a child has provided us with personal data without appropriate authorization, they may contact info@qrwize.com.

After reviewing the request, we will take appropriate measures regarding such data.

14. Links to third-party resources

QRwize may contain links to third-party websites, social networks, messaging services, payment services, and other resources.

QR codes created by users may also lead to third-party resources.

We do not control the data processing practices of such websites. Before providing personal information, we recommend reviewing their privacy policies.

15. Changes to this Policy

We may update this Policy if there are changes to:

  • QRwize features;
  • data processing practices;
  • categories of connected providers;
  • retention periods;
  • applicable legal requirements.

The current version is published on this page with the date of the latest update.

If changes materially affect the processing of data already collected, we will provide appropriate notice and, where required, obtain new consent.

16. Contact

For questions about this Policy, personal data processing, or exercising your rights, contact:

QRwize
Email: info@qrwize.com

Last updated: August 17, 2026