What this covers
This policy describes data processed when you use qrcodes.sh, create a workspace, print codes, or scan a dynamic code we host. Static codes generated in the browser are created on your device; we do not receive that payload unless you save it to a workspace.
We do not sell your data
We do not sell personal information. We do not run social posting, ad retargeting pixels, or share scan lists with brokers.
Account and workspace data
If you sign up we store email, authentication records, workspace membership, QR destinations and design settings you save, credit ledger entries, and billing identifiers from our payment provider. You can export redirect maps from Settings (never-dies escrow).
Scan analytics (no visitor IPs stored)
For dynamic codes we record scan time, country/region/city from CDN geo headers, coarse device/OS/browser from the user agent, and outcome (redirect, paused, limit, and similar). Unique-scan estimates use a daily rotating hash derived from IP + user agent; the raw IP is not written to scan analytics. Truncated user-agent strings may be stored for debugging. IP addresses may be used ephemerally for rate limiting abuse, then discarded.
Processors we actually use
These are the subprocessors wired in this codebase — not a generic SaaS list:
- Vercel — application hosting, cron jobs, custom domains, request geo headers.
- Supabase — authentication, Postgres, file storage, row-level security.
- Lemon Squeezy — subscriptions and credit top-ups (checkout and webhooks). We do not use Stripe in this product.
- Cloudflare Turnstile — optional bot protection on public forms and capture endpoints.
- Resend — optional transactional email (health alerts, workflow notices, dunning) when a key is configured.
Google OAuth may be offered through Supabase Auth if that provider is enabled on the project.
Cookies and local data
We use cookies required for login sessions. Password-protected codes set a short unlock cookie on the scanner's browser after a successful check. Free generators keep work in the browser until you save to a workspace.
Retention and your rights
Workspace data is kept while the workspace exists and as needed for billing, security, and legal holds. Email hello@binarychakra.com to request access, correction, or deletion. We may retain records required for fraud prevention, tax, or dispute handling.
Controller
TODO: legal entity name, registered address, and data-protection jurisdiction. Operating contact: Binary Chakra, Madurai, India — hello@binarychakra.com. Do not invent a company number.