Last updated July 26, 2026
Privacy Policy
What we collect, why, and how to get rid of it.
QRMapper is operated by Gnomon LLC ("we", "us"). This policy explains what we collect when you use the QRMapper website, the QRMapper iOS app and the short links we serve at qrmap.cc.
What we collect
Your account. Your name, email address and a hash of your password. If you sign in with Apple or Google, we store the identifier that provider gives us instead of a password. We never see your Apple or Google password.
Your content. The QR codes you create — their names, destinations, design settings and protection settings — and, if you publish one, the contents of your personal card.
Your subscription. If you subscribe on the web, Stripe processes the payment and we store the customer and subscription identifiers Stripe returns. If you subscribe in the iOS app, Apple processes the payment and we store the transaction identifiers Apple returns. We never receive or store your card number.
Scan data. When someone scans one of your QR codes, we record the time, the country and city reported by our CDN, and the device type, operating system and browser derived from the request. We also record where the scan came from, if the scanning app tells us.
What we do not store
We do not store the IP addresses of people who scan your codes. To tell repeat scans from new ones without keeping personal data, we combine the visitor's IP address, their browser identification, a secret key and a salt that changes every day, then hash the result and keep only the hash. The hash cannot be reversed to an IP address, and because the salt rotates daily, the same visitor produces a different hash tomorrow.
We do not use advertising identifiers, we do not run third-party ad or analytics trackers, and we do not track you across other companies' apps or websites.
Why we collect it
To run your account and keep you signed in; to redirect scans to the destination you set; to show you your scan statistics; to bill you and apply your plan's limits; and to send you transactional email — password resets, receipts and account notices. We do not send marketing email unless you ask us to.
Who we share it with
We share only what each service needs to do its job:
| Service | Purpose | What it receives |
|---|---|---|
| Railway | Hosting and database | All application data |
| Cloudflare | DNS, CDN, short links | Requests to our domains |
| Cloudflare R2 | File and image storage | Files you upload |
| Stripe | Payments on the web | Your email and billing details |
| Apple | Payments in the iOS app | Handled entirely by Apple |
| Resend | Transactional email | Your email address and message |
We do not sell your personal data, and we do not share it for advertising.
How long we keep it
Scan history is kept for as long as your plan's retention window — 7 days on Free, 30 days on Pro, 90 days on Business, 365 days on Enterprise. Older scan records are aggregated or removed. Everything else is kept while your account is open.
Deleting your data
You can delete your account at any time: in the app, open Manage → Delete account; on the web, Dashboard → Manage. Deleting your account removes your QR codes, their scan history and your personal card. Your QR codes stop resolving immediately — anything already printed will no longer work. We keep billing records where tax law requires it.
To ask what we hold about you, or to have it corrected or exported, email support@qrmapper.com from your account address.
Children
QRMapper is not directed at children under 13, and we do not knowingly collect their personal data.
Changes
If we change this policy in a way that affects you, we will update the date at the top of this page and notify account holders by email before the change takes effect.
Contact
Gnomon LLC — support@qrmapper.com