Privacy Policy
Last updated: July 24, 2026
[bracketed] placeholders, confirm the data practices and subprocessors match this app, and have counsel review before launch. This is not legal advice.Review note
This policy describes how the Service works today and is provided for transparency. It is not legal advice; the operating legal entity and postal address should be confirmed and this document reviewed by counsel before it is relied upon.
1. Who we are
The QR Gate (“we,” “us”) is a QR-code generator that lets you create, host, and track QR codes at www.theqrgate.com. This policy explains what we collect, why, and your choices. Contact us at info@tryhalfstack.com.
2. Account data
- Your email and a password, which is hashed by our authentication provider (Supabase) — we never see or store your plaintext password.
- If you sign in with Google, your name and avatar as provided by Google.
- Your display name, if you set one in Settings.
3. QR content you create
The destinations, text, links, business details, contact cards, and files you put into your QR codes are “Customer Data.” For hosted QR codes, that content is served publicly at a hard-to-guess URL (www.theqrgate.com/q/…) so anyone who scans the code can see it — treat hosted content as public. Draft and unpublished content is private to your account (enforced by row-level security). You control and are responsible for this content.
WiFi passwords entered for a WiFi QR are never written to our database or logs — they exist only in memory in your browser while you build the code, and are removed from any saved draft.
4. Uploaded files
Files you upload (PDFs, images, audio, video, logos) are stored in Supabase Storage. Drafts live in a private bucket accessible only to your account; when you publish a hosted QR, the relevant files are copied to a public bucket so the hosted page can display them.
5. Scan analytics (privacy-preserving)
When someone opens a tracked QR (www.theqrgate.com/q/… or a tracked redirect www.theqrgate.com/r/…), we record a scan event with coarse, non-identifying signals:
- approximate country / region / city (from network-edge geolocation headers);
- device type, browser, and operating system (derived from the user-agent);
- the referring website’s host, if any; and
- a one-way visitor hash for approximate unique counts.
We do not store raw IP addresses for scans. The visitor hash is a salted, one-way hash of (IP + user-agent + day) that is used only to estimate unique visitors within a day and cannot be reversed back to an IP. We exclude bots, link-preview crawlers, page prefetches, and a QR owner’s own previews from human counts. Native QR types (WiFi, direct contact cards) are not tracked at all because scanning them never contacts our servers.
Signed-in users also generate a lightweight “last seen” presence record (an opaque per-tab identifier and a coarse area such as “Dashboard”), used to show an approximate “online now” count to administrators. It contains no IP address and no session token.
6. Billing data
Subscriptions are processed by Stripe. Stripe collects and stores your card details; we do not. We store your subscription status and Stripe customer/subscription identifiers so we can provide the plan you pay for. Free accounts require no payment information.
7. Cookies & product analytics
We use essential cookies to keep you signed in and operate the Service, and privacy-friendly product analytics (Vercel Analytics / Speed Insights) to understand aggregate usage and performance. We do not use advertising cookies.
8. How we use information
- Provide, secure, and operate the Service and your QR codes;
- Show you analytics for your own QR codes;
- Process payments and manage subscriptions;
- Respond to support and send service-related notices;
- Detect and prevent abuse, and comply with law.
9. Service providers
We don’t sell your personal data. We share it only with providers that help run the Service:
- Supabase — database, authentication, and file storage;
- Stripe — payment processing;
- Resend — transactional email (when configured);
- Vercel — hosting, edge geolocation, and analytics.
10. Retention & deletion
We keep account and QR data while your account is active. You can archive or delete individual QR codes at any time. To delete your account and associated data, contact info@tryhalfstack.com; we will remove or anonymize your personal data within a reasonable period except where we must retain records for legal, tax, or security reasons. Aggregate, de-identified analytics may be retained.
11. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Manage much of your data in your account settings, or contact info@tryhalfstack.com.
12. Children
The Service isn’t directed to children under 16, and we don’t knowingly collect their data.
13. Changes
We may update this policy; material changes will be notified in-app or by email, and the “last updated” date above will change.
14. Contact
Questions or requests: info@tryhalfstack.com. The QR Gate is a Halfstack product.