Skip to content

Privacy policy

Last updated: September 27, 2026

Contents

Who is responsible for your data

The data controller is Hakili Labs, LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, United States, publisher of the QR Matrix service (qrmatrix.app). For any question about your data: support@qrmatrix.app.

We collect as little data as possible: what is needed to run your account, your codes and your subscription, nothing more. We sell no data and show no advertising.

Data we collect

If you use the generator without an account

Nothing. Static QR codes are generated in your browser: what you type is not sent to us.

If you create an account

  • Your email address and your language.
  • Your password, only in hashed form (we cannot read it). If you sign in with Google, the identifier of your Google account and the confirmation that your email is verified, instead of a password.
  • The date you accepted the terms, the account creation date and the date of your last visit (updated at most once an hour).
  • Where your sign-up came from, recorded once: campaign parameters of the landing address (utm_source, utm_medium, utm_campaign, utm_content, utm_term, gclid), the first page viewed and the domain name of the site that sent you to us.
  • Your codes: name, destination, design, logos you upload, folders.
  • Your sign-in sessions: a random identifier (stored in hashed form), its creation date and last activity date.
  • Your plan and the state of your subscription (interval, renewal date, scheduled cancellation), and the customer identifier assigned by Stripe. Your card details are processed by Stripe and never sent to us.
  • A record of the emails we send you (type of email, date), with the address stored in hashed form.

When someone scans one of your codes

Each scan is counted anonymously: date and time, approximate country, region and city, type of device (phone, tablet, computer) and system (iOS, Android…). The IP address is only used in memory, long enough to derive the country and city from a geolocation database installed on our servers, then it is forgotten: it is never stored, logged or transmitted. No cookie is set and no intermediate page is shown. Bots and link previews are not counted.

If you write to us

  • Contact form: your email, your name if you give it and your message, sent to us by email so we can answer.
  • Abuse report: the reported code, the reason, the details and, if you give it, your email address so we can keep you informed.

What we do not collect

No IP address, no device identifier or browser identification string (user agent), no tracking cookie, no advertising profile. We cannot know who scanned a code, nor count "unique visitors".

Why we use this data

  • Providing the service (account, codes, redirections, statistics, support): performance of the contract.
  • Charging the subscription, issuing invoices and meeting our accounting and tax obligations: performance of the contract and legal obligation.
  • Sending the emails related to your account (verification, security, billing, renewal reminder): performance of the contract.
  • Sending three getting-started emails in the days after sign-up, with a link to stop them: legitimate interest in helping you use the service.
  • Protecting the service and its users (rate limiting, destination checks, handling reports, log of administrative actions): legitimate interest.
  • Measuring, in aggregate, where our sign-ups come from and how the site is used: legitimate interest, without cookies and without individual tracking.

Providers and recipients

Your data is only accessible to our team and to the providers that help us run the service, each for its own task only:

  • Hostinger: hosting of the server that runs the website, the customer area, the redirection service, our email server and our audience measurement tool.
  • MongoDB Atlas (MongoDB, Inc.): database, hosted in a European Union region.
  • Stripe: payment, invoicing and tax calculation.
  • Google: sign-in with a Google account, if you choose it, and checking the destinations of codes (Google Web Risk receives the destination address, not your account data).

Scan geolocation uses a MaxMind database downloaded onto our servers: MaxMind receives no data. The site's audience measurement (Umami) and the email server are hosted by us; Umami works without cookies and does not store your IP address.

Transfers outside the European Union

Our data is hosted in the European Union. As Hakili Labs is established in the United States, and Stripe, Google and MongoDB, Inc. are US companies, some data may be accessed or processed from the United States. These transfers rely on the providers' certification under the EU–US Data Privacy Framework or on the standard contractual clauses adopted by the European Commission.

How long we keep data

  • Account and codes: as long as the account exists.
  • Account deletion (from the Settings page): your email, password, sessions, folders, logos and the subscription data we hold are erased immediately. Your codes are detached from the account and anonymised: they keep redirecting for 12 months, then show a "code removed" page.
  • Sign-in sessions: 30 days after the last activity.
  • Links sent by email: 24 hours to verify your address, 1 hour to reset your password.
  • Scan statistics: kept without time limit, as they are anonymous.
  • Invoices and payment data: at Stripe and with us, for the period required by law for accounting records.
  • Abuse reports: 12 months after they are handled. Log of administrative actions and record of emails sent: 12 months.
  • Messages sent through the contact form: in our support mailbox, 24 months at most.
  • Backups: 30 days, then overwritten.

Cookies

The site sets a single cookie, __Host-qr_session, and only when you are signed in: it keeps you signed in and does nothing else. During a Google sign-in, a second cookie, __Host-qr_oauth, checks for at most 10 minutes that the sign-in ends in the browser that started it, then it is deleted. These cookies are strictly necessary, which is why no consent banner is shown. No cookie is set on the redirection address of the codes. The payment page, hosted by Stripe, uses its own cookies, under Stripe's policy.

Security

Encrypted connections (HTTPS), passwords hashed with an attack-resistant algorithm (scrypt), session tokens and emailed links stored in hashed form, limited and logged administrative access, rate-limited sign-in attempts. No email address, IP address or token appears in our technical logs.

Your rights and contact

You can access your data, correct it, erase it, restrict its use, object to processing based on our legitimate interest and ask for a copy in a reusable format. Two of these rights can be exercised directly from your account: deleting the account and exporting your codes (Settings page).

For everything else, write to support@qrmatrix.app from your account email address, or use the contact form. We answer within one month. You can also lodge a complaint with the data protection authority of your country.

The service is for people aged 16 or over; we do not knowingly collect data about younger children.

Representative in the European Union

We have not appointed a representative in the European Union. For any question or request about your personal data, contact Hakili Labs, LLC directly, 131 Continental Dr, Suite 305, Newark, DE 19713, United States, support@qrmatrix.app.

Changes

We update this policy when the service or the law changes; the date of the last update is shown at the top of the page. If there is a significant change, we will tell you by email before it takes effect.