Privacy Policy

Last updated 14 August 2026 · easy-qr-code.com

Who we are

Mayst Impact DOOEL, a company registered in the Republic of North Macedonia, operates easy-qr-code.com and is the data controller for the personal data described in this Policy. That means Mayst Impact DOOEL decides what is collected and why, and is the party legally answerable for it.

  • Controller: Mayst Impact DOOEL
  • Address: Vladimir Komarov 25/4-16, Skopje, North Macedonia
  • Email: [email protected]
  • Tax number: 4032020546119

1. Introduction

This Privacy Policy explains what personal data we collect when you use easy-qr-code.com, why we collect it, who we share it with, and how long we keep it.

It covers two different groups of people: account holders, who register with us to create QR codes, and people who scan a QR code made with our service, who have no account and no relationship with us. Section 3 is written for the second group.

2. Information We Collect

a) Information you provide

When you register for an account, we collect:

  • Name (first and/or last)
  • Email address
  • Password, stored only as a cryptographic hash — we cannot see or recover your actual password
  • Which part of our site sent you to the registration form, if you arrived by following one of our own links — for example the upgrade offer shown after you download a free QR code. This is a single short label chosen from a fixed list we publish, such as static-offer. If that link was on one of our guides, we also note which guide, by the name in its address. It records where the link was, never anything about you, and it is blank for most accounts. We use it only to understand which parts of the site people find useful, and it is deleted with your account.

You also provide the content of the QR codes you create, which may include website addresses, contact details, WiFi credentials, message text, calendar events, locations, and any logo image you upload.

b) Information collected automatically

When you use our website while signed in, our systems record:

  • A session record holding your IP address and browser user agent, which is how we keep you signed in and can tell one signed-in browser from another
  • Your IP address on each request, used momentarily to apply rate limits and block abuse. Cloudflare sits in front of our servers and processes the same address for the same purpose.

We run no third-party tracking on this site and build no profile of you. We do not record which pages you visit or how long you spend on them, and no advertising or analytics company receives anything about you from us.

We do keep anonymous counts of how often certain things happen here — how many free QR codes were generated today, for instance, or how many people opened a checkout. A count records that something happened and never who it happened to: it carries no name, no account, no IP address, no cookie and nothing you typed, and the address you put into a free QR code is never part of it. A count may note which of our own pages it happened on, such as the homepage or one of our guides, but loading a page is never counted by itself. These counts cannot be traced back to you, connected to one another, or used to recognise you on a later visit. We keep them for 90 days and use them to understand whether the site works, not who is using it.

c) Cookies

We use only the cookies needed to run the site: a session cookie that keeps you signed in, a security cookie that protects forms against cross-site request forgery, and a cookie that records that you have seen our cookie notice.

We do not use advertising or analytics cookies. Because every cookie we set is strictly necessary to provide the service you asked for, there is nothing here to consent to or refuse — if we ever add tracking, we will ask first.

3. QR Code Scan Data

This section is for you if you scanned a QR code and want to know what was recorded. You do not have an account with us and we have no other relationship with you.

Our service offers two kinds of code. Static codes encode their destination directly in the image, so scanning one never contacts us and we learn nothing about it. Dynamic codes resolve through our servers, so scanning one is a request to us, and we record that it happened so the person who created the code can see how it is performing.

For each scan of a dynamic code we record:

  • The date and time
  • The approximate country, which Cloudflare determines from the network connection
  • The device type, operating system and browser your device reports
  • The referring page, where your browser supplies one

We do not store the IP address of anyone who scans a QR code. Your address reaches our servers, as it must for any web request, and we use it in the moment to apply rate limits — but it is not written to the scan record and we cannot go back and look it up.

This information is visible to the person who created the code, both as totals and as individual scan records. It is not connected to a name or an account, and we do not use it to recognise you across different codes or on a later visit.

We do not sell it, share it with advertisers, or use it for advertising of any kind. The legal basis is our legitimate interest in providing the scan statistics that our subscribers pay for. If you would rather not be counted, you can decline to scan a code you do not trust — and if you believe a code is being used to mislead or harm people, please tell us.

You can ask us what we hold about you. Please bear in mind that because we deliberately hold nothing that identifies you, we will usually be unable to single out your individual scan from everyone else's.

4. Why We Use Your Information, and Our Legal Basis

Where the GDPR or a comparable law applies, we must have a lawful basis for each purpose. Ours are:

Purpose Legal basis
Creating and managing your account Performance of a contract
Generating, storing and resolving your QR codes Performance of a contract
Taking payment and handling renewals Performance of a contract
Account, security and billing email Performance of a contract
Responding to your support requests Performance of a contract
Scan statistics shown to the code's owner Legitimate interest — providing the feature the owner subscribed for
Rate limiting, abuse prevention and keeping the service available Legitimate interest — operating a lawful and reliable service
Product news and promotions Consent, which you may withdraw at any time
Keeping business records required by tax and accounting law Legal obligation

We do not sell your personal data, and we do not share it with advertisers.

5. Who Processes Your Data

We use a small number of companies to run the service. Each processes personal data only on our instructions and only as far as its role requires.

Company What they do for us Where
Laravel Cloud Application hosting and database United States
Cloudflare Content delivery, TLS, bot protection, and the approximate country of a QR code scan Global edge network
Resend Delivery of account and billing email United States
AgentaOS Payment processing as merchant of record See their privacy policy
Bunny Fonts Serving the web fonts used on our public pages European Union

A note on payments. AgentaOS acts as the merchant of record for every purchase. When you subscribe you are buying from AgentaOS rather than from us, and they collect and hold your payment details, billing address and tax location directly. We never see or store your card details. They issue your invoice and receipt and are the controller for that payment data, so their own privacy policy governs it. We receive only a subscription reference, its status, and its renewal date.

Beyond these processors, we disclose personal data only to legal or regulatory authorities where the law requires it.

6. Where Your Data Is Stored

Our application and database are hosted by Laravel Cloud on servers in the United States. Email is delivered through Resend, also in the United States. Cloudflare operates a global edge network, so your request may pass through a Cloudflare location near you before it reaches our servers.

If you are in the European Economic Area, the United Kingdom or Switzerland, this means your personal data is transferred outside your region. Where such a transfer is not covered by an adequacy decision, we rely on the European Commission's Standard Contractual Clauses as the legal mechanism for it.

7. How Long We Keep It

Data How long
Account details (name, email, password hash, and where you signed up from) For as long as your account exists
Your QR codes and their destinations For as long as your account exists; deleted with it
QR code scan records 24 months, then deleted automatically. Sooner if the QR code itself is deleted, which removes its scans with it
Anonymous usage counts 90 days, then deleted automatically. A count records that something happened, never who it happened to, so there is nothing in one to connect to you
Sign-in session records A session expires after 120 minutes of inactivity
Subscription records As long as tax and accounting law requires. AgentaOS holds the invoice itself, as merchant of record

When you delete your account we remove your personal details and your QR codes from our active systems, except anything the law requires us to keep. Copies inside encrypted backups disappear as those backups age out of rotation.

8. Email Communication

By creating an account, you agree to receive:

  • Service email we cannot reasonably operate without — confirming your account, resetting your password, warning you that your trial is ending, and telling you when a payment fails
  • Product updates or promotions, only if you opt in. You can unsubscribe from these at any time without losing access to anything.

9. Your Rights

Depending on where you live — for example under the GDPR or the CCPA — you have the right to:

  • Access the data we hold about you
  • Request correction or deletion of your data
  • Restrict or object to certain processing, including our legitimate-interest processing
  • Request a copy of your data in a portable format
  • Withdraw consent for marketing email
  • Not be discriminated against for exercising any of these rights

To exercise any of them, email [email protected]. We will not charge you for it and we aim to respond within 30 days.

You also have the right to lodge a complaint with a data protection supervisory authority. If you are in the EEA or the UK, that is the authority in your country of residence. We would rather you came to us first so we can put things right, but you do not have to.

10. Data Security

We take reasonable measures to protect your information, including:

  • Passwords stored as one-way hashes, never in a readable form
  • All traffic encrypted in transit over HTTPS
  • Restricted database access
  • Card details never touching our servers — AgentaOS handles payment data

However, no online service can be completely secure, and we do not claim otherwise.

11. Children

The service is not intended for children. You must be at least 18 years old to create an account, as set out in our Terms and Conditions. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Any change is posted here with a new "last updated" date, and if a change materially affects your rights we will notify you by email or through the website before it takes effect.

13. Contact Us

If you have any question about this Policy or about your data, contact us at: