Last updated: September 11, 2026
This Privacy Policy explains how GenerateQR ("GenerateQR", "we", "us", or "our") collects, uses, shares, and protects information when you visit generateqr.org and use our QR code generator and related account features (together, the "Service"). By using the Service, you agree to the practices described here. If you do not agree, please do not use the Service.
If you have any questions about this policy or your data, contact us at [email protected].
Quick summary
- You can create static QR codes for free with no account. The content you enter is used only to generate your code and is not tied to your identity.
- Creating an account (including through Sign in with Google) lets you save codes and create dynamic QR codes. This involves collecting more information, described below.
- Dynamic QR codes record scan analytics so you can see how your codes perform.
- We do not sell your personal information.
Information you provide to us
- Account information. When you register, we collect your email address, a display name if you provide one, and a password. Passwords are stored only in hashed form, never in plain text.
- QR code content. The information you enter to generate a code, such as a web address, WiFi network details, contact details for a vCard, an event, a phone number, or a payment address. For static codes this is used to render the image and is not linked to an account.
- Dynamic QR code data. For dynamic codes we store the short link and the destination you set, along with the settings and labels you save in your dashboard.
- Payment information. If you purchase a paid plan, our payment provider processes your payment. We receive limited billing details such as your plan, transaction identifiers, and billing status, but we do not store full card numbers.
- Communications. If you contact us, we keep your messages and contact details so we can respond and keep a record of support.
Information we collect automatically
- Generated image files. When you create a static code, the content is sent to our server to render the image. Generated image files are stored temporarily so you can download them and are removed automatically after a short period.
- Scan analytics for dynamic codes. When someone scans a dynamic code, we process technical information about that scan so we can show you statistics. This can include the IP address, an approximate location derived from it, the device type, operating system and browser, the referring source, and the date and time.
- Log and usage data. Like most websites, our servers record standard log information such as IP address, browser type, pages viewed, and timestamps, which we use for security and to keep the Service reliable.
- Cookies and similar technologies. Described in the Cookies section below.
Signing in with Google
If you choose Sign in with Google, Google shares a limited set of profile information with us so we can create and secure your account. This can include your name, email address, profile picture, and Google account identifier. We use this information only to authenticate you and to create and manage your GenerateQR account.
Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, and we do not sell it or transfer it to others except as needed to provide the Service, to comply with the law, or as part of the situations described in the Sharing section. You can revoke our access at any time from your Google Account permissions page.
How we use information
- To generate the QR codes you request.
- To provide, maintain, and improve accounts, dynamic codes, and scan analytics.
- To authenticate you and keep your account secure.
- To process payments and manage plans, where applicable.
- To respond to your messages and provide support.
- To monitor, prevent, and address fraud, abuse, and security issues.
- To understand aggregate usage so we can improve the product.
- To comply with legal obligations and enforce our terms.
Legal bases for processing
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases: performance of a contract, to provide the Service you request; legitimate interests, to keep the Service secure, reliable, and improving; consent, where required, for example for certain cookies or optional communications; and legal obligation, where the law requires us to process data.
How we share information
We do not sell your personal information. We share information only in these situations:
- Service providers. With companies that help us run the Service, such as hosting and infrastructure, our payment provider, email delivery, and privacy-conscious analytics. They may process data only on our instructions.
- At your direction. Information you choose to make public, such as a destination you encode into a code you publish, is shared because you chose to distribute it.
- Legal and safety. When we believe disclosure is required by law, regulation, or legal process, or is needed to protect the rights, property, or safety of GenerateQR, our users, or the public.
- Business transfers. If GenerateQR is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy.
Cookies and similar technologies
We use a small number of cookies and similar technologies:
- Essential cookies keep the Service working and, when you sign in, keep you logged in securely.
- Functional cookies remember preferences and let our marketing pages show whether you are signed in so the menu can link to your dashboard.
- Analytics help us understand aggregate usage so we can improve the product.
You can control cookies through your browser settings. Blocking essential cookies may stop parts of the Service, such as signing in, from working.
Data retention
We keep information only for as long as we need it. Generated static image files are removed automatically after a short period. Account information is kept while your account is active and for a reasonable period afterward to meet legal, security, and accounting needs. Scan analytics for dynamic codes are kept while the code and account remain active. You can ask us to delete your account and associated data at any time.
Security
We take reasonable technical and organizational measures to protect your information, including encryption of traffic in transit, hashed passwords, and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your data and to respond promptly to any issue.
International data transfers
We may process and store information in countries other than the one where you live. Where we transfer personal data across borders, we take steps to ensure it remains protected in line with this policy and applicable law.
Your rights and choices
Depending on where you live, you may have some or all of the following rights: to access the personal data we hold about you, to correct inaccurate data, to delete your data, to restrict or object to certain processing, to receive your data in a portable format, and to withdraw consent where processing is based on consent. If you are in California, you have the right to know what personal information we collect, to request deletion, and to not have your information sold, which we do not do in any case. You will not be treated differently for exercising these rights.
To make a request, email us at [email protected]. You can also manage and delete your saved codes and close your account from your dashboard. If you are in the EEA or UK, you may also lodge a complaint with your local data protection authority.
Children
The Service is intended for a general audience and is not directed at children under the age required by the laws of their country. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
Third-party destinations
A QR code opens whatever destination is encoded in it, such as a website, a payment page, or a WiFi network. Those destinations and any third-party services are governed by their own privacy policies, and we are not responsible for their practices.
Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the date below and, where appropriate, provide a more prominent notice. Your continued use of the Service after an update means you accept the revised policy.
Contact us
If you have questions, requests, or concerns about this Privacy Policy or your personal data, contact us at [email protected].