Privacy Policy
This Privacy Policy explains how QR Set (“we”, “us”, or “our”) collects, uses, discloses, retains and protects personal data when people use QR Set, including our website, mobile applications, Account, QR-code creation and management tools, dynamic redirect infrastructure and related services (the “Service”).
1. Controller and scope
Tarfion Ltd, Griva Digeni, 59, Kaimakliotis Building, 5th Floor, 6043 Larnaca, Cyprus, is the controller of personal data that we process for our own purposes. Contact us at [email protected].
A customer that creates a QR Code may independently determine the purpose of collecting data at the destination page or through content linked by that QR Code. This Policy does not govern a customer’s own website, form, app, campaign or other destination.
2. Personal data we collect
2.1 Data you provide
-
Account data, such as name, email address, organization, role, language, login information and profile settings.
-
QR and Content data, such as URLs, files, text, images, logos, contact details, QR labels, folders, tags, landing-page content and destination settings.
-
Billing and transaction data, such as billing address, tax information, plan, transaction identifiers, purchase channel, payment status, renewal status, refunds and chargebacks. Full card numbers are not stored by us.
-
Communications, such as support requests, emails, complaints, survey responses, feedback and attachments.
-
Information you submit when exercising privacy, cancellation, refund or legal rights.
2.2 Data collected automatically from the website
Technical data such as IP address, device type, browser, operating system, language, time zone and similar device or network information.
- Usage data such as sessions, screens or pages viewed, feature interactions, QR creation events, errors, performance data and security events.
2.3 Device permissions
Depending on the features you use, the Website may request access to camera, photo library, files or other permissions. We request device permission only when needed for the feature you choose. The operating system controls permission settings, and you can revoke a permission in device settings. If a permission is optional, refusing it may prevent only the related feature from working.
2.4 Data from third parties
-
Payment status and limited transaction information from Payment Processor for Direct Purchases.
-
Fraud, security or abuse signals from providers, where used.
4. How we use personal data and legal bases
We use personal data for the following purposes:
-
Provide and administer the Service
-
Process purchases and subscriptions
-
Security and abuse prevention
-
Support and communications
-
Product analytics and improvements
-
Marketing and advertising
-
Legal compliance
5. Cookies, SDKs and similar technologies
Our website may use cookies, local storage, mobile SDKs, pixels or similar technologies for necessary functionality, authentication, preferences, security, analytics, diagnostics, experimentation, attribution or advertising.
6. How we disclose personal data
We disclose personal data only as reasonably necessary for the purposes described in this Policy, including to:
-
hosting, cloud and infrastructure providers;
-
payment processors;
-
authentication providers;
-
analytics, product and experimentation providers;
-
crash, diagnostics and monitoring providers;
-
customer support and communications providers;
-
security and fraud-prevention providers;
-
advertising or attribution providers;
-
courts, regulators, law enforcement or other authorities where disclosure is required by law or reasonably necessary to protect rights, security and safety.
10. Retention
Personal data is generally retained only for as long as necessary to fulfill the purposes described in this Privacy Policy, comply with our obligations under the Terms of Use, and meet applicable legal or regulatory requirements. Where applicable law requires us to retain certain information for a longer period, we will retain such information for the period required by law.
Certain information may continue to be retained after a user deletes their profile or account. Such retention may be necessary to comply with legal, regulatory, accounting, or operational obligations, including those relating to payment processing, financial recordkeeping, dispute handling and resolution, fraud prevention, anti-money laundering requirements, or other applicable legal obligations.
11. Security
We use administrative, technical and organizational safeguards designed to protect personal data. Contact [email protected] if you suspect unauthorized access or a security vulnerability. We investigate incidents and provide legally required breach notifications.
12. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing; obtain a portable copy; withdraw consent; opt out of sale, sharing, targeted advertising or certain profiling; appeal a denied request; and receive information about our practices. You may also have the right to complain to a competent data protection authority.
Submit a request through [email protected]. We may verify identity and authority before responding. We will respond within the period required by applicable law.
14. Marketing and notifications
We may send you email notifications to the email address associated with your registered account. You can unsubscribe from marketing emails using the link in the message or via contacting our Support Team at [email protected]. Transactional or service messages about billing, security, Account administration, legal notices or requested services may continue.
15. Children
The Service is not directed to children under 18 and users under the Account eligibility age may not create an Account. We do not knowingly collect personal data from children in a manner prohibited by applicable law. If you believe a child has provided personal data, contact [email protected] so we can investigate and take appropriate action.
16. Third-party links and QR destinations
The Service and QR Codes may link to third-party websites, apps, payment pages or other destinations. Their privacy practices apply to data they collect. We do not control those practices. Review the privacy notice of a destination before providing personal data.
17. Changes to this Policy
We may update this Policy to reflect changes in law, technology, security, the Service or our practices. We will post the revised Policy here.