Skip to main content

Privacy Policy

Last updated: July 24, 2026

This Privacy Policy explains how Magpie Nexus, Inc. ("Magpie Nexus", "we", "us", or "our") collects, uses, and shares personal data when you use QR Code Genius — our websites, dashboard, QR code generator, short links, and APIs (together, the "Service") — and describes the rights and choices available to you. If you do not agree with this policy, please do not use the Service.

1. Who We Are and Scope of This Policy

QR Code Genius is operated by Magpie Nexus, Inc., a company incorporated in the State of Delaware, United States. For personal data relating to your account and your own use of the Service, Magpie Nexus, Inc. acts as the data controller.

When someone scans a QR code or opens a short link created by one of our customers, we process the resulting scan data on that customer's behalf in order to provide the customer with analytics. The customer who created the QR code is responsible for the content behind the code and for complying with the laws that apply to their own campaigns, including providing any notices or obtaining any consents required from the people who scan their codes.

You can contact us about anything in this policy at support@qrcodegenius.com.

2. Information You Provide to Us

  • Account information. When you sign up we collect your name, email address, and a password (stored only in hashed form), together with your interface language. If you sign in with Google, we receive your name, email address, and profile picture from your Google account.
  • QR code content. We store the content you place in your QR codes and short links. Depending on the type of code, this can include destination URLs, free text, contact details (vCard: names, phone numbers, email addresses, organizations), Wi-Fi network names and passwords, phone numbers and message text, email addresses, cryptocurrency wallet addresses, event details, and social media links.
  • Files you upload. Logo images embedded in QR codes, profile pictures, and PDF documents attached to PDF-type codes. Logo images and profile pictures are stored in publicly addressable storage, meaning anyone who has the file's direct URL can view it — do not upload confidential images.
  • Billing information. Payments are processed by Stripe. Your full card number never reaches our servers. We store your Stripe customer and subscription identifiers, your plan and subscription status, and a record of payment events (amounts, currency, invoice references) for accounting and support.
  • Communications. Messages you send us, for example support requests by email.

3. Information Collected When a QR Code Is Scanned

When a person scans a dynamic QR code or opens a short link served through the Service, we automatically record information about that scan:

  • Network and device data: IP address, browser type and version, operating system, device type, vendor, and model, and the full user-agent string.
  • Approximate location derived from the IP address: country, region, city, and approximate coordinates. This is IP-based estimation, not GPS positioning.
  • Context data: browser language, referring page (if any), date and time of the scan, and, where the code uses A/B testing, the variant served.
  • An anonymous visitor identifier stored in a cookie (see Cookies below), used to distinguish unique visitors from repeat scans.

This scan data is made available to the customer who created the QR code through their analytics dashboard. Customers on paid plans can also choose to receive a notification for each scan — by email or to a webhook endpoint they configure — containing scan details such as location, device, browser, and operating system.

4. Cookies and Similar Technologies

We use the following cookies and browser storage:

  • Strictly necessary cookies: authentication session cookies that keep you signed in, a signed access cookie that remembers when you have entered the password for a password-protected QR code, and your language preference.
  • Scan attribution cookie: when you open a short link we set an anonymous visitor identifier (a random ID with a lifetime of one year) so that the code's owner can distinguish new visitors from returning ones. It does not contain your name or contact details.
  • Local storage on your device: your cookie-consent choice, your light/dark theme preference, dashboard onboarding state, and QR designs you save as drafts. Draft designs are stored only in your browser and are not sent to our servers until you save them to your account.
  • Analytics cookies: Google Analytics cookies (such as _ga) are set only after you accept analytics in our cookie banner.

You can decline analytics cookies in the banner, block or delete cookies in your browser settings, and withdraw a previously given consent by clearing this site's data in your browser. Blocking strictly necessary cookies may prevent parts of the Service from working.

5. Website Analytics

With your consent, we use Google Analytics 4 and Google Tag Manager to understand how the Service is used. This covers events such as page views, QR code generation and downloads, sign-ups, logins, and checkout activity, as well as page performance metrics. If you are signed in and have consented, these events may be associated with your user ID, plan, and email address for measurement purposes (for example, purchase and conversion measurement). Google processes this data in accordance with its own privacy policy. We also record key account events (such as sign-ups and purchases) server-side, associated with your user ID, to keep our product metrics accurate.

6. How We Use Personal Data

  • To provide and operate the Service: creating and serving QR codes and short links, storing your designs, and showing scan analytics to the code owner.
  • To manage plans and billing: processing subscriptions, metering monthly usage and prepaid credits, and maintaining payment records.
  • To communicate with you: transactional emails such as email verification, password resets, billing notices, payment-failure alerts, and — where you enable them — scan notifications.
  • To keep the Service safe: preventing fraud and abuse, enforcing usage limits, reviewing QR codes reported or flagged for abuse, and maintaining audit logs of administrative actions.
  • To improve the Service: understanding feature usage and diagnosing problems.
  • To comply with legal obligations, including tax and accounting requirements.

7. Legal Bases for Processing (EEA and UK)

Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (providing the Service you signed up for, including billing); legitimate interests (securing the Service, preventing abuse, improving our product, and providing scan analytics as a business service to our customers); consent (analytics cookies and associated measurement); and compliance with legal obligations (for example, retaining payment records).

8. How We Share Personal Data

We do not sell personal data, and we do not share it for cross-context behavioral advertising. We share personal data only as follows:

  • Service providers that process data on our behalf: Supabase (database, authentication, and file storage), Stripe (payment processing), Resend (transactional email delivery), Google (sign-in with Google, and analytics where you have consented), and our hosting infrastructure provider (Railway).
  • QR code owners: scan data described above is shared with the customer whose code was scanned, through their dashboard and, if they enable it, through notification emails or webhooks they configure. Webhook endpoints are chosen by the code owner, and data sent to them is governed by the owner's own practices.
  • Legal reasons: where required by law, regulation, legal process, or an enforceable governmental request, or where necessary to protect the rights, safety, or property of our users, the public, or Magpie Nexus.
  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of the transaction, subject to this policy.
  • With your direction: when you ask us to share data with a third party.

9. If You Scanned a QR Code

If you arrived here after scanning a QR code created with our Service: the content you were shown (the destination website, file, or contact card) was chosen by the person or organization that created the code, not by us. When you opened the link we recorded the scan data described in this policy and made it available to the code's creator. If you have questions about a specific campaign, or wish to exercise privacy rights regarding data a creator holds about you, please contact the code's creator; we will assist them in responding where we act as their processor. You can also contact us directly at support@qrcodegenius.com.

10. Data Retention

  • Account data is retained for as long as your account exists.
  • QR code content and scan analytics are retained until you delete the relevant QR code or your account is deleted.
  • Payment and billing records are retained for as long as required by tax, accounting, and other legal obligations.
  • When your account is deleted, your profile, QR codes, scan analytics, API keys, and related records are permanently removed. Residual copies may persist in encrypted backups for a limited period before being purged.

11. Security

We take technical and organizational measures appropriate to the risk, including encryption of data in transit (TLS), hashed storage of passwords, storage of API keys only as cryptographic hashes, hashed storage of QR code access passwords, database row-level access controls that limit each account to its own data, and an append-only audit log of administrative actions. A limited number of authorized staff can access user data for support, moderation, and operations, and those actions are logged. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

12. Your Rights and Choices

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to restrict or object to certain processing, and to withdraw consent at any time (without affecting processing that happened before withdrawal).

  • You can edit your profile, change your password, and delete individual QR codes, folders, and uploads at any time from your dashboard.
  • To request deletion of your entire account and associated data, or to exercise any other right, contact us at support@qrcodegenius.com from the email address associated with your account. We may need to verify your identity before acting on a request. Account deletion is permanent.
  • You can decline or withdraw analytics consent as described in the Cookies section.
  • If you are in the EEA or UK, you may lodge a complaint with your data protection supervisory authority. If you are a California resident, you have the rights provided by the CCPA/CPRA, including the right not to be discriminated against for exercising them; as noted above, we do not sell or share personal data as those terms are defined in California law.

13. International Data Transfers

We are based in the United States, and the providers we use may process data in the United States and other countries. Where personal data of individuals in the EEA, UK, or Switzerland is transferred to countries that have not received an adequacy decision, we and our providers rely on appropriate safeguards such as Standard Contractual Clauses.

14. Children's Privacy

The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us at support@qrcodegenius.com and we will delete it.

15. Changes to This Policy

We may update this policy from time to time. We will post the updated version on this page and revise the "Last updated" date above. If a change materially affects your rights, we will provide more prominent notice, for example by email or a notice in the Service. This policy is provided in several languages for convenience; if there is any conflict between versions, the English version controls.

16. Contact Us

Magpie Nexus, Inc.

Incorporated in the State of Delaware, United States.

For privacy requests, questions about this policy, or legal notices, email support@qrcodegenius.com.