How QRfox collects, uses, and protects your information.
This Privacy Policy explains how 465 Media ("465 Media," "we," "us," or "our"), the company behind QRfox (qrfox.io and the qrfox.co short-link domain, together "QRfox" or the "Service"), collects, uses, shares, and protects information.
When you create a QRfox account, we collect your email address and a securely hashed password. If you sign up or log in with Google, we receive your name, email address, and profile picture from Google instead of a password.
If you subscribe to a paid plan, payments are processed by Stripe. We do not receive or store your full card number — Stripe shares back a customer/subscription reference we use to manage your plan. If you redeemed a QRfox license through AppSumo, we store the license key and its status to keep your account entitlements in sync.
We store the QR codes you create and everything needed to make them work: destination URLs or content, labels, tags, folder assignments, design/styling choices, saved design templates, and access controls you set (like passwords, scan limits, or active date ranges).
If you use team features, we store the email addresses and roles of people you invite, and which workspace (yours or a team's) each member is currently viewing.
Every time someone scans one of your QR codes, we log: the time of the scan, the referring page (if any), and technical details about the device, operating system, browser, and approximate country used to view it. These details are derived from the scan request itself. We do not store the scanning visitor's IP address or precise location, and we do not place tracking cookies on their device. This data is shown back to you (the code's owner) as scan analytics.
If you email us or use the contact form, we collect the name, email address, and message you provide so we can respond.
We use a small number of first-party cookies required for the Service to function: a session cookie that keeps you logged in, a short-lived cookie used only during Google sign-in to prevent CSRF, and, if you unlock a password-protected QR code, a cookie that remembers you've already entered the password. We also use HeyCatch, a product analytics service, to understand how the qrfox.io website and dashboard are used (pages viewed, features used); it stores an identifier in your browser for that purpose. We don't use advertising cookies, and analytics apply only to the qrfox.io site itself — never to people who scan your QR codes.
We do not sell your personal information, and we do not use your data to serve third-party advertising.
We share information only as needed to run the Service:
We may also disclose information if required by law, to protect the rights, property, or safety of QRfox, our users, or the public, or in connection with a merger, acquisition, or sale of assets (with notice to affected users where required).
QRfox is used by our customers to create QR codes that route to content, links, or contact details they choose. If you scanned a QRfox code, the destination and any information collected there (for example, a form on the destination page) is controlled by whoever created that code, not by us. QRfox itself only records the limited, non-identifying scan analytics described above (timestamp, referrer, device/browser/OS type, approximate country) — no IP address or precise location.
We retain account and content data for as long as your account is active. Scan records are retained to provide historical analytics and are deleted when the associated QR code or account is deleted. If your account is deactivated (for example, following an AppSumo refund), QR codes stop redirecting but the underlying data isn't immediately erased, so the account can be reactivated. We retain data as needed to comply with legal, tax, or accounting obligations.
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, or to object to or restrict certain processing (for example, under the EU/UK GDPR or the California Consumer Privacy Act). To exercise any of these rights, email us at [email protected] and we'll respond within a reasonable time. You can update most account details yourself from within the app; account deletion is currently handled by our team on request while we build self-serve deletion.
We use industry-standard measures to protect your information, including password hashing, encrypted connections (HTTPS), and httpOnly session cookies. No method of transmission or storage is 100% secure, and we can't guarantee absolute security.
QRfox is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we'll delete it.
QRfox is operated from the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S., which may have different data protection laws than your country.
We may update this Privacy Policy from time to time. If we make material changes, we'll update the effective date above and, where appropriate, notify you directly.
Questions about this Privacy Policy or how we handle your data? Reach us at [email protected] or through our contact page.