Privacy policy

Effective: 28 August 2026 Controller: Presttige s. r. o. Jurisdiction: Slovakia / EU

This Privacy Policy explains how Presttige s. r. o., a company established in Slovakia, with registered office at Veľké Bierovce, 913 11 Veľké Bierovce, Slovakia, company ID (IČO) 50 461 796, processes personal data when people visit, register for, or use the DynamicQRCode QR code application available at dynamic-qrs.com and related pages.

Privacy at a glance

Local geolocation

QR scan geolocation is performed on our server. Scanner IP addresses are not sent to MaxMind during local database lookups.

Pseudonymised scan records

The application stores a SHA-256 identifier derived from the IP address, not the raw IP address, in its scan analytics table.

No sale of personal data

We do not sell personal data or knowingly share it for cross-context behavioural advertising.

Your choices and rights

You may contact us to exercise applicable privacy rights, including access, correction, deletion, restriction and objection.

1Controller and Contact Details

The controller of personal data is:

Presttige s. r. o.
Registered office: Veľké Bierovce, 913 11 Veľké Bierovce, Slovakia
Company ID (IČO): 50 461 796
Country: Slovakia
Email: info@dynamic-qrs.com

Users may contact us about privacy matters at the email above. EU/EEA users may also contact the Slovak supervisory authority, the Office for Personal Data Protection of the Slovak Republic.

2Scope

This Policy applies to visitors, registered account users, people who scan dynamic QR codes, and people whose personal data is entered into a QR code by an account user.

When an account user enters personal data about another person into a QR code, that account user is responsible for having a lawful basis and providing any required privacy notice.

3Personal Data We Process

Account and login data

Username, email address, password hash, account type, GDPR agreement flag, verification token, password reset token, login session data, remember-me series ID/token, cookie expiry information, and related account records.

QR code content and files

Dynamic QR data includes filenames, destination URLs, redirect identifiers, QR image files, status and timestamps, owner/user IDs, account settings, device-specific and fallback URLs, scan limits and counters.

Static QR data may include text, email content, phone numbers, messages, Skype usernames, coordinates, vCard/contact data, event details, URLs, Wi-Fi credentials, payment fields, cryptocurrency addresses, filenames, QR images and timestamps.

Payment and subscription data

Account email address, Stripe customer and subscription IDs, subscription status and expiry, plan selection, checkout metadata and billing portal access. Payment card details are handled by Stripe and are not stored in our application database.

Support and email data

Email addresses, usernames, password reset and verification emails, subscription notices, support messages and related delivery metadata handled through our configured SMTP/email provider.

Security and anti-abuse data

reCAPTCHA verification responses, URL safety checks, blocked-domain checks, authentication sessions, CSRF tokens, server logs and technical data needed to prevent abuse, fraud, spam, malicious links and unauthorized access.

Cookies and similar technologies

Necessary cookies and session storage support login, authentication, CSRF protection, remember-me login, preferences and website operation. Remember-me cookies are currently designed to last up to 30 days.

Scan analytics and IP geolocation

When a dynamic QR code is scanned, the Service temporarily processes the scanner's raw IP address on our server to determine an approximate country and, for United States scans, state/region where available. This lookup is performed locally using a GeoLite2 City database stored on our server. The scanner's IP address is not sent to MaxMind as part of this lookup.

The raw IP address is not stored in the scan analytics database. Before a scan record is stored, the IP address is transformed using SHA-256 hashing. We store the resulting hashed IP identifier together with the scan timestamp, QR code ID, browser session ID, derived country/state and broad device type such as Android, iOS, Desktop or Unknown.

Privacy classification: We treat the hashed IP identifier as pseudonymised personal data rather than anonymous data. It is used for purposes such as distinguishing unique scans, providing analytics, maintaining security and preventing fraud or abuse. Raw IP addresses may separately appear for a limited period in technical server or security logs used for hosting, troubleshooting, security and abuse prevention.

4Purposes and Legal Bases

Purpose Examples of data GDPR legal basis
Account registration and login Username, email, password hash, sessions, verification tokens Contract performance; legitimate interests in security
QR code creation and management QR content, filenames, URLs, QR images, owner IDs, account type Contract performance
Dynamic QR redirection and analytics QR identifier, scan timestamp, session ID, hashed IP identifier, country/state, device type Contract performance for QR owners; legitimate interests in analytics, service operation and fraud prevention
Subscription and billing Email, Stripe customer/subscription IDs, plan data, subscription status Contract performance; legal obligation for accounting/tax records
Email verification and service notices Email, username, reset/verification tokens Contract performance; legitimate interests in account security
Abuse prevention and security reCAPTCHA, URL checks, logs, CSRF/session data Legitimate interests; legal obligation where applicable
Compliance and disputes Account, payment, logs, communications Legal obligation; legitimate interests in legal claims
Optional marketing, if used Email and communication preferences Consent or legitimate interests where legally allowed

We do not use personal data for solely automated decisions that produce legal or similarly significant effects.

5Third-Party Processors, Recipients and Data Sources

We may share personal data with service providers that help us operate the Service, including:

  • hosting and database providers;
  • Stripe for payment and subscription processing;
  • Google reCAPTCHA and Google Safe Browsing for security and abuse prevention;
  • goQR.me / api.qrserver.com for applicable QR-code functionality;
  • SMTP/email providers;
  • WordPress or cookie-consent components;
  • professional advisers, authorities, courts and regulators where required by law.

Approximate scan geolocation is performed on our server using the locally installed GeoLite2 City database. MaxMind supplies the GeoLite data but does not receive scanner IP addresses through these local database lookups.

This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com.

6International Transfers

Because the Service is available globally and uses global cloud, payment, email, security and other service providers, personal data may be processed outside Slovakia, the EEA, or the user's country.

Where GDPR applies and data is transferred outside the EEA, we rely on appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, processor data protection terms, or another lawful transfer mechanism.

Using the local GeoLite2 City database for a scan does not itself transfer that scanner's IP address to MaxMind.

7Retention

  • Account data: kept while the account exists and for a reasonable period afterward where needed for legal, security, accounting or dispute purposes.
  • Active QR codes and scan logs: while a dynamic QR code and the QR owner's account remain active, QR records, image files and associated scan logs are retained to provide redirection, historical analytics, reporting, security and service operation. We do not currently apply a fixed automatic expiration period to active scan logs.
  • Authentication data: password reset tokens are designed to expire after approximately 1 hour. Remember-me login cookies are designed to last up to 30 days.
  • Billing records: may be kept for the period required by Slovak accounting, tax and commercial law.
  • Server and security logs: kept for a period appropriate to security needs and may be retained longer when connected to an investigation, dispute, legal obligation or legal claim.

Deleted QR codes and restricted copies

When a QR code is deleted, it is deactivated and removed from the user's ordinary account access. Deletion does not immediately destroy every associated QR image file, configuration record or scan log. These records may persist only as restricted server-side copies. The user can no longer access, modify, export or erase those copies through ordinary account tools.

Restricted recoverable server-side copies may be preserved where reasonably necessary to restore an accidental deletion, maintain service integrity, or protect records that may be relevant to suspected fraud or abuse, an existing or reasonably anticipated investigation, a dispute, a legal obligation, or the establishment, exercise or defence of legal claims. This restricted retention helps prevent the deletion function from being used to destroy or conceal potential evidence. Restoration is not guaranteed.

The retention of deleted QR records and associated scan logs is determined according to the QR code and account lifecycle, the need for recovery, the nature and severity of suspected misuse, applicable legal limitation periods, and whether an investigation, dispute or legal hold is active or reasonably anticipated.

Evidence-preservation retention is applied only where reasonably necessary and proportionate to the relevant risk or matter. Retained server-side information is not available through ordinary account analytics, and access is restricted to authorized personnel and providers with a need to know. It is deleted or irreversibly anonymized when the applicable retention purpose ends, unless continued storage is required by law. Anonymous aggregate statistics may be retained for longer.

Controller and processor roles for analytics

Where we process scan analytics solely on behalf of a QR owner, the QR owner determines the relevant retention instructions as controller, subject to the applicable data-processing agreement. Where we independently retain limited information for our own service security, fraud and abuse prevention, legal compliance or legal claims, we act as controller for that separate processing and retain only the information reasonably necessary for that purpose.

8Security Measures

We use technical and organizational measures intended to protect personal data, including:

  • hashed passwords;
  • session regeneration on login;
  • HTTP-only remember-me cookies where supported;
  • CSRF protection for checkout;
  • URL validation and malicious URL checks;
  • QR ownership checks and access controls;
  • pseudonymised storage of scan IP identifiers using SHA-256 hashing; and
  • local GeoLite2 lookups that avoid sending scanner IP addresses to an external geolocation API for each scan.

9User Responsibilities for QR Content

Users control the content they enter into QR codes. Users must not submit unlawful, harmful, misleading, infringing or malicious content, and must not enter personal data about another person unless they have a valid legal basis and have provided any required notice or consent.

Users should avoid placing special category data, payment secrets, passwords, private credentials, health data, children's data or confidential third-party data into QR codes unless strictly necessary and legally permitted.

10Your GDPR Rights

Where GDPR applies, data subjects may have rights to:

  • access their personal data;
  • request correction or erasure;
  • request restriction of processing;
  • receive portable data where applicable;
  • object to processing;
  • withdraw consent where processing relies on consent;
  • not be subject to solely automated decision-making with legal or similarly significant effects; and
  • lodge a complaint with a supervisory authority.

Requests should be sent to info@dynamic-qrs.com. We may need to verify the requester's identity before acting on a request. We normally respond within one month where GDPR applies, subject to permitted extensions.

11Rights for Non-EU Users

Users outside the EU/EEA may have privacy rights under local law, such as rights to know, access, correct, delete, opt out of certain disclosures, or appeal a privacy decision. We will handle such requests according to applicable law.

We do not sell personal data, and we do not knowingly share personal data for cross-context behavioral advertising as those terms may be defined under certain US state privacy laws.

12Children's Privacy

The Service is intended for business and general users and is not directed to children. Users must not create accounts or submit children's personal data unless they have the legal authority and lawful basis to do so. If we learn that we process children's personal data unlawfully, we will take appropriate steps to delete or restrict it.

13Changes to This Policy

We may update this Privacy Policy from time to time. The updated version will be posted on the website with a new effective date. If changes are material, we may provide additional notice through the Service or by email.

Dynamic-qrs

A dynamic QR code is a type of QR code that allows you to change the content or target URL after it has been printed or distributed, without needing to create a new code

Copyright © 2026 dynamic-qrs. All Rights Reserved.