Privacy policy

Privacy Policy

DynamicQRCode / dynamic-qrs.com
Effective date: 9 August 2026

This Privacy Policy explains how Presttige s. r. o., a company established in Slovakia, with registered office at Veľké Bierovce, 913 11 Veľké Bierovce, Slovakia, company ID (IČO) 50 461 796, processes personal data when people visit, register for, or use the DynamicQRCode QR code application available at dynamic-qrs.com and related pages.

Important: This is an implementation-informed legal template based on the current application code. It should be reviewed by qualified Slovak/EU privacy counsel before publication.

1. Controller and Contact Details

The controller of personal data is:

  • Presttige s. r. o.
  • Registered office: Veľké Bierovce, 913 11 Veľké Bierovce, Slovakia
  • Company ID (IČO): 50 461 796
  • Country: Slovakia
  • Email: info@dynamic-qrs.com

Users may contact us about privacy matters at the email above. EU/EEA users may also contact the Slovak supervisory authority, the Office for Personal Data Protection of the Slovak Republic.

2. Scope

This Policy applies to visitors, registered account users, people who scan dynamic QR codes, and people whose personal data is entered into a QR code by an account user.

When an account user enters personal data about another person into a QR code, that account user is responsible for having a lawful basis and providing any required privacy notice.

3. Personal Data We Process

Account and Login Data

Username, email address, password hash, account type, GDPR agreement flag, verification token, password reset token, login session data, remember-me series ID/token, cookie expiry information, and related account records.

QR Code Content and Files

Dynamic QR data includes filenames, destination URLs, redirect identifiers, QR image files, QR status, created/updated timestamps, owner/user IDs, account feature settings, device-specific redirect URLs, fallback URLs, scan-limit settings, and scan counters. Static QR data may include text, email content, phone numbers, message text, Skype username, coordinates, vCard/contact data, event details, bookmark URLs, Wi-Fi SSID/password, PayPal payment fields, Bitcoin address, labels/messages, filenames, QR image files, and timestamps.

Scan Analytics Data

When a dynamic QR code is scanned, the Service processes scan timestamp, QR code ID, browser session ID, hashed IP address, derived country and, for United States scans, state/region where available, and broad device type such as Android, iOS, Desktop, or Unknown. The raw IP address is used temporarily to request geolocation data and is then hashed before storage.

Payment and Subscription Data

For paid subscriptions, we process account email address, Stripe customer ID, Stripe subscription ID, subscription status, subscription expiry, plan selection, checkout metadata, and billing portal access. Payment card details are handled by Stripe and are not stored by us in the application database.

Support and Email Data

We process email addresses, usernames, password reset emails, verification emails, subscription notices, support messages, and related delivery metadata handled through our configured SMTP/email provider.

Security and Anti-Abuse Data

We process reCAPTCHA verification responses, URL safety checks, blocked-domain checks, authentication sessions, CSRF tokens, server logs, and technical data needed to prevent abuse, fraud, spam, malicious links, and unauthorized access.

Cookies and Similar Technologies

The Service uses necessary cookies/session storage for login, authentication, CSRF protection, remember-me login, preferences, and website operation. Remember-me cookies are currently designed to last up to 30 days.

4. Purposes and Legal Bases

Purpose Examples of data GDPR legal basis
Account registration and login username, email, password hash, sessions, verification tokens Contract performance; legitimate interests in security
QR code creation and management QR content, filenames, URLs, QR images, owner IDs, account type Contract performance
Dynamic QR redirection and analytics QR identifier, scan timestamp, session ID, hashed IP, country/state, device type Contract performance for QR owners; legitimate interests in analytics and fraud prevention
Subscription and billing email, Stripe customer/subscription IDs, plan data, subscription status Contract performance; legal obligation for accounting/tax records
Email verification and service notices email, username, reset/verification tokens Contract performance; legitimate interests in account security
Abuse prevention and security reCAPTCHA, URL checks, logs, CSRF/session data Legitimate interests; legal obligation where applicable
Compliance and disputes account, payment, logs, communications Legal obligation; legitimate interests in legal claims
Optional marketing, if used email and communication preferences Consent or legitimate interests where legally allowed

We do not use personal data for solely automated decisions that produce legal or similarly significant effects.

5. Third-Party Processors and Recipients

We may share personal data with service providers that help us operate the Service, including hosting/database providers, Stripe, Google reCAPTCHA, Google Safe Browsing, ipgeolocation.io, goQR.me / api.qrserver.com, SMTP/email providers, WordPress or cookie-consent components, advisers, authorities, courts, and regulators where required by law.

6. International Transfers

Because the Service is available globally and uses global cloud, payment, email, security, and analytics providers, personal data may be processed outside Slovakia, the EEA, or the user’s country. Where GDPR applies and data is transferred outside the EEA, we rely on appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, processor data protection terms, or another lawful transfer mechanism.

7. Retention

  1. Account data is kept while the account exists and for a reasonable period afterward where needed for legal, security, accounting, or dispute purposes.
  2. While a dynamic QR code and the QR owner’s account remain active, the QR code records, QR image files, and associated scan logs are retained to provide redirection, historical analytics, reporting, security, and service operation. We do not currently apply a fixed automatic expiration period to active scan logs.
  3. When a QR code is deleted, it is deactivated and removed from the user’s ordinary account access. Deletion does not immediately destroy every associated QR image file, configuration record, or scan log. These records may persist only as restricted server-side copies. The user can no longer access, modify, export, or erase those copies through ordinary account tools. Restricted recoverable server-side copies may be preserved where reasonably necessary to restore an accidental deletion, maintain service integrity, or protect records that may be relevant to suspected fraud or abuse, an existing or reasonably anticipated investigation, a dispute, a legal obligation, or the establishment, exercise, or defence of legal claims. This restricted retention helps prevent the deletion function from being used to destroy or conceal potential evidence. Restoration is not guaranteed.
  4. The retention of deleted QR records and associated scan logs is determined according to the QR code and account lifecycle, the need for recovery, the nature and severity of suspected misuse, applicable legal limitation periods, and whether an investigation, dispute, or legal hold is active or reasonably anticipated. Evidence-preservation retention is applied only where reasonably necessary and proportionate to the relevant risk or matter. Retained server-side information is not available through ordinary account analytics and access is restricted to authorized personnel and providers with a need to know. It is deleted or irreversibly anonymized when the applicable retention purpose ends, unless continued storage is required by law. Anonymous aggregate statistics may be retained for longer.
  5. Password reset tokens are designed to expire after approximately 1 hour. Remember-me login cookies are designed to last up to 30 days.
  6. Billing and transaction records may be kept for the period required by Slovak accounting, tax, and commercial law.
  7. Server, security, and abuse-prevention logs are kept for a period appropriate to security needs and may be retained longer where connected to a specific investigation, dispute, legal obligation, or legal claim.

Where we process scan analytics solely on behalf of a QR owner, the QR owner determines the relevant retention instructions as controller, subject to the applicable data-processing agreement. Where we independently retain limited information for our own service security, fraud and abuse prevention, legal compliance, or legal claims, we act as controller for that separate processing and retain only the information reasonably necessary for that purpose.

8. Security Measures

We use technical and organizational measures intended to protect personal data, including hashed passwords, session regeneration on login, HTTP-only remember-me cookies where supported, CSRF protection for checkout, URL validation, malicious URL checks, QR ownership checks, access controls, and hashed storage of scan IP addresses.

9. User Responsibilities for QR Content

Users control the content they enter into QR codes. Users must not submit unlawful, harmful, misleading, infringing, or malicious content, and must not enter personal data about another person unless they have a valid legal basis and have provided any required notice or consent.

Users should avoid placing special category data, payment secrets, passwords, private credentials, health data, children’s data, or confidential third-party data into QR codes unless strictly necessary and legally permitted.

10. Your GDPR Rights

Where GDPR applies, data subjects may have rights of access, rectification, erasure, restriction, portability, objection, consent withdrawal, not to be subject to solely automated decision-making with legal or similarly significant effects, and to lodge a complaint with a supervisory authority.

Requests should be sent to info@dynamic-qrs.com. We may need to verify the requester’s identity before acting on a request. We normally respond within one month where GDPR applies, subject to permitted extensions.

11. Rights for Non-EU Users

Users outside the EU/EEA may have privacy rights under local law, such as rights to know, access, correct, delete, opt out of certain disclosures, or appeal a privacy decision. We will handle such requests according to applicable law. We do not sell personal data, and we do not knowingly share personal data for cross-context behavioral advertising as those terms may be defined under certain US state privacy laws.

12. Children’s Privacy

The Service is intended for business and general users and is not directed to children. Users must not create accounts or submit children’s personal data unless they have the legal authority and lawful basis to do so. If we learn that we process children’s personal data unlawfully, we will take appropriate steps to delete or restrict it.

13. Changes to This Policy

We may update this Privacy Policy from time to time. The updated version will be posted on the website with a new effective date. If changes are material, we may provide additional notice through the Service or by email.

    Dynamic-qrs

    A dynamic QR code is a type of QR code that allows you to change the content or target URL after it has been printed or distributed, without needing to create a new code

    Copyright © 2026 dynamic-qrs. All Rights Reserved.