Legal & Transparency

Cookie Policy

Effective Date: September 25, 2026 | Last Updated: September 25, 2026

1. About This Cookie Policy

This Cookie Policy explains which cookies and similar technologies qr-code.love uses, why, and how you control them. It sits alongside our Privacy Policy, which covers how we handle personal data in general, including your rights under India's Digital Personal Data Protection Act, 2023, the GDPR and the CCPA.

The short version: the QR code generator itself needs no cookies. On a first visit nothing is stored at all. Two small preference items are written to your browser only when you use the theme switch or answer the consent notice. Google Analytics cookies are set only if you press Allow analytics, and you can withdraw that at any time.

2. What Cookies and Similar Technologies Are

A cookie is a small text file that a website asks your browser to keep, so it can recognise the same browser on a later request. Local storage is a similar browser feature: a small key and value that a page can save and read back. Unlike a cookie, local storage is not sent to the server with every request. It stays in your browser unless the page's own code reads it.

Cookies set by the site you are visiting are first-party. Cookies set on behalf of another company, such as an analytics provider, are third-party. Some cookies last only for the browser session. Others persist for a set period or until you delete them.

3. What We Store, and When

This is the complete list of cookies and storage items the site uses.

  • sqr_theme_pref (first-party local storage, preference). Remembers whether you chose the light or dark theme. Written only when you use the theme switch, and kept until you clear this site's data. It contains only the word light or dark and is never sent anywhere.
  • sqr_consent (first-party local storage, strictly necessary). Records your analytics choice (allowed or declined) and when you made it, so we do not ask again on every page and can respect a withdrawal. Written only when you press Allow analytics or Decline, and kept until you clear this site's data. It is never sent anywhere.
  • _ga (Google Analytics cookie, analytics). A random identifier that lets Google Analytics tell one visitor from another, so visits can be counted without knowing who you are. Set only after you allow analytics. Expires after 2 years.
  • _ga_<ID> (Google Analytics cookie, analytics). Keeps the state of your current session for Google Analytics. Set only after you allow analytics. Expires after 2 years.

We do not use advertising, retargeting or social media tracking cookies. Google Consent Mode signals for advertising (ad_storage, ad_user_data and ad_personalization) are always set to denied, even when analytics is allowed. If we ever introduce advertising, we will ask for your consent first and update this policy before doing so.

4. Strictly Necessary and Preference Storage

The two sqr_ items exist only to do what you asked. One keeps the theme you picked and the other remembers the consent choice you made. Neither identifies you, tracks you across sites or leaves your device, so they do not require consent under the ePrivacy rules in the EU and UK. They are still listed here so that the list is complete. You can remove them at any time by clearing this site's data in your browser.

The generator keeps everything else in memory only. Form contents, generated codes and any logo you upload are held by the open page and discarded when you close or reload it. None of it is written to cookies or storage.

5. Analytics Cookies (Only With Your Consent)

We use Google Analytics 4 to understand which pages are useful and how visitors reach the site. Analytics is opt-in. The Google Analytics script is not loaded, and no _ga cookie is set, until you press Allow analytics. Declining, closing the notice or simply ignoring it all leave analytics off, and the generator works exactly the same either way.

When analytics is allowed, Google Analytics receives your browser and device type, the pages you visit, the referring site and an approximate location derived from your IP address. Google Analytics 4 does not log or store IP addresses. It never receives the content of your QR codes. More detail, including how long analytics data is kept, is in sections 3 and 7 of the Privacy Policy.

If your browser sends a Global Privacy Control signal, we treat it as a decline. We do not show the consent notice and do not load analytics unless you later choose otherwise.

6. Other Third-Party Requests

The site's typefaces (Archivo, IBM Plex Sans and IBM Plex Mono) are served by Google Fonts. When a page loads, your browser requests the font files from fonts.googleapis.com and fonts.gstatic.com. Like any web request, this passes your IP address and browser details to Google so the files can be delivered. Google Fonts does not set cookies. If a font request is blocked, the page falls back to your device's own fonts and keeps working.

The site loads no other third-party scripts, widgets or embeds. Links to external sites, such as the official browser help pages below, are ordinary links. Those sites have their own cookie policies, which apply once you visit them.

7. How to Control Cookies

On this site: use Privacy choices at the foot of any page, or this button: . You can allow or decline analytics, and change your mind as often as you like. When you withdraw consent, the site stops sending analytics data straight away and deletes the _ga cookies it can reach.

In your browser: every major browser lets you view, block and delete cookies and site data. Blocking all cookies does not stop the generator from working. Official guides:

Google Analytics opt-out: Google also offers a browser add-on that stops Google Analytics on every site you visit.

8. The Laws We Follow

We ask for consent before setting non-essential cookies because the laws in our main markets require it. Consent must be freely given, specific, informed and unambiguous, given by a clear affirmative action, and as easy to withdraw as to give. That applies under India's Digital Personal Data Protection Act, 2023 (sections 5 and 6), the EU General Data Protection Regulation together with Article 5(3) of the ePrivacy Directive, and the UK GDPR with the Privacy and Electronic Communications Regulations. For visitors in California, we do not sell or share personal information under the CCPA/CPRA, and we honour Global Privacy Control signals.

9. Changes to This Policy

We will update this policy whenever we change what the site stores. That includes adding a new cookie or provider, or changing a retention period. The date at the top of the page shows when it last changed. If a change needs new consent, for example a new category of cookie, we will ask again through the consent notice rather than assume your earlier answer covers it.

10. Contact

Questions about this Cookie Policy can go to support@qr-code.love or through the Contact page. For requests about your personal data, including grievances under the DPDP Act, see section 7 of the Privacy Policy.