Legal & Transparency

Privacy Policy

Effective Date: August 22, 2026 | Last Updated: September 25, 2026

1. Introduction & Core Commitment

At qr-code.love (accessible at https://qr-code.love), your privacy is our highest priority. We operate a strictly client-side static QR code generator. This Privacy Policy document outlines the types of information that are collected and recorded by qr-code.love, how we use it, and your rights regarding data protection and cookies.

If you have additional questions or require more information about our Privacy Policy, do not hesitate to contact us through our Contact Page.

2. 100% Client-Side QR Generation Architecture

Unlike traditional online QR code generators, qr-code.love executes all barcode calculations, Reed-Solomon polynomial math, canvas rasterization, and vector SVG generation entirely inside your device's web browser using client-side JavaScript.

  • No Payload Transmission: Your input data (such as destination URLs, text messages, vCard contact information, phone numbers, SMS text, email addresses, and WiFi network passwords) is never transmitted to our web servers, third-party APIs, or remote databases.
  • No Server Logs of QR Data: We do not log, inspect, store, intercept, or monetize the content of your QR codes.
  • Local File Reading for Logos: When you upload a custom logo or brand icon, it is processed locally in your browser memory via the HTML5 FileReader API. No image files are uploaded to our hosting servers.

4. Local Browser Storage (localStorage)

qr-code.love uses your browser's native localStorage API exclusively to remember non-sensitive user interface preferences, specifically:

  • sqr_theme_pref: Saves your preference for Dark Mode or Light Mode across browser sessions.
  • sqr_consent: Records your analytics choice (allowed or declined) and the date and time you made it, so we do not ask again on every page and can show you your current choice.

This data never leaves your browser and can be cleared at any time through your browser's cache settings.

5. GDPR Privacy Rights (For European Economic Area & UK Users)

Under the General Data Protection Regulation (GDPR), users residing in the European Union and the United Kingdom are entitled to the following data protection rights:

  • The right to access: You have the right to request copies of your personal data.
  • The right to rectification: You have the right to request that we correct any information you believe is inaccurate.
  • The right to erasure ("Right to be Forgotten"): You have the right to request that we erase your personal data under certain conditions. (Because we do not store your QR content, no personal QR data exists on our servers to erase).
  • The right to restrict processing: You have the right to request that we restrict the processing of your personal data.
  • The right to object to processing: You have the right to object to our processing of your personal data.
  • The right to data portability: You have the right to request that we transfer data we have collected to another organization.

If you make a request, we have one month to respond to you. If you wish to exercise any of these rights, please contact us.

6. CCPA / CPRA Privacy Rights (For California Residents)

Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California consumers have specific rights regarding their personal information:

  • Right to Know: You have the right to request disclosures regarding the categories and specific pieces of personal data collected about you.
  • Right to Delete: You have the right to request deletion of personal information collected from you.
  • Right to Opt-Out of Sale or Sharing: qr-code.love does not sell or share personal information, and the site shows no advertising, so there is no cross-context behavioural advertising to opt out of. We also honour Global Privacy Control signals.
  • Right to Non-Discrimination: We will not discriminate against you in pricing, service quality, or functionality for exercising your privacy rights.

7. India: Digital Personal Data Protection Act, 2023

This section is our notice under the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the Digital Personal Data Protection Rules, 2025. It applies to you as a Data Principal if you use qr-code.love in India, and to digital personal data we process in connection with offering the site to people in India. The operator of qr-code.love is the Data Fiduciary. Google acts as our Data Processor for analytics.

7.1 What personal data we process, and why

  • QR code content: not collected. Everything you type into the generator, and any logo you upload, is processed only on your own device. It never reaches us, so we hold none of it and cannot access, share or lose it.
  • Analytics data, only with your consent. A cookie identifier, device and browser details, pages visited and an approximate location, as described in section 3. Purpose: to measure overall site traffic and find out which pages are useful. Basis: your consent (section 6 of the DPDP Act). Retention: no longer than 14 months, the longest period Google Analytics offers for this data, after which it is deleted automatically.
  • Messages you send us. If you email us, including through the contact page, we receive your email address, your name if you give it, and your message. Purpose: to reply to you. Basis: you provided the data voluntarily for that purpose (legitimate use under section 7(a) of the DPDP Act). Retention: until your query is resolved, then deleted unless the law requires us to keep it.

7.2 How we ask for consent

Where we rely on consent, it must be free, specific, informed, unconditional and unambiguous, and given by a clear affirmative action. That is why analytics is off until you press Allow analytics. There are no pre-ticked boxes, and staying on the page or scrolling is never treated as consent. Decline is offered with the same prominence as Allow, and declining never limits what the generator can do. We ask only for the data needed for the stated purpose.

You may withdraw consent at any time, as easily as you gave it, from Privacy choices at the foot of every page or with the button in section 3. After you withdraw, we stop processing, and have our Data Processor stop processing, within a reasonable time. Withdrawal does not affect the lawfulness of processing done before it. Once a Consent Manager registered with the Data Protection Board of India is available, you may also give, manage, review or withdraw consent through it.

7.3 Your rights as a Data Principal

  • Right to access information (section 11): a summary of the personal data we process about you and of the processing activities, and the identities of the Data Fiduciaries and Data Processors we have shared it with, together with a description of the data shared.
  • Right to correction and erasure (section 12): to have your personal data corrected, completed or updated, and to have it erased once it is no longer needed for the purpose, unless the law requires us to keep it.
  • Right to grievance redressal (section 13): a readily available way to raise a complaint with us about how we process your data, and a response from us.
  • Right to nominate (section 14): to nominate another individual to exercise your rights if you die or become incapable.

Analytics data is linked only to a random cookie identifier, not to your name. To act on a request about it, we may need that identifier from your browser. Often the quickest route is to withdraw consent and clear this site's cookies yourself. We may ask for reasonable information to confirm your identity before acting on a request, so that we never disclose or erase someone else's data.

7.4 Grievances and the Data Protection Board of India

To exercise a right or raise a grievance, email support@qr-code.love with the subject "DPDP request" or "Grievance". This address reaches the person who can answer questions about our processing of personal data on behalf of the Data Fiduciary. We will respond within the time limit set by the DPDP Rules, 2025. If you are not satisfied once our grievance process is complete, you may complain to the Data Protection Board of India.

7.5 Children and persons with disability

Under the DPDP Act, a child is anyone under 18. The site is a general-purpose tool and is not directed at children. We do not knowingly process a child's personal data, and we do not track, behaviourally monitor or target advertising at children. If you are under 18, please do not allow analytics unless your parent or lawful guardian has given verifiable consent. The same applies to a person with a disability who has a lawful guardian. If you believe we have processed a child's data, contact us and we will delete it.

7.6 Security, breaches and transfers

We protect the data we handle with reasonable security safeguards, including HTTPS on every page and a Content Security Policy. Keeping QR content on your device means there is no store of it to breach. If a personal data breach occurs, we will inform the Data Protection Board of India and each affected Data Principal in the form and within the time the DPDP Rules, 2025 require. Analytics data is processed by Google, which may store it on servers outside India. Section 16 of the DPDP Act permits such transfers except to countries the Central Government has restricted by notification.

7.7 Your duties and language of this notice

Section 15 of the DPDP Act asks Data Principals not to impersonate another person, not to suppress material information, not to register false or frivolous grievances or complaints, and to give only verifiably authentic information when asking for a correction or erasure. This notice is in English. You may ask for it in any language listed in the Eighth Schedule to the Constitution of India by emailing us.

8. Managing and Disabling Cookies in Your Browser

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. Follow the official guides below to manage cookies in your browser:

9. Children's Privacy (COPPA Compliance)

qr-code.love does not knowingly collect any Personal Identifiable Information from children under the age of 13. If a parent or guardian believes that qr-code.love has inadvertently collected personal information of a child, please contact us immediately and we will promptly remove such information from our records.

10. Changes to This Privacy Policy

We may update our Privacy Policy from time to time to reflect changes in legal requirements or platform enhancements. We advise you to review this page periodically for any updates. Changes are effective immediately upon posting on this page.

11. What the Site Stores in Your Browser

The site sets at most two items in your browser's local storage. sqr_theme_pref records whether you chose the light or dark theme. It is written only when you use the theme switch, contains nothing but that word, and is removed when you clear the site's data. sqr_consent records your analytics choice and when you made it. It is written only when you press Allow analytics or Decline. Neither item is sent to us.

Logo files you select are read into memory by the page and drawn onto the preview. They are not uploaded, not written to storage, and are discarded when you close or reload the page. Form contents are held in memory in the same way and leave your device only inside the file you choose to download.

12. Contacting Our Data Privacy Team

If you have any questions, inquiries, or feedback concerning this Privacy Policy, please reach out via our dedicated Contact Page.