Privacy Policy
Effective Date: August 22, 2026 | Last Updated: September 25, 2026
1. Introduction & Core Commitment
At qr-code.love (accessible at https://qr-code.love), your privacy is our highest priority. We operate a strictly client-side static QR code generator. This Privacy Policy document outlines the types of information that are collected and recorded by qr-code.love, how we use it, and your rights regarding data protection and cookies.
If you have additional questions or require more information about our Privacy Policy, do not hesitate to contact us through our Contact Page.
2. 100% Client-Side QR Generation Architecture
Unlike traditional online QR code generators, qr-code.love executes all barcode calculations, Reed-Solomon polynomial math, canvas rasterization, and vector SVG generation entirely inside your device's web browser using client-side JavaScript.
- No Payload Transmission: Your input data (such as destination URLs, text messages, vCard contact information, phone numbers, SMS text, email addresses, and WiFi network passwords) is never transmitted to our web servers, third-party APIs, or remote databases.
- No Server Logs of QR Data: We do not log, inspect, store, intercept, or monetize the content of your QR codes.
- Local File Reading for Logos: When you upload a custom logo or brand icon, it is processed locally in your browser memory via the HTML5
FileReaderAPI. No image files are uploaded to our hosting servers.
3. Web Analytics & Your Consent
We use Google Analytics 4 (GA4) to count visits and see which pages are useful. Analytics is off by default. The Google Analytics script is not loaded and no analytics cookie is set until you press Allow analytics in the consent notice. If you press Decline, close the notice or ignore it, analytics stays off and every part of the generator works exactly the same.
If you allow it, Google Analytics collects:
- Browser type, operating system, device type and screen resolution.
- The referring website, pages visited and time spent on them.
- An approximate location (country or city) that Google works out from your IP address. Google Analytics 4 does not log or store IP addresses.
- A random identifier stored in a cookie, so that repeat visits can be counted.
- Feature counts that carry no content, such as how many downloads were PNG and how many were SVG.
What is never sent: the content of your QR codes, including URLs, WiFi passwords, phone numbers and contact details, and any logo you upload. Advertising signals (Google Consent Mode ad_storage, ad_user_data and ad_personalization) are always set to denied.
Cookies set only after you allow analytics:
_ga: distinguishes visitors (Google Analytics, expires after 2 years)._ga_<ID>: keeps session state (Google Analytics, expires after 2 years).
Withdrawing consent: you can change your choice at any time, and withdrawing is as easy as giving consent. Use the Privacy choices link at the foot of every page, or this button: . When you withdraw, the site stops sending data straight away and deletes the _ga cookies it can reach. Withdrawing does not affect data processed before you withdrew.
Global Privacy Control: if your browser sends a Global Privacy Control signal, we treat it as a decline. We do not show the notice, and analytics stays off unless you choose otherwise under Privacy choices.
4. Local Browser Storage (localStorage)
qr-code.love uses your browser's native localStorage API exclusively to remember non-sensitive user interface preferences, specifically:
sqr_theme_pref: Saves your preference for Dark Mode or Light Mode across browser sessions.sqr_consent: Records your analytics choice (allowed or declined) and the date and time you made it, so we do not ask again on every page and can show you your current choice.
This data never leaves your browser and can be cleared at any time through your browser's cache settings.
5. GDPR Privacy Rights (For European Economic Area & UK Users)
Under the General Data Protection Regulation (GDPR), users residing in the European Union and the United Kingdom are entitled to the following data protection rights:
- The right to access: You have the right to request copies of your personal data.
- The right to rectification: You have the right to request that we correct any information you believe is inaccurate.
- The right to erasure ("Right to be Forgotten"): You have the right to request that we erase your personal data under certain conditions. (Because we do not store your QR content, no personal QR data exists on our servers to erase).
- The right to restrict processing: You have the right to request that we restrict the processing of your personal data.
- The right to object to processing: You have the right to object to our processing of your personal data.
- The right to data portability: You have the right to request that we transfer data we have collected to another organization.
If you make a request, we have one month to respond to you. If you wish to exercise any of these rights, please contact us.
6. CCPA / CPRA Privacy Rights (For California Residents)
Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California consumers have specific rights regarding their personal information:
- Right to Know: You have the right to request disclosures regarding the categories and specific pieces of personal data collected about you.
- Right to Delete: You have the right to request deletion of personal information collected from you.
- Right to Opt-Out of Sale or Sharing: qr-code.love does not sell or share personal information, and the site shows no advertising, so there is no cross-context behavioural advertising to opt out of. We also honour Global Privacy Control signals.
- Right to Non-Discrimination: We will not discriminate against you in pricing, service quality, or functionality for exercising your privacy rights.
7. India: Digital Personal Data Protection Act, 2023
This section is our notice under the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the Digital Personal Data Protection Rules, 2025. It applies to you as a Data Principal if you use qr-code.love in India, and to digital personal data we process in connection with offering the site to people in India. The operator of qr-code.love is the Data Fiduciary. Google acts as our Data Processor for analytics.
7.1 What personal data we process, and why
- QR code content: not collected. Everything you type into the generator, and any logo you upload, is processed only on your own device. It never reaches us, so we hold none of it and cannot access, share or lose it.
- Analytics data, only with your consent. A cookie identifier, device and browser details, pages visited and an approximate location, as described in section 3. Purpose: to measure overall site traffic and find out which pages are useful. Basis: your consent (section 6 of the DPDP Act). Retention: no longer than 14 months, the longest period Google Analytics offers for this data, after which it is deleted automatically.
- Messages you send us. If you email us, including through the contact page, we receive your email address, your name if you give it, and your message. Purpose: to reply to you. Basis: you provided the data voluntarily for that purpose (legitimate use under section 7(a) of the DPDP Act). Retention: until your query is resolved, then deleted unless the law requires us to keep it.
7.2 How we ask for consent
Where we rely on consent, it must be free, specific, informed, unconditional and unambiguous, and given by a clear affirmative action. That is why analytics is off until you press Allow analytics. There are no pre-ticked boxes, and staying on the page or scrolling is never treated as consent. Decline is offered with the same prominence as Allow, and declining never limits what the generator can do. We ask only for the data needed for the stated purpose.
You may withdraw consent at any time, as easily as you gave it, from Privacy choices at the foot of every page or with the button in section 3. After you withdraw, we stop processing, and have our Data Processor stop processing, within a reasonable time. Withdrawal does not affect the lawfulness of processing done before it. Once a Consent Manager registered with the Data Protection Board of India is available, you may also give, manage, review or withdraw consent through it.
7.3 Your rights as a Data Principal
- Right to access information (section 11): a summary of the personal data we process about you and of the processing activities, and the identities of the Data Fiduciaries and Data Processors we have shared it with, together with a description of the data shared.
- Right to correction and erasure (section 12): to have your personal data corrected, completed or updated, and to have it erased once it is no longer needed for the purpose, unless the law requires us to keep it.
- Right to grievance redressal (section 13): a readily available way to raise a complaint with us about how we process your data, and a response from us.
- Right to nominate (section 14): to nominate another individual to exercise your rights if you die or become incapable.
Analytics data is linked only to a random cookie identifier, not to your name. To act on a request about it, we may need that identifier from your browser. Often the quickest route is to withdraw consent and clear this site's cookies yourself. We may ask for reasonable information to confirm your identity before acting on a request, so that we never disclose or erase someone else's data.
7.4 Grievances and the Data Protection Board of India
To exercise a right or raise a grievance, email support@qr-code.love with the subject "DPDP request" or "Grievance". This address reaches the person who can answer questions about our processing of personal data on behalf of the Data Fiduciary. We will respond within the time limit set by the DPDP Rules, 2025. If you are not satisfied once our grievance process is complete, you may complain to the Data Protection Board of India.
7.5 Children and persons with disability
Under the DPDP Act, a child is anyone under 18. The site is a general-purpose tool and is not directed at children. We do not knowingly process a child's personal data, and we do not track, behaviourally monitor or target advertising at children. If you are under 18, please do not allow analytics unless your parent or lawful guardian has given verifiable consent. The same applies to a person with a disability who has a lawful guardian. If you believe we have processed a child's data, contact us and we will delete it.
7.6 Security, breaches and transfers
We protect the data we handle with reasonable security safeguards, including HTTPS on every page and a Content Security Policy. Keeping QR content on your device means there is no store of it to breach. If a personal data breach occurs, we will inform the Data Protection Board of India and each affected Data Principal in the form and within the time the DPDP Rules, 2025 require. Analytics data is processed by Google, which may store it on servers outside India. Section 16 of the DPDP Act permits such transfers except to countries the Central Government has restricted by notification.
7.7 Your duties and language of this notice
Section 15 of the DPDP Act asks Data Principals not to impersonate another person, not to suppress material information, not to register false or frivolous grievances or complaints, and to give only verifiably authentic information when asking for a correction or erasure. This notice is in English. You may ask for it in any language listed in the Eighth Schedule to the Constitution of India by emailing us.
8. Managing and Disabling Cookies in Your Browser
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. Follow the official guides below to manage cookies in your browser:
9. Children's Privacy (COPPA Compliance)
qr-code.love does not knowingly collect any Personal Identifiable Information from children under the age of 13. If a parent or guardian believes that qr-code.love has inadvertently collected personal information of a child, please contact us immediately and we will promptly remove such information from our records.
10. Changes to This Privacy Policy
We may update our Privacy Policy from time to time to reflect changes in legal requirements or platform enhancements. We advise you to review this page periodically for any updates. Changes are effective immediately upon posting on this page.
11. What the Site Stores in Your Browser
The site sets at most two items in your browser's local storage. sqr_theme_pref records whether you chose the light or dark theme. It is written only when you use the theme switch, contains nothing but that word, and is removed when you clear the site's data. sqr_consent records your analytics choice and when you made it. It is written only when you press Allow analytics or Decline. Neither item is sent to us.
Logo files you select are read into memory by the page and drawn onto the preview. They are not uploaded, not written to storage, and are discarded when you close or reload the page. Form contents are held in memory in the same way and leave your device only inside the file you choose to download.
12. Contacting Our Data Privacy Team
If you have any questions, inquiries, or feedback concerning this Privacy Policy, please reach out via our dedicated Contact Page.