aiQRlink
Privacy

Privacy Policy

Your privacy matters to us. This policy explains what data we collect, how we use it, and the choices you have — clearly and without legal jargon.

Last updated: June 2026
~7 min read
GDPR Compliant · Anonymised Tracking · No data sold

Privacy at a Glance

We never sell your data

Anonymised click tracking

Encrypted data storage

Delete your data anytime

1. Who We Are

aiQRlink ("we," "us," or "our") is the data controller responsible for your personal information collected through our platform at https://yourdomain.com.

This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our website or use our services, including our QR code generator, short link manager, bio page builder, landing page builder, and AI analytics dashboard.

2. Data We Collect

Account & Profile Data

  • Name and email address
  • Profile photo (optional)
  • Password (stored hashed — never in plain text)
  • Billing address and payment method details (processed by Stripe / PayPal)
  • Account preferences and settings

Content You Create

  • QR codes and their destination URLs
  • Short link aliases and destination URLs
  • Bio page content, blocks, and themes
  • Landing page content, blocks, and themes
  • Custom domain names you connect

Usage & Analytics Data

  • Anonymised IP address (last octet masked by default)
  • Country and city (derived from IP — IP is not stored)
  • Device type, operating system, and browser
  • Scan and click timestamps
  • Referrer / traffic source
  • Pages visited within the platform

Technical Data

  • Log files (error and access logs, retained for 30 days)
  • Cookies and session tokens (see Cookies section)
  • API keys you generate

3. How We Use Your Data

We use the data we collect for the following purposes:

Providing the Service — To operate, maintain, and improve the Platform, including QR code generation, link routing, page rendering, and analytics.
Account Management — To create and manage your account, process payments, and send billing-related communications.
Transactional Emails — To send account verification, password reset, subscription confirmation, and invoice emails.
AI Insights — To generate natural-language analytics summaries based on aggregated scan and click data associated with your content.
Security & Fraud Prevention — To detect, investigate, and prevent fraudulent transactions, abuse, and security incidents.
Legal Compliance — To meet our legal obligations under applicable law, including GDPR and other data protection regulations.
Service Improvement — To analyse aggregated usage patterns and improve product features, performance, and reliability.

4. Data Sharing

We do not sell, rent, or trade your personal data to any third party for marketing purposes — ever.

We may share your data with trusted third-party service providers solely for the purpose of operating our platform:

Provider Purpose Data
Stripe Payment processing Billing info, card details
Mail provider (SMTP) Transactional emails Email address, name
Hosting / CDN Infrastructure & delivery Log data, files

We may also disclose your data when required by law, court order, or government authority, or to protect the rights, property, or safety of aiQRlink, our users, or the public.

5. Google Sign-In Data Collection

If you choose to sign in using Google or another third-party authentication provider, we may receive information such as your name, email address, profile image, and unique account identifier.

We use this information solely for authentication, account creation, account management, and security purposes.

We do not receive, access, or store your Google account password.

6. AI Provider Disclosure

Certain AI-powered features may process submitted content through third-party AI providers such as OpenAI, Claude, or Google Gemini, as configured by the Platform administrator.

Submitted content may be transmitted to these providers solely for the purpose of generating requested AI outputs and providing AI-powered functionality.

7. Data Retention Period

We retain personal information only for as long as necessary to provide services, comply with legal obligations, resolve disputes, and enforce agreements.

Account information may be retained after account deletion where required by law, regulatory requirements, fraud prevention purposes, or other legitimate business interests.

8. Cookies & Tracking

We use cookies and similar technologies to operate the Platform. Here is a breakdown:

Required

Essential Cookies

Required for login sessions, CSRF protection, and core functionality. Cannot be disabled.

Optional

Preference Cookies

Remember your settings, dark/light theme preference, and language.

Optional

Analytics Cookies

Track anonymised usage patterns to improve the Platform. No personal data is tied to these cookies.

You can manage cookie preferences through your browser settings. Note that disabling essential cookies will prevent you from logging in to the Platform.

9. Analytics & AI Insights

When someone scans your QR code or clicks your short link, we collect anonymised usage data including approximate location (country/city), device type, browser, and referrer. We do not collect or store the full IP address of scanners.

This data is associated with your account (not the scanner) and is used to populate your analytics dashboard with real-time statistics and AI-generated performance insights.

The AI Insights feature sends aggregated, anonymised analytics summaries to a language model to generate natural-language recommendations. No personally identifiable information (PII) is sent to any AI model.

10. Data Retention

We retain your data for as long as your account is active or as needed to provide the service. Specific retention periods:

Data Type Retention Period
Account data Until account deletion, then 90 days
QR codes, links, and pages Until deleted by user, then 90 days
Analytics / scan data Up to 2 years, aggregated after 12 months
Payment records 7 years (legal/tax obligation)
Server log files 30 days

11. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

Access

Request a copy of the personal data we hold about you.

Rectification

Request correction of inaccurate or incomplete data.

Deletion

Request deletion of your account and associated data ("right to be forgotten").

Restriction

Request that we restrict processing of your data in certain circumstances.

Portability

Request your data in a structured, machine-readable format.

Objection

Object to processing based on legitimate interests or for direct marketing.

To exercise any of these rights, please contact us using the details in the Contact section below. We will respond within 30 days.

12. Security

We implement industry-standard security measures to protect your data, including:

  • TLS/SSL encryption for all data in transit.
  • Encrypted storage of sensitive data at rest.
  • Hashed and salted passwords — never stored in plain text.
  • Regular security audits and dependency updates.
  • Restricted access to production systems — only authorised personnel.

While we strive to protect your data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.

13. Third-Party Links

The Platform may contain links to external websites, services, or resources not operated by us. We have no control over the content or privacy practices of those sites and are not responsible for their privacy policies.

We strongly encourage you to review the privacy policy of any external website you visit.

14. Children's Privacy

aiQRlink is not directed to or intended for use by children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately and we will take steps to delete it.

15. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. When we do, we will update the "Last updated" date at the top of this page.

For material changes, we will notify registered users via email or an in-app notification at least 14 days before the change takes effect. Your continued use of the Platform after the effective date constitutes acceptance of the revised policy.

16. Contact Us

If you have any questions, concerns, or wish to exercise your data rights, please get in touch — we aim to respond within 2 business days.

Privacy Email

privacy@yourdomain.com

Website

https://yourdomain.com