Privacy Policy
Last updated: July 5, 2026
1. Introduction
AQRHub ("we", "us", "our") operates aqrhub.com. This policy explains what data we collect, how we use it, and your rights.
2. Information We Collect
Account data
- Email address
- First name (optional)
- Password (hashed, never stored in plain text)
Payment data
Payments are processed by Stripe. AQRHub does not store credit card numbers. Stripe's privacy policy applies to payment data.
QR code scan data
When someone scans your QR code we collect and store the scanner's IP address, along with device type, browser, operating system, referrer, and timestamp. We use the IP address to derive an approximate location (country, region, city) through a third-party IP geolocation service (IPinfo), and to help distinguish real scans from bots and automated traffic in your analytics. An IP address can be considered personal data under some privacy laws.
Scan analytics are reported in aggregate. AQRHub does not attempt to identify the individual person who scanned a QR code.
QR code content
We store the content you encode into your QR codes, including destination URLs and any data you place in them (for example vCard, WiFi, SMS, or email payloads). Destination URLs may be checked against Google Safe Browsing to protect users from malicious links.
Log and abuse-prevention data
To protect the Service we log certain events, such as contact-form submissions and blocked URLs, together with the sender's IP address and the submitted content. We use reCAPTCHA and Cloudflare Turnstile to detect bots on our forms.
Usage data
We use Google Analytics to understand how visitors use AQRHub, such as which pages are visited, how long people stay, the type of device and browser, and general geographic region. This information is aggregated and helps us improve the product. We do not use Google Analytics to identify individual visitors.
First-party product analytics
We also record limited first-party product events, such as when a QR code is created or when certain features are used. These events help us improve AQRHub, troubleshoot issues, and understand which features are most valuable. This information is not sold or shared with advertisers.
Authentication
If you sign in with Google we receive your name, email address, and profile picture from Google.
3. How We Use Your Data
- To provide and improve the Service
- To send transactional emails (welcome, password reset, billing notifications)
- To display scan analytics in your dashboard
- We do not sell your personal information or share it with advertisers
4. Data Retention
We retain your account data for as long as your account is active. QR code scan data, including scanner IP addresses and derived location, is retained for as long as the associated QR code exists so that it can power your analytics dashboard. We do not currently apply a fixed expiry to scan data, so it is retained indefinitely by default until the QR code or account is deleted. Unverified, abandoned free accounts are automatically deleted after 7 days. You may request deletion of your account and data by emailing support@aqrhub.com
5. Cookies
AQRHub uses cookies in two categories:
- Strictly necessary cookies that keep you signed in and protect against cross-site request forgery. These are set by AQRHub itself and cannot be turned off without breaking core functionality of the site.
- Analytics cookies set by Google Analytics on our public pages for the analytics purposes described under Usage data above.
Most browsers let you block or delete cookies from the browser settings. Blocking analytics cookies will not affect your ability to use the Service.
6. Third Party Services and Subprocessors
We share data with the following third party services in order to operate AQRHub. Each receives only the data needed for its function:
- Stripe: payment processing. Receives your billing details; card numbers are handled by Stripe and never stored by AQRHub (stripe.com/privacy).
- Render: cloud hosting and database. Stores the application data described in this policy.
- Cloudflare: content delivery, security, image and file storage (R2), and custom-domain routing for our servers. As our edge network it processes visitor requests, including IP addresses.
- IPinfo: IP geolocation. Receives scanner IP addresses to return approximate location (ipinfo.io/privacy-policy).
- Google Analytics: site usage analytics on our public pages, as described under Usage data above.
- Google OAuth: optional sign-in method. Provides us your name, email address, and profile picture when you choose to sign in with Google.
- Google Safe Browsing: URL safety checks. Receives QR code destination URLs to screen for malicious links.
- Google reCAPTCHA and Cloudflare Turnstile: bot and abuse protection on our forms. Receive request and token data, including IP address.
- AWS SES (Amazon Simple Email Service): sends transactional email (verification, password reset, billing, and support messages) from support@aqrhub.com. Receives recipient email addresses and message content.
We do not sell your personal information or share it with advertisers.
7. Children's Privacy
AQRHub is not directed at children under 13. We do not knowingly collect data from children under 13.
8. Your Rights
You may request access to, correction of, or deletion of your personal data at any time by emailing support@aqrhub.com
9. Security
We use HTTPS encryption and store passwords using secure hashing. We take reasonable measures to protect your data but cannot guarantee absolute security.
10. Changes to This Policy
We may update this policy at any time. We will notify users of significant changes by email.
11. Contact
Questions about this policy? Email us at support@aqrhub.com