Privacy Policy

Last updated August 8, 2026

1. Who we are

QRPixel ("QRPixel", "we", "us") operates qrpixel.net, a link-in-bio, scheduling and QR code service. This policy explains what personal data we collect, why, how long we keep it, and the choices you have. It applies to everyone who uses QRPixel — account holders ("hosts") and the visitors who view a host's page or book time with them.

2. Data we collect

Account data. Name, email address, password (stored as a salted hash, never in plain text), and profile details you add — headline, bio, avatar photo, links, theme, and your event-scheduling preferences.

Booking data. When someone books time with a host, we store the invitee's name, email, any notes they leave, and answers to any custom questions the host has configured.

Prospect / contact-exchange data. Premium hosts can enable a "Save Contact" exchange on their page — if a visitor chooses to use it, we store the name, email and phone number they submit.

Usage & analytics data. With your consent (see Section 5), we record page views along with a one-way hashed visitor identifier, coarse device/browser/OS type, referrer and country. We never store your raw IP address or a reversible identifier — the hash cannot be turned back into your IP. Link clicks, QR code scans and bookings are recorded as basic usage counters regardless of the analytics consent choice, since they reflect the host's own content being used, not passive visitor surveillance.

Billing data. Subscription payments are handled entirely by Paddle, our payment processor and Merchant of Record. We never see or store your card number — we only receive your subscription status and billing period from Paddle.

Calendar data (optional). If you connect Google Calendar, we request only the narrow scopes needed to create/update booking events and check your free/busy status — never full calendar read access.

Referral / affiliate data. Every account gets its own referral link. If you sign up after using one (see Section 5 for how this is tracked), we record which account referred you and, one level up, who referred them, so commissions can be calculated on your future purchases. We don't collect anything extra about you for this — just the link between accounts. See our Terms of Service for how the affiliate program itself works.

3. How we use your data

  • To provide the service — hosting your page, processing bookings, sending confirmation emails, rendering QR codes.
  • To operate your subscription and billing, via Paddle.
  • To keep the service secure — detecting abuse, enforcing rate limits, preventing double-bookings.
  • To show you basic usage stats about your own page (views, clicks, scans, bookings).
  • To respond to support requests you send us.

We do not sell your personal data, and we do not use it for third-party advertising or ad targeting. Google Analytics (Section 5) is used only for aggregate usage insights, never to build an ad profile of you.

4. Who we share it with

We share data only with the service providers ("processors") needed to run QRPixel:

  • Paddle — payment processing and billing (Merchant of Record for subscriptions).
  • SendGrid — transactional email delivery (booking confirmations, requests, declines).
  • Google (sign-in & calendar) — OAuth sign-in and, if you opt in, Calendar sync.
  • Google (analytics) — if you accept analytics cookies, Google Tag Manager and Google Analytics receive aggregated visit data (pages viewed, coarse device/traffic-source info) to help us understand site usage. See Section 5.
  • Our hosting and database infrastructure providers, who store data on our behalf under contract and don't use it for their own purposes.

A host's public page is, by design, publicly visible — anything you choose to put on it (bio, links, event types) is shown to anyone who visits your qrpixel.net/username URL.

5. Cookies & analytics

We use Google Tag Manager to manage the scripts that run on qrpixel.net, and Google Analytics to understand how visitors use the site — pages viewed, general traffic sources, and coarse device/location data. Neither loads until you accept the cookie banner shown on first visit; if you decline, no Google Tag Manager container and no Google Analytics script are loaded at all. Google Analytics sets its own cookies to distinguish visitors across sessions and, per Google's terms, may process this data on servers outside your country — see Google's Privacy Policy for how Google handles it. You can change your mind any time via the "Cookie preferences" link in the footer.

Referral cookie. If you arrive via someone's affiliate link, we set a short first-party cookie (qp_ref) holding only that referral code — never anything that identifies you — so we can credit the right account if you go on to register. It's kept for up to 30 days (shown on the link at the time you use it) or until you sign up, whichever comes first. Unlike the analytics cookies above, this one is set automatically rather than gated behind the cookie banner, since it exists to make the affiliate program itself work rather than to analyze your behavior — it isn't used for advertising, isn't shared with anyone, and doesn't track you across other sites. It's simply discarded if you never create an account.

Besides the above and the local storage that keeps you signed in (which the service can't function without), we don't set any other tracking cookies.

6. How we protect your data

We apply the following safeguards to sensitive data, including passwords, authentication credentials, and payment-related information:

  • Encryption in transit. All connections to qrpixel.net and our API are encrypted with HTTPS/TLS — we don't accept unencrypted connections.
  • Password hashing. Passwords are never stored in plain text. We store a salted, one-way bcrypt hash that cannot be reversed back into your password, even by us.
  • Encryption at rest. Our database and file storage run on infrastructure providers that encrypt data at rest at the storage layer.
  • Restricted-access fields. Especially sensitive fields — two-factor authentication secrets, 2FA recovery codes, and Google Calendar access tokens — are stored in a way that's excluded from our API responses by default and only ever read by the specific server-side process that needs them (e.g. verifying a 2FA code), never returned to the client or any other part of the app.
  • No card data on our servers. We never receive, transmit, or store your card or bank details. Payments are handled entirely by Paddle, our PCI-DSS compliant payment processor and Merchant of Record; we only receive your subscription status back from them.
  • Access control. Regular user accounts can only access their own data. Administrative access to other users' data is limited to a small number of authorized administrator accounts, separate from normal sign-in, and is used only for support, abuse prevention, and account management.
  • Data minimization. We collect only the data described in Section 2, and Google Calendar access is limited to the narrow scopes needed for booking sync — never full calendar read access.
  • Breach notification. If a data breach affecting your personal data occurs, we will notify affected users and relevant authorities as required by applicable law.

7. Data retention

  • Account and profile data is kept for as long as your account is active.
  • Analytics events are retained for 7 days on the Free plan and 365 days on Premium, then automatically age out.
  • Booking records are kept as part of your host's booking history until you or the host request deletion.
  • Referral attribution (which account referred you, if any) and the resulting commission records are kept for as long as your account exists, for accounting purposes.
  • If you delete your account, we remove your profile, links, bookings, QR codes, uploaded files, and any commissions tied to your account; accounts you referred simply keep no further record of you as their referrer.
  • Contact us to request account deletion — see Section 10.

8. Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Request deletion of your data ("right to be forgotten").
  • Export your data in a portable format.
  • Object to or restrict certain processing.
  • Withdraw analytics consent at any time (Section 5).
  • Lodge a complaint with your local data protection authority.

To exercise any of these rights, email [email protected].

9. International transfers

Our infrastructure and service providers may process data outside your home country. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for these transfers.

10. Contact

Questions about this policy or how your data is handled: [email protected].

11. Changes to this policy

We'll update the "Last updated" date above whenever this policy changes, and post material changes here before they take effect.