Privacy policy

Information on how your personal data is processed under the Swiss Data Protection Act (revDPA) and the EU General Data Protection Regulation (GDPR).

1. Controller

The controller for data processing within QRown is:

QRown

Flugbrunnenstrasse 430

3065 Bolligen

Schweiz

Data protection email: info@qrown.io

2. What data we collect

2.1 Account data

When you register we collect:

  • Email address (required for login and communication)
  • First and last name (optional, can be changed in your profile at any time)
  • Password (stored as a bcrypt hash, never in plain text)
  • Company name and language (optional)
  • Preferred invoice currency (CHF / EUR)
  • Billing address (optional; it appears on your invoices and is synchronised with Stripe so that it is also correct on Stripe receipts)

2.2 QR code content

When you create QR codes we store:

  • QR content (URLs, text, vCards, Wi-Fi data and more)
  • Design and branding settings
  • Uploaded files (logos, images, PDFs for file uploads)

2.3 Scan analytics (dynamic QR codes only)

Each time a dynamic QR code is scanned we record:

  • Timestamp of the scan
  • IP address — anonymised immediately (last octet for IPv4, last 80 bits for IPv6); only the anonymised form is stored or used to determine location
  • Approximate location based on the anonymised IP: country, region/city and approximate coordinates at city level — not the GPS position of your device (the device's location services are never accessed)
  • The browser's user agent string and the device type, operating system and browser family derived from it
  • Preferred browser language (Accept-Language) and referrer (where available)

Static QR codes are decoded directly by the device and generate no server logs. When a code is scanned, a technically necessary session cookie is set to avoid double counting. Individual scan records are deleted after 90 days (see clause 7).

Allocation of roles: Where we provide scan statistics on behalf of the person who created the QR code, we process this data as a processor (Art. 28 GDPR); for the purposes of security, abuse prevention and running the platform we are an independent controller. Business customers who need a data processing agreement should contact the address given in clause 1.

2.4 Technical data

When you visit the website the following is recorded automatically:

  • Server logs (IP, date, time, URL requested, status code)
  • Browser type and version, operating system
  • Language settings used to select the interface language

2.5 Payment data

Credit card and bank details are processed exclusively by Stripe and are never stored on our servers (PCI-DSS Level 1). We only store the Stripe customer ID, the invoice amount, the currency, the payment status and — if you have provided it — your billing address for the invoice PDFs.

2.6 Teams and invitations

If a user invites you to a team by email, we store your email address solely in order to deliver the invitation. The invitation email tells you where your data came from (Art. 14 GDPR). If you do not accept the invitation, the address is deleted automatically after 7 days; if you decline, immediately. Team activity is logged with an anonymised IP and deleted after 180 days.

2.7 Bulk creation (bulk import)

For bulk imports via CSV file (for example vCard contact data) the uploaded file is deleted immediately after processing; the content is assigned to the customer's newly created QR codes. The customer is responsible as controller for the lawfulness of any third-party data uploaded; QRown processes it as a processor solely in order to create the QR codes.

2.8 File downloads via QR codes

When a file shared via a QR code is downloaded we log the anonymised IP address, the user agent, the approximate location (country/city) and the time, in order to provide the creator with download statistics and to detect misuse.

2.9 Abuse reports and URL security checks

Abuse reports submitted through our reporting form are stored with a pseudonymised IP (hash) for 12 months. We check the destination URLs of dynamic QR codes automatically for phishing and malware (see clause 6.7) in order to protect people who scan our QR codes.

3. Purposes of processing

  • Providing and running the QR code generator and the management platform
  • Authentication and administration of your user account
  • Providing scan statistics for dynamic QR codes
  • Handling payments, invoicing and accounting
  • Service-related communication (email verification, invoices, support)
  • Optional marketing communication (only with your express consent)
  • Security (abuse detection, spam protection, audit logs)
  • Legal obligations (in particular commercial and tax retention requirements)

5. Cookies and tracking

We use cookies and similar technologies (local storage). Cookies are small text files that your browser stores on your device.

5.1 Necessary cookies

Required in order to run the site (session cookie after login, CSRF token, cookie consent, selected language and currency). Legal basis: Art. 6(1)(f) GDPR. They cannot be rejected without impairing the functioning of the website.

5.2 Analytics cookies (optional) — Google Analytics 4

With your express consent given through the cookie banner we use Google Analytics 4 (Google Ireland Limited, Dublin; parent company Google LLC, USA) in order to understand how our website is used. Cookies such as _ga and _ga_* are set. Google Analytics 4 does not log or store IP addresses; in addition we send the IP truncation signal. Without consent no Google script is loaded. Consent can be withdrawn at any time on the Cookie settings page (also linked in the footer).

Data transfer to the USA on the basis of standard contractual clauses and the EU-US Data Privacy Framework.

We log your consent decision (granting, change, withdrawal) on the server with an anonymised IP as evidence under Art. 7(1) GDPR (retention: 3 years). If this policy changes materially, the cookie banner is shown again.

6. Third parties

6.1 Stripe (payment processing)

Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Stripe receives your name, email address, billing address, payment method and amount. Card and bank details are processed exclusively on PCI-DSS certified Stripe infrastructure and are never passed on to QRown. Data transfer to the USA is based on the EU standard contractual clauses and the EU-US Data Privacy Framework.

DPA: stripe.com/legal/dpa, Privacy policy: stripe.com/privacy.

6.2 Infomaniak (hosting and email)

Infomaniak Network SA, Rue Eugène-Marziano 25, 1227 Les Acacias, Switzerland. Hosts our servers and sends transactional emails (verification, invoices, password reset). Data stays exclusively in Switzerland.

Privacy policy: infomaniak.com/legal.

6.3 Google OAuth (optional sign-in)

If you choose to sign in with Google, your email address, name, Google user ID and profile picture URL are passed to QRown. No access to Drive, Gmail or Calendar is requested. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company Google LLC, USA). Data transfer on the basis of standard contractual clauses and the EU-US Data Privacy Framework.

Privacy: policies.google.com/privacy.

6.4 Brevo (newsletter delivery)

We send our newsletter through Brevo (Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France; servers in the EU). Brevo receives your email address, language and delivery events (bounce, unsubscribe, open/click for deliverability measurement). Legal basis: your consent (Art. 6(1)(a) GDPR, double opt-in). A data processing agreement under Art. 28 GDPR is in place. If you delete your account or unsubscribe from the newsletter, your contact record at Brevo is deleted or blocked.

Privacy: brevo.com/legal/privacypolicy.

6.5 GeoIP service ipapi.co (location lookup)

To determine the approximate location for QR scans (analytics) and to select the currency automatically (CHF/EUR) we query the service ipapi.co (Kloudend Ltd., based in the USA). What is transmitted is exclusively the IP address that has already been anonymised (last octet or last 80 bits zeroed) over an encrypted connection — never your full IP. Legal basis: Art. 6(1)(f) GDPR (statistics on an anonymised basis). Transfer on the basis of the EU standard contractual clauses.

6.6 Google Web Risk (URL security check)

We check the destination URLs of dynamic QR codes automatically against the Google Web Risk database (Google LLC, USA) for phishing and malware, before or while people who scan them are redirected. Only the URL to be checked is transmitted, no data about the person scanning. Legal basis: Art. 6(1)(f) GDPR (protecting people who scan against abusive links). Transfer on the basis of standard contractual clauses and the EU-US Data Privacy Framework.

6.7 VirusTotal (file scanning)

Where enabled, files uploaded to the platform and shared publicly are sent to VirusTotal (Chronicle LLC, a Google subsidiary, USA) for malware checking before they are released. Please do not upload files containing confidential personal data if you do not want this check. Legal basis: Art. 6(1)(f) GDPR (security of recipients). Transfer on the basis of standard contractual clauses.

6.8 Address search (OpenStreetMap / geo.admin.ch)

For location QR codes you can search for addresses in the editor; the search query is sent to the Nominatim service of the OpenStreetMap Foundation (UK). If that returns no result, the query is additionally sent to the SearchServer service of geo.admin.ch (Federal Office of Topography swisstopo, Switzerland), which covers the official Swiss building register. Legal basis: Art. 6(1)(b) GDPR (a function you requested).

6.9 Fonts and libraries

We host all fonts (Inter, Font Awesome) and JavaScript libraries locally on our own servers. When you visit our pages, no libraries or fonts are loaded from external content delivery networks.

7. Retention periods

  • Account data: Until you delete your account (at any time under "Profile → Delete account"). We delete inactive accounts automatically: after 23 months without a login we send a warning by email; if there is no login within 30 days, the account is deleted completely.
  • QR code content: For as long as the account exists, or until you delete the QR code.
  • Anonymous QR codes (without login): 24 hours, then automatic deletion including the anonymised IP; anonymous drafts in the editor 12 hours.
  • Individual scan records: 90 days. Aggregated, anonymous counters are retained.
  • Payment and invoice data: 10 years (commercial and tax retention requirement).
  • Newsletter: Until you unsubscribe; unsubscribed addresses are kept on a suppression list for 24 months.
  • Records of consent: 3 years as evidence.
  • Server and security logs: A maximum of 90 days (security event logs up to 180 days).
  • Email delivery log: 90 days after sending.
  • Team invitations: 7 days (open invitations), then automatic deletion; completed invitations after 30 days.
  • Bulk import files (CSV): Deleted immediately after processing.
  • Support tickets: 3 years after closure.
  • Abuse reports: 12 months.

8. Your rights

You have the following rights in relation to your personal data held by QRown:

  • Access (Art. 15 GDPR / Art. 25 revDPA): what data do we hold about you?
  • Rectification (Art. 16 GDPR / Art. 32 revDPA): correction of incorrect data.
  • Erasure (Art. 17 GDPR / Art. 32 revDPA): provided no retention obligations apply.
  • Restriction of processing (Art. 18 GDPR).
  • Data portability (Art. 20 GDPR): export of your data in a structured, machine-readable format — available to you at any time when logged in under "Profile → My data → Export data".
  • Objection to processing (Art. 21 GDPR).
  • Withdrawal of consent at any time with effect for the future.
  • Complaint to a supervisory authority (Switzerland: FDPIC, EU: the competent data protection authority).

Notice of your right to object (Art. 21 GDPR)

You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of legitimate interests (Art. 6(1)(f) GDPR). We will then no longer process the data unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

As a logged-in user you can obtain access to your data and an export immediately and without a request, using the export link in your profile. For all other matters please contact info@qrown.io. We respond within 30 days.

9. Data security

We apply the following technical and organisational measures:

  • TLS 1.2+ transport encryption across the whole platform
  • Bcrypt hashing of all passwords (cost factor at least 12)
  • HSTS, CSP, X-Frame-Options and X-Content-Type-Options headers
  • CSRF tokens for all state-changing requests
  • SameSite cookies (Lax) and HttpOnly flags
  • Pseudonymisation of IP addresses before storage
  • Least-privilege principle for database access
  • Daily encrypted backups
  • Audit logs for administrative actions
  • Regular security reviews and dependency updates

10. Transfers to third countries

Our servers are located in Switzerland (Infomaniak); this also applies to our redirect domains qrwn.ch and qron.ch, through which QR code short links are resolved — this privacy policy and the same legal notice apply. Some third parties (Stripe, Google, VirusTotal, ipapi.co) also process data in the USA. We rely on the following for these transfers:

  • The European Commission's adequacy decision for Switzerland (Switzerland → EU)
  • EU standard contractual clauses including supplementary measures
  • The EU-US Data Privacy Framework (for certified US providers)

11. Minors

Our service is not aimed at people under the age of 16. We do not knowingly collect personal data from minors without the consent of a parent or guardian. If we become aware of such data we delete it without delay.

12. Changes to this privacy policy

We may amend this privacy policy if the legal framework or our data processing changes. The current version, with its date and version number, is always available on this page. In the event of material changes the cookie banner is shown again and fresh consent is requested.

Last updated: 27.08.2026 · Version 1

This privacy policy is available in several languages. The German version prevails; translations are provided for convenience.