1. Introduction
Welcome to QRolling. QRolling ("QRolling," "we," "us," "our," or the "Company"), a limited liability company registered in Georgia under number B26345195 (National Agency of Public Registry), with Tax ID EN3289008 and registered office at 75A Erosi Manjgaladze Street, Tbilisi 0159, Georgia, operates the website qrolling.com, its subdomains (app, api, view), and the associated QR code creation, management, analytics, and campaign platform (collectively, the "Service").
QRolling is the data controller for the personal data processed in connection with the Service, except where this Privacy Policy indicates that we act as a data processor on behalf of our customers (for example, for end-user form submissions and scan analytics collected through a customer’s QR codes). This Privacy Policy explains how we collect, use, disclose, retain, and protect your personal information when you use our Service, visit our website, or interact with us in any manner.
For any privacy or data-protection matter you may contact us at [email protected]. No Data Protection Officer (DPO) has been appointed because QRolling is not a public authority, its core activities do not consist of large-scale, systematic monitoring of data subjects, and it does not process special categories of personal data on a large scale within the meaning of Article 37 GDPR. We will reassess this determination as our processing scale evolves.
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please do not use the Service.
This Privacy Policy applies to:
- Registered users who create and manage QR codes through our platform ("Users" or "QR Code Creators");
- Individuals who scan QR codes generated by our Users ("End Users" or "Scanners");
- Visitors to our website who do not hold an account ("Visitors"); and
- Team members invited by Users to collaborate on QR code projects ("Team Members").
2. International Users
QRolling is operated by a company organized and registered in Georgia, with infrastructure and sub-processors located in various countries around the world. By using the Service, you acknowledge that your personal data may be transferred to, stored in, and processed in Georgia and in other countries where our sub-processors operate. These countries may have data protection laws that differ from the laws of your jurisdiction.
QRolling is committed to respecting the data protection rights of all users, regardless of where they are located. We design our practices to comply with, and respect the principles of, the following data protection and privacy frameworks (among others):
- GDPR — General Data Protection Regulation (European Union);
- UK GDPR — United Kingdom General Data Protection Regulation;
- CCPA/CPRA — California Consumer Privacy Act and California Privacy Rights Act (United States);
- LGPD — Lei Geral de Proteção de Dados (Brazil);
- PIPEDA — Personal Information Protection and Electronic Documents Act (Canada);
- PIPA — Personal Information Protection Act (South Korea);
- APPI — Act on the Protection of Personal Information (Japan);
- Privacy Act 1988 — Privacy Act (Australia);
- KVKK — Kişisel Verilerin Korunması Kanunu (Turkey); and
- All other applicable data protection and privacy laws in the jurisdictions where our users are located.
For details on how we safeguard data during international transfers, please see Section 9 — International Data Transfers. For information on your specific rights, please see the sections applicable to your jurisdiction (GDPR, CCPA/CPRA, LGPD).
3. Information We Collect
We collect information in two broad categories: information you provide to us directly and information collected automatically through your use of the Service.
3.1 Information You Provide to Us
Account Data. When you register for an account, we collect your name, email address, password (stored in a securely hashed format; we never store passwords in plain text), profile picture (if uploaded), preferred language, and account role. We also record the date and time of account creation.
Payment and Billing Data. When you subscribe to a paid plan or make a purchase, we collect your billing address, transaction history, subscription plan details, and invoice records. Payment method details (such as credit or debit card numbers) are collected and processed exclusively by our PCI DSS-compliant third-party payment processors.
QR Code Content. We store all data you input into QR codes you create through the Service. This may include, but is not limited to: URLs, plain text, contact information (vCard data), WiFi network credentials, social media links, PDF documents, images, video files, and any other content you choose to encode. This content is stored on our servers so that dynamic QR codes can resolve to the intended destination.
Team Data. If you use our team collaboration features, we collect team member email addresses, assigned roles (e.g., admin, editor, viewer), and activity logs recording which team member created, edited, or deleted specific resources and when.
Campaign Data. When you create marketing campaigns, we collect campaign names, descriptions, tags, goals, and information about which QR codes are associated with each campaign.
Communication Data. When you contact us for support, submit feedback, or otherwise communicate with us, we collect the content of those communications along with associated metadata (e.g., date, email address, subject line).
OAuth and Third-Party Sign-In Data. When you choose to sign in to QRolling using a third-party authentication provider such as Google or Apple ("Sign in with Google" or "Sign in with Apple"), we receive the following information from the provider: your name, email address, and profile picture (if available and if you have authorized the provider to share it). We do not receive or have access to your password from these providers. We use this information solely to create and maintain your QRolling account. You can manage or revoke QRolling's access to your account at any time through your Google Account settings (myaccount.google.com/permissions) or Apple ID settings (appleid.apple.com).
3.2 Information Collected Automatically
Scan Analytics Data. When an End User scans a QR code generated through our Service, we automatically collect the following data points to provide analytics to the QR Code Creator:
- IP address of the scanning device;
- Approximate geolocation (country and city), derived from the IP address — we do not collect precise GPS coordinates;
- Device type (mobile, desktop, or tablet);
- Operating system of the scanning device;
- Browser name and version;
- Language preference as reported by the browser;
- Timestamp of the scan;
- Unique visitor fingerprint — a securely hashed identifier generated from device and browser characteristics, used solely for the purpose of distinguishing unique scans from repeat scans (we do not use this fingerprint to identify individuals);
- Referrer URL (the page from which the scan originated, if available).
Usage Data. We collect information about how you interact with the Service, including pages visited, features used, session duration, clickstream data, and actions taken within the platform.
Cookie and Local Storage Data. We use cookies and browser local storage to maintain authentication sessions, store language preferences, and cache translation data. See Section 13 for complete details on our use of cookies and similar technologies.
4. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery. To provide, operate, and maintain the Service, including creating, hosting, and resolving QR codes; processing scan redirects; and delivering analytics dashboards to Users.
- Authentication and Security. To verify your identity, maintain your session, protect accounts from unauthorized access, detect and prevent fraud, and enforce our Terms of Service.
- Billing and Payments. To process subscriptions, generate invoices, manage payment transactions through our third-party processors, and handle billing inquiries.
- Analytics and Insights. To compile, aggregate, and present scan analytics data to QR Code Creators, enabling them to understand how their QR codes are being used.
- Communication. To send transactional emails (account verification, password resets, billing receipts), respond to support inquiries, and, where you have opted in, send marketing communications about new features or promotions.
- Service Improvement. To analyze usage patterns, diagnose technical issues, conduct internal research, and develop new features and improvements to the Service.
- Team Collaboration. To facilitate team invitations, manage roles and permissions, and maintain activity audit logs.
- Legal Compliance. To comply with applicable laws, regulations, legal processes, or governmental requests, and to establish, exercise, or defend legal claims.
5. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), the United Kingdom, or any other jurisdiction that requires a legal basis for processing personal data, we rely on the following grounds:
| Legal Basis | Applies To |
|---|---|
| Performance of a Contract | Processing necessary to provide the Service you have signed up for, including account management, QR code hosting, scan analytics delivery, and billing. |
| Consent | Marketing communications, non-essential cookies, and any processing where we specifically request your opt-in consent. You may withdraw consent at any time. |
| Legitimate Interests | Service improvement, fraud prevention, security monitoring, internal analytics, and ensuring the reliability and performance of the Service — where such interests are not overridden by your fundamental rights. |
| Legal Obligation | Retaining billing records as required by tax and accounting laws, responding to lawful governmental requests, and complying with applicable regulations. |
6. How We Share Your Information
We may share your information in the following limited circumstances:
- Sub-processors. We engage the third-party providers listed in the table below to operate the Service on our behalf. Each is bound by a written agreement to process data only on our instructions and in accordance with applicable data protection laws. See also our current sub-processor list, which we update when material changes occur.
- Law Enforcement and Legal Requirements. We may disclose your information if we are required to do so by law, in response to a valid subpoena, court order, or other legally binding governmental request, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, investigate fraud, or respond to a government request.
- Business Transfers. In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal data may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website of any change in ownership or use of your personal data, as well as any choices you may have regarding your personal data.
- With Your Consent. We may share your information for any other purpose with your explicit consent.
6.1 Current Sub-processors
As of the “Last Updated” date of this Privacy Policy, the following sub-processors process personal data on our behalf:
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| Paddle.com Market Ltd | Merchant of record — subscription billing, tax handling, fraud prevention | Name, billing email, billing address, country, card token (tokenised by Paddle), transaction amounts | United Kingdom / EU |
| Akamai Technologies (Linode) | Cloud hosting of application servers, databases, and backups | All account and Service data at rest and in transit | European Union / United States (selected regions) |
| QRolling-operated mail infrastructure (outbound SMTP via JavaMailSender) | Transactional email (account verification, password reset, notifications) | Name, email address, message content | Georgia / EU hosting |
| Google LLC – Cloud Translation API | On-the-fly translation of user-facing strings and QR type metadata | Text strings to be translated (may include user-entered labels) | United States |
| Grafana Labs | Infrastructure monitoring, error tracking, and service-availability dashboards | System logs, performance metrics, error traces (may contain truncated identifiers) | European Union |
| Replicate, Inc. | Generative-AI inference for the AI Templates Extension (when activated) | User-provided prompts, reference images, and generated outputs | United States |
| Google LLC – OAuth | “Sign in with Google” authentication | Google account identifier, name, email, profile picture (as authorised by the user) | United States |
| Apple Inc. – Sign in with Apple | “Sign in with Apple” authentication | Apple-issued identifier, name, relay or real email (as authorised by the user) | United States |
Transfers outside the European Economic Area are safeguarded by the European Commission’s Standard Contractual Clauses or by equivalent mechanisms recognised under applicable data protection law. The current, authoritative version of this list is maintained at sub_processors.html.
6.2 No Sale or Sharing for Cross-Context Behavioural Advertising
We do not sell personal data and do not share personal data for cross-context behavioural advertising within the meaning of the CCPA/CPRA or equivalent laws. Section 11 sets out the dedicated California disclosures and the Do Not Sell or Share My Personal Information mechanism.
When we share data with third parties, we ensure that appropriate contractual and technical safeguards are in place to protect your personal information.
6A. Automated Decision-Making & Profiling
The Service does not take decisions that produce legal or similarly significant effects on you based solely on automated processing within the meaning of Article 22 GDPR. However, the Service uses automated processing in the following limited ways:
- Scan analytics aggregation. Scan events are aggregated and enriched (for example, deriving country and device type) to build dashboards for the account holder. No decision affecting you is made by this processing.
- Abuse and fraud signals. Automated heuristics (rate limits, anomaly detection, duplicate-account detection) may flag accounts for human review. A human always takes the final decision on any account suspension or refund denial based on these signals.
- Generative AI (AI Templates Extension). When you use AI Templates, your prompts are processed by a third-party AI model to generate design suggestions. No decision affecting your legal rights is made by this processing; the output is only a suggestion that you can accept, modify, or ignore.
Where required by applicable law, you may contact us at [email protected] to request human review of any automated decision that materially affects you.
7. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
| Data Category | Retention Period |
|---|---|
| Account Data | For the duration of your active account, plus 30 days following account deletion to allow for account recovery and to resolve any pending matters. |
| QR Code Content | For the duration of your active account. Deleted within 30 days after account termination or deletion of the specific QR code. |
| Scan Analytics Data | Retained while the associated account is active. Anonymized or deleted within 30 days of account termination. |
| Payment and Billing Records | Retained for the period required by applicable tax, accounting, and financial regulations — typically up to 7 years after the transaction date. |
| Communication Data | Retained for up to 2 years after the last interaction, or longer if related to an unresolved dispute or legal matter. |
| Usage and Cookie Data | Aggregated usage data may be retained indefinitely in anonymized form. Raw session data is retained for up to 12 months. |
When data is no longer needed, we securely delete or irreversibly anonymize it so that it can no longer be associated with you.
8. Data Security
We take the security of your personal data seriously and implement industry-standard technical and organizational measures to protect it against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption in Transit. All data transmitted between your device and our servers is encrypted using TLS/SSL (Transport Layer Security / Secure Sockets Layer) protocols.
- Encryption at Rest. Sensitive data stored on our servers, including passwords and payment references, is encrypted at rest using strong encryption algorithms.
- Password Hashing. User passwords are stored using industry-standard one-way hashing algorithms with unique salts. We never store passwords in plain text.
- Access Controls. Access to personal data is restricted to authorized personnel on a need-to-know basis. We employ role-based access controls, multi-factor authentication for administrative systems, and regular access reviews.
- Regular Security Assessments. We conduct periodic security audits, vulnerability assessments, and penetration testing to identify and remediate potential security weaknesses.
- Incident Response. We maintain an incident response plan to promptly detect, investigate, and mitigate data security breaches. In the event of a breach affecting your personal data, we will notify you and the relevant supervisory authorities as required by applicable law.
While we strive to use commercially reasonable means to protect your personal data, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee the absolute security of your data.
9. International Data Transfers
QRolling is based in Georgia. Your personal data may be transferred to, stored in, and processed in countries other than the country in which you reside. These countries may have data protection laws that differ from the laws of your jurisdiction. Georgia is an EU candidate country whose data protection legislation, including the Law of Georgia on Personal Data Protection, is aligned with EU standards and the GDPR.
When we transfer personal data across borders, we take appropriate safeguards to ensure that your data receives an adequate level of protection, including:
- Entering into Standard Contractual Clauses (SCCs) approved by the European Commission with data recipients outside the EEA;
- Ensuring that our hosting and infrastructure providers maintain appropriate certifications and compliance frameworks;
- Implementing additional technical measures (such as encryption) to protect data during transfer.
By using the Service, you acknowledge and consent to the transfer and processing of your personal data in accordance with this Privacy Policy.
10. Your Rights Under the GDPR
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR) and applicable local laws:
- Right of Access. You have the right to request a copy of the personal data we hold about you, along with information about how we process it.
- Right to Rectification. You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
- Right to Erasure ("Right to Be Forgotten"). You have the right to request the deletion of your personal data, subject to certain legal exceptions (e.g., where we are required by law to retain the data).
- Right to Restriction of Processing. You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to its processing.
- Right to Data Portability. You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance.
- Right to Object. You have the right to object to the processing of your personal data where we rely on legitimate interests as our legal basis, including profiling based on those interests.
- Right to Withdraw Consent. Where we process your data based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
- Right to Lodge a Complaint. You have the right to lodge a complaint with a supervisory authority in the EU/EEA member state of your habitual residence, place of work, or place of the alleged infringement if you believe that our processing of your personal data infringes the GDPR. Additionally, as QRolling is based in Georgia, you may also file a complaint with the Personal Data Protection Service of Georgia (PDPS), the local supervisory authority responsible for overseeing compliance with the Law of Georgia on Personal Data Protection.
How to Exercise Your Rights
To exercise any of the above rights, please contact us at [email protected] with the subject line "Data Rights Request." We will respond to your request within 30 days. We may request verification of your identity before processing your request. If your request is complex or you have made a large number of requests, we may extend the response period by an additional 60 days, in which case we will notify you of the extension and the reasons for it.
There is no fee for exercising your rights, except where requests are manifestly unfounded or excessive (in particular, if they are repetitive), in which case we may charge a reasonable fee or refuse to act on the request.
11. California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you specific rights regarding your personal information. This section supplements the rest of this Privacy Policy and applies solely to residents of the State of California.
11.1 Categories of Personal Information Collected
In the preceding twelve (12) months, we have collected the following categories of personal information from California consumers:
- Identifiers: Name, email address, account username, IP address, and unique account identifiers.
- Internet or Other Electronic Network Activity Information: QR code scan data, browsing and interaction data, device type, operating system, browser information, and referrer URLs.
- Geolocation Data: Approximate geographic location (country and city) derived from IP addresses. We do not collect precise GPS coordinates.
- Commercial Information: Subscription plan details, billing history, and transaction records.
- Professional or Employment-Related Information: Only if voluntarily provided in account or team settings.
11.2 Your Rights Under CCPA/CPRA
As a California resident, you have the following rights:
- Right to Know. You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which the information was collected, the business or commercial purpose for collecting the information, and the categories of third parties with whom we share it.
- Right to Delete. You have the right to request the deletion of your personal information, subject to certain legal exceptions.
- Right to Correct. You have the right to request the correction of inaccurate personal information that we maintain about you.
- Right to Opt-Out of Sale or Sharing. You have the right to opt out of the "sale" or "sharing" of your personal information. As stated above, QRolling does not sell or share (as defined by the CCPA/CPRA) your personal information, so there is no need to opt out. However, you may still contact us to confirm this at any time.
- Right to Limit Use of Sensitive Personal Information. We do not use or disclose sensitive personal information for purposes other than those permitted under the CPRA.
- Right to Non-Discrimination. We will not discriminate against you for exercising any of your CCPA/CPRA rights. We will not deny you goods or services, charge you different prices or rates, provide you a different level or quality of goods or services, or suggest that you may receive a different price or quality of goods or services as a result of exercising your rights.
To submit a CCPA/CPRA request, contact us at [email protected] with the subject line "CCPA Request." We will verify your identity and respond within forty-five (45) days. You may also designate an authorized agent to make a request on your behalf, subject to identity verification.
12. Brazilian Users (LGPD)
If you are located in Brazil, the Lei Geral de Proteção de Dados (LGPD — General Data Protection Law, Law No. 13,709/2018) provides you with specific rights regarding your personal data. This section supplements the rest of this Privacy Policy and applies to individuals located in Brazil.
12.1 Legal Bases for Processing
QRolling processes the personal data of Brazilian users based on the following legal bases under the LGPD:
- Consent: Where you have given your free, informed, and unambiguous consent to the processing of your personal data for a specific purpose (e.g., marketing communications, non-essential cookies).
- Performance of a Contract: Where processing is necessary to fulfill or prepare a contract to which you are a party (e.g., providing the Service, managing your account, processing payments).
- Legitimate Interest: Where processing is necessary for the legitimate interests of QRolling or a third party, provided that such interests do not override your fundamental rights and freedoms (e.g., fraud prevention, service improvement, security monitoring).
- Legal or Regulatory Obligation: Where processing is required to comply with applicable legal or regulatory obligations (e.g., tax record retention, responding to lawful requests).
12.2 Your Rights Under the LGPD
As a data subject located in Brazil, you have the following rights under the LGPD:
- Confirmation and Access. The right to obtain confirmation of the existence of processing activities and to access your personal data held by QRolling.
- Correction. The right to request the correction of incomplete, inaccurate, or outdated personal data.
- Anonymization, Blocking, or Deletion. The right to request anonymization, blocking, or deletion of unnecessary or excessive personal data, or data that is processed in non-compliance with the LGPD.
- Data Portability. The right to request the portability of your personal data to another service provider or product, subject to applicable regulations and commercial and industrial secrets.
- Deletion. The right to request the deletion of personal data processed with your consent, except where retention is legally required or otherwise permitted under the LGPD.
- Information About Sharing. The right to obtain information about the public and private entities with which QRolling has shared your personal data.
- Information About Consent. The right to be informed about the possibility of not providing consent and about the consequences of such refusal.
- Withdrawal of Consent. The right to withdraw your consent at any time, without affecting the lawfulness of processing carried out prior to the withdrawal.
12.3 Data Protection Officer (DPO)
QRolling has appointed a Data Protection Officer to oversee compliance with the LGPD and to serve as a point of contact for data subjects and the Brazilian National Data Protection Authority (ANPD). You may contact our DPO at:
- DPO Email: [email protected]
12.4 Complaints to the ANPD
If you believe that QRolling has processed your personal data in violation of the LGPD, you have the right to file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD), the Brazilian National Data Protection Authority. Information about the ANPD and the complaint process is available at www.gov.br/anpd.
13. Cookies and Tracking Technologies
We use cookies and similar technologies (including browser local storage) to enable core functionality, remember your preferences, and understand how you use the Service.
13.1 Types of Cookies We Use
| Category | Purpose | Examples |
|---|---|---|
| Essential | Required for the Service to function. Cannot be disabled. | Authentication token (JWT session cookie), CSRF protection |
| Functional | Remember your preferences and settings. | Language preference, theme selection (dark/light mode) |
| Analytics | Help us understand usage patterns and improve the Service. | Google Analytics cookies, internal usage tracking |
13.2 Local Storage
We use browser local storage (localStorage) to cache translation data for our multi-language interface. This improves loading performance and is limited to non-personal, functional data.
13.3 Managing Cookies
Today we only set strictly necessary cookies and a small number of functional browser-storage items for your preferences (language, theme); we do not currently run analytics, marketing or advertising cookies. As long as that remains the case, no cookie consent banner is shown because none is required under Article 5(3) of the ePrivacy Directive. The moment we activate any non-essential cookie (for example, Google Analytics, currently planned but not yet active), we will present a cookie consent banner that lets you accept, reject or customise per category, with the choice stored in a 12-month qr_consent cookie and changeable from a “Cookie settings” link in the footer.
Most web browsers also allow you to manage cookies through their own settings. You can typically choose to block all cookies, accept all cookies, or be notified when a cookie is set. Please note that disabling essential cookies may prevent you from using core features of the Service, such as remaining signed in.
For the complete, itemised list of cookies and trackers we use (name, purpose, duration, first or third party), see our dedicated Cookie Policy.
For more information on managing cookies, visit www.allaboutcookies.org.
14. Children's Privacy
The Service is not directed at, and is not intended for use by, children under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a child under 16 without verification of parental consent, we will take steps to delete that information promptly.
If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at [email protected] so that we can take appropriate action.
15. Third-Party Links
QR codes created using our Service may contain links to third-party websites, applications, or services that are not owned or controlled by QRolling. This Privacy Policy applies only to our Service. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party websites or services.
When you scan a QR code that redirects you to a third-party website, that website's privacy policy governs the collection and use of your data from that point forward. We strongly encourage you to review the privacy policy of every website you visit.
QRolling shall not be liable for any damages or losses arising from your use of or reliance on any third-party content, goods, or services available through QR codes generated on our platform.
16. Scan Data and Third-Party QR Code Scanners
This section is important for both End Users who scan QR codes and Users who create QR codes through our platform.
16.1 How Scan Data Is Collected
When an End User scans a QR code generated by QRolling, the scan request passes through our servers before redirecting the End User to the destination URL. During this redirect, we automatically collect the scan analytics data described in Section 3.2 of this policy. This data collection occurs regardless of which QR code scanning application the End User uses.
16.2 Data Controller and Data Processor Roles
As the data controller, the QR Code Creator is responsible for:
- Ensuring that their collection and use of scan analytics data complies with applicable data protection laws;
- Providing appropriate privacy notices to End Users where required by law (for example, by including a privacy notice link on the destination page of their QR codes);
- Responding to data subject requests from End Users regarding the scan data associated with their QR codes; and
- Ensuring a valid legal basis exists for the processing of scan data.
16.3 QRolling's Responsibilities as Data Processor
As a data processor, QRolling:
- Processes scan data only in accordance with the instructions of the QR Code Creator and the terms of our agreement;
- Implements appropriate technical and organizational security measures to protect scan data;
- Assists the QR Code Creator in fulfilling data subject rights requests where technically feasible;
- Does not use scan data for its own independent purposes beyond providing the Service, except in anonymized or aggregated form for statistical analysis and service improvement; and
- Promptly notifies the QR Code Creator of any personal data breach affecting scan data.
16.4 Third-Party Scanner Applications
End Users may use various QR code scanning applications (including built-in camera applications on their mobile devices) to scan QR codes. These third-party scanner applications may independently collect data about the End User. QRolling has no control over, and is not responsible for, the data collection practices of third-party scanner applications. End Users should review the privacy policy of the scanner application they use.
17. Add-On Extensions
QRolling offers optional paid add-on features (“Extensions”) that expand the functionality of your base plan. This section explains the additional personal data that is collected and processed when you activate one of these Extensions. The general data-handling practices described elsewhere in this Privacy Policy continue to apply in full; this section only covers what is specific to each Extension.
17.1 Programs & Forms
The Programs & Forms Extension lets you build forms that can be filled out by end-users who scan your QR codes (“Form Respondents”).
Data we process on your behalf. When a Form Respondent submits one of your forms, QRolling processes the answers as a data processor acting on your instructions. You, as the account holder, are the data controller for those submissions. Data processed may include:
- Fields you have defined in your form (for example: names, email addresses, phone numbers, postal addresses, dates, free-text answers, file uploads, signatures, ratings).
- Technical metadata captured at submission: timestamp, IP address, browser, operating system, device type, and approximate geolocation derived from the IP address.
- A reference to the QR code that was scanned to reach the form.
Your responsibilities as the controller. You are responsible for: (i) informing Form Respondents about how their data will be used, (ii) obtaining any consent or other legal basis required by applicable law before collecting personal data through your forms, (iii) responding to data-subject requests submitted by Form Respondents, and (iv) not requesting special categories of personal data (such as health, biometric, or financial data) through forms unless you have an appropriate legal basis and safeguards in place.
Retention. Form submissions are stored for as long as the Extension is active on your account. If you deactivate the Extension, submissions are retained for thirty (30) days and then permanently deleted unless you export them beforehand or reactivate the Extension within that period.
17.2 Print Studio
The Print Studio Extension lets you design printable materials that embed your QR codes.
Data processed. Content you upload or create inside Print Studio, such as logos, images, brand assets, text, and layout files. These materials are processed only to generate previews and downloadable files for you.
Third-party providers. If, in the future, we enable direct physical printing or shipping through a third-party print provider, we will share only the specific files, addresses, and order information needed to fulfill that order. No such sharing takes place today unless expressly initiated by you.
Retention. Design files are retained for as long as the Extension is active. After deactivation, designs follow the 30-day retention rule described in our Terms and Conditions.
17.3 AI Templates
The AI Templates Extension uses generative AI to suggest QR code designs and layouts based on prompts and reference material you provide.
Data processed. The text prompts, keywords, colors, brand assets, and other inputs you submit to the AI generator, together with the generated outputs.
Third-party AI providers. Prompts and inputs may be transmitted to reputable third-party AI service providers solely to generate the requested output. QRolling selects providers that contractually agree not to use customer inputs to train their public models and that provide data-processing terms aligned with GDPR and equivalent laws. We do not sell or share these inputs for advertising or any purpose unrelated to generating the output you requested.
What not to submit. Do not submit personal data of third parties, confidential business information you are not authorized to disclose, or special categories of personal data into AI prompts. You are responsible for ensuring you have the right to use any material you upload.
Retention. Prompts and outputs are retained within your account for as long as the Extension is active. After deactivation, they follow the 30-day retention rule.
17.4 Common Rules for All Extensions
- No new selling of data. Activating any Extension does not change our core commitment: we do not sell your personal data or the personal data of your Form Respondents.
- Legal basis. For account holders, processing related to Extensions is based on performance of our contract with you. For Form Respondents and other end-users, you are responsible for identifying the applicable legal basis under GDPR, CCPA/CPRA, LGPD, or other laws that apply to you.
- Sub-processors. Any third parties used to operate an Extension (hosting, AI, print fulfillment, email delivery) act as sub-processors under appropriate contractual safeguards. A current list is available on request at [email protected].
- Deactivation. You can deactivate any Extension at any time from your account settings. Deactivation stops future data collection immediately and triggers the 30-day retention window described above.
- Data-subject requests. If a Form Respondent or other end-user contacts us directly about data collected through your Extension usage, we will typically forward the request to you as the controller and will assist you in responding where required by law.
18. Data Processing Agreement
QRolling offers a Data Processing Agreement (DPA) to enterprise customers and any User who requires one for compliance with the GDPR or other data protection regulations.
The DPA supplements this Privacy Policy and details the specific terms under which QRolling processes personal data on behalf of the User as a data processor, including:
- The subject matter, duration, nature, and purpose of the processing;
- The types of personal data processed and categories of data subjects;
- The obligations and rights of the data controller;
- Sub-processor engagement and notification procedures;
- Data breach notification obligations; and
- Data return and deletion procedures upon termination.
To request a DPA, please contact us at [email protected].
19. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make changes, we will update the "Last Updated" date at the top of this page.
For material changes — such as changes to the categories of data we collect, how we use your data, or the third parties with whom we share it — we will provide at least 30 days' prior notice by sending an email to the address associated with your account and/or by posting a prominent notice on our website before the changes take effect.
Your continued use of the Service after the effective date of a revised Privacy Policy constitutes your acceptance of the changes. If you do not agree with the updated policy, you should discontinue your use of the Service and, if applicable, delete your account.
20. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Company: QRolling
- Registered address: 75A Erosi Manjgaladze Street, Tbilisi 0159, Georgia
- Company registration: B26345195 (National Agency of Public Registry, Georgia)
- Tax ID: EN3289008
- Privacy & data protection email: [email protected]
- General & billing email: [email protected]
- Website: qrolling.com
We aim to respond to all inquiries within 30 days. For data rights requests under the GDPR, we will respond within the timeframes specified in Section 10.
EU and EEA data subjects may also lodge a complaint with their national supervisory authority. Users in Georgia may contact the Personal Data Protection Service of Georgia (PDPS).