---
title: "Privacy Policy — qr3.app"
description: "Privacy Policy of qr3.app — GDPR compliant"
canonical: "https://qr3.app/en/legal/privacy/"
lang: "en"
robots: "noindex"
---

# Privacy Policy — qr3.app

> Privacy Policy of qr3.app — GDPR compliant

Canonical: <https://qr3.app/en/legal/privacy/>

Privacy

# Privacy Policy

Last updated: March 2026 | Controller: Ostheimer OG, Fabriksgasse 20, 2230 Gänserndorf, Austria
| [office@qr3.app](mailto:office@qr3.app)

## 1. Principles

We process personal data in accordance with GDPR (EU) 2016/679. qr3.app is built with *Privacy by Design*: IP addresses are **never stored** — they are immediately pseudonymised with HMAC-SHA-256
using a long-lived master secret, purpose, and UTC day at the Cloudflare edge before any data is persisted.

## 2. Data We Process

### 2.1 API Users (Registered Accounts)

- **Account data:** Email address, name (via Clerk.com authentication)
- **Billing data:** Stripe customer ID, subscription status (no card data — Stripe processes
payments directly)
- **Usage data:** Created QR codes, workspace configurations
- **Legal basis:** Art. 6(1)(b) GDPR — contract performance

### 2.2 QR Code Scan Analytics (End Users)

- **IP pseudonym:** HMAC-SHA-256 with a long-lived master secret, purpose, and UTC day
— *pseudonymous personal data; not directly recoverable from the hash, though a secret holder
can recompute a known IP candidate for that day*
- **Device data:** Device type, OS, browser (anonymized from User-Agent)
- **Geo data:** Country, city (from Cloudflare CF-IPCountry header — no IP stored)
- **Legal basis:** Art. 6(1)(f) GDPR — legitimate interest of QR code owners in analytics
- **Retention:** 90 days, then automatically deleted

### 2.3 Website Visits (qr3.app)

- No tracking cookies
- Server logs: Cloudflare processes connection data per their [Privacy Policy](https://www.cloudflare.com/privacypolicy/)

To count page views per language version, qr3.app uses **Cloudflare Web Analytics**. The service does not use cookies or any other client-side storage mechanism, does not store
IP addresses, and does not build user profiles. Data collected, in aggregate: page path,
referrer, browser and device type, and country. Provider: Cloudflare, Inc., as data processor ([Data Processing Addendum](https://www.cloudflare.com/cloudflare-customer-dpa/)). Legal basis: Art. 6(1)(f) GDPR — legitimate interest in per-language reach. No opt-out
cookie is required, since no data is stored on your device.

## 3. Third-Party Services

We share data only with:

- **Cloudflare, Inc.** (USA) — infrastructure, CDN, Workers. Legal basis: Standard Contractual
Clauses (SCCs)
- **Clerk.com** — authentication. Legal basis: SCCs
- **Stripe, Inc.** (USA) — payment processing. Legal basis: SCCs

No data is shared for advertising purposes.

## 4. Your Rights (GDPR Art. 15–22)

- **Access (Art. 15):** `GET /v1/account/privacy` or email [office@qr3.app](mailto:office@qr3.app)
- **Portability (Art. 20):** `GET /v1/account/export` — full JSON export
- **Erasure (Art. 17):** `DELETE /v1/account` or email — full deletion within 30 days
- **Restriction (Art. 18):** Email [office@qr3.app](mailto:office@qr3.app)
- **Objection (Art. 21):** At any time for legitimate interest processing

## 5. Cookies

qr3.app uses only technically necessary session cookies (authentication via Clerk). No marketing
or tracking cookies. Cloudflare Web Analytics (see section 2.3) also does not use cookies.
Cookie consent banners are not required.

## 6. Data Security

All data is transmitted encrypted (TLS 1.3). Database encryption at rest via Cloudflare D1. API
keys are stored hashed. Webhook signatures use HMAC-SHA256.

## 7. Right to Lodge a Complaint

You have the right to lodge a complaint with the Austrian Data Protection Authority:
[Datenschutzbehörde (dsb.gv.at)](https://www.dsb.gv.at), Barichgasse
40-42, 1030 Vienna, Austria

## 8. Contact

Ostheimer OG

Fabriksgasse 20, 2230 Gänserndorf, Austria
[office@qr3.app](mailto:office@qr3.app)
