Skip to content
KeeperQR

Draft, not yet in force

This document has not been reviewed by a lawyer and does not bind anyone yet. It is published here so it can be read and corrected before launch. Do not rely on it.

Privacy Policy

Last updated 16 September 2026

There are two sets of people in this policy: customers, who have a KeeperQR account, and scanners, who point a phone at a QR code a customer printed and have never heard of us. The second group cannot consent to anything, so what we record about them is deliberately small.

1.What we collect about account holders

  • Your name, email address, and profile image, from signup or from Google if you sign in that way.
  • A hash of your password, if you set one. We never store the password itself.
  • Passkey public keys and two-factor secrets, if you enable them.
  • The workspaces, campaigns, QR codes, destinations, and routing rules you create.
  • Billing state: your plan, whether you are on a trial, and identifiers linking you to your Stripe customer record. Card numbers never reach us.
  • Operational records: sign-in attempts, invitations, and an audit trail of changes made in your workspace.

We use this to run your account, bill you, send the emails you have asked for, and secure the service. We do not sell it, and we do not use it to advertise to you.

2.What we record when someone scans a code

For each scan of a customer’s code we store:

  • The time of the scan and which code was scanned.
  • Country, country code, and city, derived from network-level geolocation provided by our hosting platform. We do not use GPS and we do not ask the device for a location.
  • Device type, operating system, and browser, parsed from the user-agent string the browser sends.
  • The referring page, when the browser provides one.
  • A keyed one-way hash of the IP address, used only to tell repeat scans apart from distinct ones.
  • A coarsely masked form of the IP address for display, such as 1.2.***.***.

The raw IP address is never written down. It exists only in memory for the moment it takes to hash and mask it. The hash is keyed with a secret we hold, so it cannot be reversed by guessing every possible address, and it is not usable as an identifier by anyone who obtained the database without that key.

We do not set a cookie on a scan, show an interstitial, or fingerprint the device. A scan resolves straight to the destination the customer chose.

Scans by bots, link preview fetchers, and scripted clients are redirected but not recorded at all.

Between a customer and the people who scan their codes, the customer is the data controller and we are their processor. If you scanned a code and want the record removed, contact whoever published the code. If you cannot identify them, contact us and we will pass it on.

3.Website analytics

Our marketing pages and sign-in pages use Vercel Web Analytics, which counts page views without cookies and without tracking anyone across sites. The signed-in application is not tracked at all.

4.How long we keep things

  • Scan IP data: the hash is erased and the masked address fully redacted after 13 months. Everything else about the scan, including the country and device, is kept so historic totals stay correct.
  • Scan records: kept until the QR code is deleted, which deletes them with it.
  • Account data: kept while your account exists. Deleting your account deletes your codes, campaigns, and scan records.
  • Billing records: kept as long as tax and accounting law requires, which is generally seven years.
  • Email we receive at our role addresses: stored so we can act on abuse reports and support requests.

5.Who else processes it

We use a small number of providers to run the service, listed with what each one receives on the subprocessors page. We do not sell personal data, and we do not share it for advertising.

Payments are handled by Stripe, through Link, which acts as merchant of record. That means Stripe is responsible for its own handling of your payment details under its own privacy policy. A data deletion request made to Link will cancel your subscription with us.

We are based in the United States and data is processed there. Transfers out of the UK and EEA rely on the standard contractual clauses our providers have in place.

6.Your rights

Depending on where you live, you can ask for a copy of your data, ask us to correct or delete it, object to some processing, or ask us to restrict it. Much of this is self-serve: your settings let you edit your profile, export your scan data as CSV, and delete your account outright.

For anything else, email support@keeperqr.com. We will respond within 30 days. If you are in the UK or EEA you may also complain to your data protection authority.

7.Security and changes

Data is encrypted in transit and at rest, passwords are hashed with bcrypt, and access to production data is limited to those who need it. No system is perfect; if a breach affects you we will tell you and the relevant regulator as the law requires.

If we change this policy materially we will email account holders before the change takes effect. The date at the top always reflects the current version.