Privacy Policy
Effective date: June 1, 2025 · Last reviewed: 2026
1. Who We Are
TemporaryQR ("we," "us," or "our") operates the website temporaryqr.xyz and provides a free temporary QR code generation service. We are committed to protecting your privacy and handling your data transparently.
For data protection inquiries, contact us via the Contact page.
2. Data We Collect
2.1 QR Content
When you create a QR code, we store the content you provide (URL, text, Wi-Fi credentials, contact details, etc.) in Cloudflare KV. This data is stored only for the duration you specify and is automatically deleted after expiry.
2.2 Scan Analytics
When someone scans a QR code, we record:
- Timestamp of the scan
- User-Agent string (device/browser type)
- HTTP Referrer (if present)
- A one-way SHA-256 hash of the IP address (not the IP address itself)
We do not perform IP geolocation, reverse-DNS lookup, or any form of precise location tracking.
2.3 Cookies and Local Storage
We use strictly necessary cookies for service functionality. Analytical and advertising cookies are only set with your explicit consent via our Cookiebot banner.
2.4 Contact Form
If you contact us, we collect your name, email address, and message content solely to respond to your inquiry.
3. How We Use Your Data
- To generate and deliver QR codes as requested
- To provide scan analytics to QR creators
- To enforce privacy controls (expiry, scan limits, password protection)
- To detect and prevent abuse of the service
- To respond to support and legal inquiries
We do not use your data for profiling, targeted advertising, or any purpose beyond operating the service.
4. Legal Basis (GDPR)
For users in the European Economic Area (EEA) and UK, our legal bases are:
- Legitimate interests — for operating the QR service, storing QR records, and basic security monitoring
- Consent — for analytics and advertising cookies (via Cookiebot banner)
- Legal obligation — for responding to lawful law enforcement requests
5. Data Retention
QR records are stored for the duration specified at creation. Cloudflare KV's TTL mechanism automatically purges expired records. Contact form submissions are retained for up to 90 days. Hashed IP addresses stored in scan logs are deleted with the QR record.
6. Data Sharing
We do not sell, rent, or share your personal data. Data may be accessed by:
- Cloudflare, Inc. — as our infrastructure provider (subject to Cloudflare's DPA)
- Law enforcement — only when required by a valid legal order
7. Your Rights (GDPR / CCPA)
Depending on your jurisdiction, you have the right to:
- Access — request a copy of data we hold about you
- Deletion (right to be forgotten) — request deletion of your QR records at any time via the management link or contact form
- Correction — request correction of inaccurate data
- Portability — receive your data in a machine-readable format
- Objection — object to processing based on legitimate interests
- Withdraw consent — for cookie-based analytics at any time via the Cookiebot panel
To exercise any of these rights, use the Contact form and select "GDPR / Data Deletion Request."
8. Cookies
For full details about cookies we use and how to manage them, see our Cookie Policy.
9. Children's Privacy
TemporaryQR is not directed at children under 16. We do not knowingly collect data from minors. If you believe a child has submitted data, contact us immediately for deletion.
10. Changes to This Policy
We may update this policy periodically. The effective date at the top of this page will reflect the most recent revision. Continued use of the service after updates constitutes acceptance of the revised policy.
11. Contact
For privacy-related inquiries: Contact form — select "Privacy / Data Request."
You also have the right to lodge a complaint with your national data protection authority (e.g., ICO in the UK, CNIL in France, or your local EU supervisory authority).