hasQR logo

hasQR

← Back to generator

Privacy Policy

Last updated: August 2026

This is a draft template, not legal advice. Data-privacy requirements (GDPR, CCPA, and similar laws) vary by where your users are located — review this with counsel before relying on it, particularly if you have EU or California visitors.

This policy explains what ASFMS, LLC ("we," "us") collects through hasQR and why. We've tried to write it plainly rather than bury the details.

1. Using the generator without an account

If you generate and download a QR code without signing in, nothing you type or upload is sent to our servers — the code is rendered entirely in your browser, and we don't see or log the content you encode.

The one exception: each time you press "Generate QR code," your browser sends a single anonymous ping to record that a code was generated. That ping carries no content, no IP-linked identity, and no account information — just a timestamp, used to show aggregate generation volume (e.g. "how many codes were generated this week") on our internal admin dashboard.

2. What we collect if you create an account

DataWhy we collect it
Email addressTo identify your account and let you log in
PasswordStored as a salted hash (bcrypt) — we never store or can see your plaintext password

3. What we collect when a tracked code is scanned

If you turn on scan tracking for a code, every scan of the resulting link logs:

DataDetail
TimestampWhen the scan occurred
Approximate locationCity/region/country, derived from the visitor's IP address using an offline lookup — not GPS, and often accurate only to a metro area
IP addressStored to compute the location and to estimate "unique" scans
Device OSiOS, Android, or other, parsed from the browser's user-agent string
ReferrerThe page that linked to the scan, if any

This data belongs to the account that created the tracked code and is visible only to that account, via the dashboard.

4. If you're a visitor scanning someone else's hasQR code

If the code you scanned has tracking enabled, the data above is logged and visible to whoever created that code — not to the general public, and not used by us for advertising or sold to third parties. We don't tie this data to an identity unless the code creator already knows who you are through some other means.

5. Data retention

Account data and click logs are retained until you delete the associated code or account. Deleting a code also deletes its click history.

6. Third parties

We don't sell personal data. The IP-to-location lookup runs offline using a bundled database — no third-party service receives visitor IPs as part of that lookup.

This site uses Google Analytics to understand overall traffic and usage patterns. Google Analytics sets cookies and collects standard web-analytics data (pages viewed, approximate location, device/browser type) according to Google's own privacy policy. This is separate from the QR-code-specific data described above.

Pages on this site may also display ads served through Google or other ad networks, which can set their own cookies and collect data under their respective privacy policies.

7. Your rights

You can delete any tracked code (and its click history) at any time from your dashboard, or delete your account entirely by contacting us.

8. Contact

Questions about this policy can be sent to the contact address listed on our About page.