FlexQR

Privacy Policy

Effective Date: September 2026 | Global Compliance Edition

1. Executive Overview & Scope

FlexQR ("Platform", "we", "us", or "our") provides dynamic QR code redirection, logo customisation, and custom domain routing services. This Privacy Policy details how we collect, process, store, and protect personal data across our services in strict compliance with the European General Data Protection Regulation (GDPR), the UK Data Protection Act, the South African Protection of Personal Information Act (POPIA), and US State Privacy Laws (including California CCPA/CPRA).

2. Data We Collect & Processing Purposes

Account Owners: Email address, argon2id/bcrypt password hashes, custom domain bindings, uploaded brand logos.
End-User Scanners: Anonymized IP addresses, User-Agent strings (device/browser category), timestamp, dynamic destination URL.

We do not install intrusive tracking cookies or fingerprint end-users who scan your generated QR codes. Scan processing is performed exclusively for real-time URL redirection and aggregated metrics counting.

3. Legal Bases for Data Processing

We process personal data strictly under valid legal bases:

  • Contractual Necessity: Operating account credentials, custom domain routes, and dynamic link redirects.
  • Legitimate Interests: Dual-key rate limiting (IP/Email), honeypot anti-spam defense, and brute-force prevention.
  • Legal Obligation: Fraud prevention, abuse mitigation, and compliance with court directives.

4. Data Storage, Isolation & Off-Site Encryption

All database records are isolated in segregated database schemas. Automated database backups are compressed and stored above the public web root directory (`/home/.../backups/`) to prevent unauthorized HTTP access. Backups are replicated off-site to encrypted cloud storage via Make.com and purged automatically after 30 days.

5. Third-Party Sub-Processors

We restrict data sharing to vetted operational infrastructure providers required to deliver the platform:

  • Infrastructure & Hosting: Managed cPanel / LiteSpeed Web Servers.
  • Edge Security & DNS: Cloudflare WAF & Turnstile Bot Mitigation.
  • Payment Processing: Stripe / PayFast (Financial credentials are processed directly by PCI-DSS Compliant gateways and never touch our servers).

6. Your Global Data Rights

Under GDPR, POPIA, and CCPA/CPRA, you hold the following rights regarding your personal information:

Right to Access & Export Request a copy of your stored account data and link records.
Right to Erasure ("Right to be Forgotten") Delete your account and associated custom domain mappings permanently.

7. Contact Information

For privacy inquiries, data requests, or information regulator concerns, contact our Data Protection Office at: privacy@flexqr.tools.