Privacy Policy
How Abundera QR handles data: near-zero on the free tool (the contact form is the one exception); minimal and explicit on Pro.
1. Summary
Two products, two different data pictures.
- Free Tool (qr.abundera.ai): no account, no analytics, no tracking cookies, no requests to our servers for QR generation or scanning. Your content never leaves your browser. The one server-side path on this site is the contact form, described in Section 2.
- Pro Service (pro.qr.abundera.ai): account-based. We store your email, Stripe customer ID, the QR codes you create, and the minimal scan records described in Section 4. We do not track your end users across the web; we do not sell your data; we do not use ad tech.
2. Data we process on the Free Tool
Server-side: none, except the contact form. Abundera QR is a client-side application. Every QR code, vCard, WiFi password, business card, batch CSV, and scanned image is processed entirely inside your browser, including the QR scanner (camera and uploaded images are decoded on your device). No form data, no QR content, no images, no logs leave your device. There is no server-side scanner on this site; the separate safety checker at check.qr.abundera.ai has its own privacy page.
The contact form (/contact/) is the exception. When you press Send we receive what you typed: your message, the purpose you picked, your consent choice, and your name, email and country if you gave them. Alongside it we store a keyed hash of your IP address (an HMAC with a server-side key, so it cannot be reversed to your address, used only for rate limiting and abuse handling), the country Cloudflare derives from your connection, and your browser's User-Agent string. Photos you attach are checked for file type and size, forwarded to us by email, and never stored on our servers. Submissions are deleted after 12 months; the purge runs each time a new submission arrives. Before we accept a submission, Cloudflare Turnstile checks that you are not a bot; that check sends your IP address and browser signals to Cloudflare (Section 6). To delete a submission earlier, email privacy@abundera.ai.
Client-side (your browser's storage only): interface preferences, chosen language, saved style templates, recent QR history, and the per-QR project files you explicitly save. Recent QR history keeps the content you entered for each code together with a thumbnail in your browser's local storage, except codes that carry a password, key, identity document or payment details, which keep only the code type and style; the form you are working on is also mirrored to session storage so it survives a reload. None of this data is transmitted to us. On a shared computer, clear it from the history panel or via your browser's clear-site-data control.
Requests to other hosts: generator pages load one shared script, the language switcher, from abundera.ai, which we operate; like any page load that request carries your IP address and browser headers to that host, and nothing else. The contact page loads the Turnstile bot check from challenges.cloudflare.com. The newsletter box in the page footer sends the email address you typed to abundera.ai only when you press Subscribe. No fonts, scripts, images, or analytics are loaded from anywhere else. The optional QR scanner uses your camera locally. The optional photo-URL field for vCards fetches the image from the URL you typed, that one request goes directly from your browser to that host, never through us.
3. Data we process on the Pro Service
3.1 Account data
When you sign in via abundera.ai, we receive your email address and a user identifier via our JWKS-delegated auth flow. We store:
- Email address (to send billing notices, critical service messages, and cancellation confirmations)
- Stripe customer ID (to bill the payment method you provide)
- Account preferences (plan tier, team memberships, API-key metadata)
- Timestamps (account created, updated, delete requested)
We do not store passwords; authentication is delegated to abundera.ai. We do not collect demographics, marketing preferences, or device identifiers beyond what is already described here.
3.2 Your codes and URLs
When you create a dynamic QR code, we store the destination URL, an optional label you set, optional tags, the 7-character shortcode, and the code's lifecycle status. This is what makes dynamic QR resolution possible.
3.3 Payment data
Payments are processed by Stripe, Inc. We do not store card numbers, CVC, or bank-account numbers. Stripe returns a reference (the customer ID and subscription ID) which we store so we can reconcile renewals and invoices. Your payment-method details stay with Stripe.
4. Scan analytics (what we record when someone scans one of your codes)
This is where most commercial QR vendors collect a rich behavior profile. We do the opposite.
What we record per scan:
- The UTC calendar date (day-level bucket)
- The country derived from Cloudflare's
CF-IPCountryrequest header - The device class (mobile / tablet / desktop / unknown) classified from a short User-Agent regex
- The code's shortcode (so we can attribute the scan to the right code)
For Team and Agency tiers, we additionally record the UTC hour-of-day bucket for up to 7 days back. Day-bucketed records are retained per plan (see Section 7).
What we do not record: IP address, precise geolocation (no city or latitude/longitude), referrer URL, raw User-Agent string, sub-hour timestamp, cookie or session identifier for the scanner, or anything else. After device-class classification, the User-Agent string is discarded; it is never written to our database.
Countries with fewer than five scans in the analytics window you select are rolled up as "Other" so individual scanners cannot be re-identified from a small sample.
5. Cookies and tracking
Free Tool: no tracking, no fingerprinting, no analytics cookies. If you pick a language in the switcher, one preference cookie, abundera_locale, stores that choice for a year across abundera.ai sites so you are not asked again. It holds the language code and nothing else. Until you pick a language, the site sets no cookie at all.
Pro Service: a single strictly-necessary cookie, __Secure-abundera_session, carries the signed session token required to keep you logged in. It is HttpOnly, Secure, and SameSite=Strict. We do not use marketing cookies, advertising cookies, or cross-site trackers. No Google Analytics, Meta Pixel, or similar.
6. Sub-processors we use
Operating the service requires a few third parties. The current list:
| Sub-processor | Purpose | Data accessed | Jurisdiction |
|---|---|---|---|
| Cloudflare, Inc. | Compute, edge caching, database (D1), key-value store (KV), DNS; Turnstile bot check on the contact form | All Pro Service data; scan headers at the edge; contact-form submissions (Section 2); IP address and browser signals during the Turnstile check | US with global edge |
| Stripe, Inc. | Payment processing and billing | Email, payment details, subscription records | US |
| Zoho Corporation / ZeptoMail | Transactional email (welcome, cancellation, payment failure); delivery of contact-form submissions to us | Email address, email body, contact-form photos in transit | US / India |
A current, dated sub-processor list is maintained at abundera.ai/legal/subprocessors/. We will update that page before adding a new sub-processor and give subscribers at least thirty (30) days to object where required by applicable law.
7. How long we keep your data
Account data: retained while your account is active. When you request account deletion, the account enters a 30-day hold, then all personal data is purged from production systems.
Dynamic QR codes: retained while the associated subscription is active, through any grace period, and through the 30-day account-deletion hold. After that, the codes and their shortcodes are deleted.
Scan records: retained per plan: 365 days on Solo, 730 days on Business, 1,095 days on Team and Agency, 30 days on Keep-Alive. Beyond that window, older scan records are purged on a rolling basis by our daily cron.
Payment and tax records: Stripe transaction records and tax records are retained for at least seven (7) years as required by US tax law; EU VAT jurisdictions may require additional retention. This data cannot be deleted on request during that period.
Contact-form submissions (Free Tool): 12 months, then deleted; the purge runs each time a new submission arrives. Deleted earlier on request (Section 9).
Security logs: structured application logs (no PII beyond what the handler explicitly writes, such as Stripe-webhook user-IDs) are retained by Cloudflare for up to 30 days.
8. Legal basis for processing (GDPR / EEA users)
Where the GDPR applies, we rely on the following legal bases:
- Contract performance, for account creation, subscription billing, code resolution, and technical support. This covers essentially all Pro Service processing.
- Legitimate interests, for security monitoring, fraud prevention, answering and moderating contact-form submissions (including the keyed IP hash used to stop abuse of the form), and the scan-analytics you as our customer use to understand campaign performance, which is minimal by design. Our assessment is that the impact on scanners is minimal because no scanner-identifying data is retained.
- Legal obligation, for retention of payment and tax records as described in Section 7.
- Consent, only where we explicitly request it (e.g., future optional opt-in communications). We do not currently rely on consent for any mandatory processing.
9. Your rights
Subject to applicable law and the retention carve-outs in Section 7, you have the following rights:
- Access: download a ZIP of your account data (codes, scans, README) at any time from Account → Privacy → Export, or by emailing support@abundera.ai.
- Rectification: update account data through your account page or by contacting support.
- Deletion: request account deletion from Account → Privacy → Delete. 30-day hold, then hard-delete. Contact-form submissions on the Free Tool: email privacy@abundera.ai and we delete the submission.
- Portability: the Export ZIP is machine-readable CSV plus a README.
- Object / restrict processing: contact support@abundera.ai. We will honor valid requests and confirm in writing.
- Withdraw consent: where processing is based on consent, you may withdraw at any time without affecting processing done before withdrawal.
- Lodge a complaint: EEA users may complain to their local supervisory authority. UK users: the ICO. Other jurisdictions: the equivalent authority.
Response time: we acknowledge within 5 business days and fulfill within 30 days of acknowledgment, as required by GDPR Article 12. Complex requests may extend to 90 days with notice. California (CCPA), Colorado (CPA), Virginia (VCDPA), and other US state privacy rights are honored on the same 30-day timeline.
10. "Do not sell or share my personal information"
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes other than providing the service. Because we do not engage in these practices, no opt-out is required, however, California residents who want a written confirmation may request one at support@abundera.ai.
11. Children
The Pro Service is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe we have, contact support@abundera.ai and we will delete it.
12. International transfers
We are US-based. Personal data collected from EEA, UK, or Swiss residents is transferred to the US. We rely on the EU Standard Contractual Clauses (SCCs) for these transfers with our sub-processors (Cloudflare, Stripe, Zoho/ZeptoMail). The current sub-processor list at abundera.ai/legal/subprocessors/ documents the transfer mechanism for each.
13. Security
We use industry-standard controls: TLS 1.3 in transit, encrypted storage at rest (Cloudflare D1, KV), scoped API keys, rate limiting, CSRF protection (SameSite=Strict cookies + origin checks), and structured access logging. We do not claim the service is unbreakable. If you suspect a security issue, report it to security@abundera.ai.
14. Breach notification
If we become aware of a personal-data breach affecting data we hold about you, we notify the competent supervisory authority without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of it (GDPR Article 33), unless the breach is unlikely to result in a risk to your rights and freedoms. Where the breach is likely to result in a high risk to you, we also tell you directly, without undue delay (GDPR Article 34). Both notices include: nature of the breach, categories and approximate number of affected records, likely consequences, and measures taken or proposed.
15. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified by email to the address on file for Pro subscribers and by posting a prominent notice on this page. The effective date at the top of this page reflects the current version. Historical versions are available at the changelog.
16. Contact
Privacy questions, data-subject requests, or concerns: privacy@abundera.ai (dedicated) or support@abundera.ai.
Abundera, Inc., 200 W Sahara Ave, Unit 3301, Las Vegas, NV 89102, USA.