Privacy Policy
Last updated: August 31, 2026
1. Who we are
Scanitix ("we", "us") operates a platform for creating and tracking QR codes and short links. This policy explains what personal data we collect, why we collect it and the choices you have. You can reach us at hello@scanitix.com.
2. Data we collect
- Account data: name, email address, password (stored only as a hash), language and timezone preferences.
- Billing data: plan type and payment status. Card details are processed by our payment providers and never stored on our servers.
- Usage and analytics data: when someone scans a QR code or opens a short link, we record the event timestamp, an approximate location derived from IP (country/city level), device type, browser and operating system.
- Technical data: IP address, browser language and user agent, recorded at sign-in for security purposes.
- Sign-in method data: if you sign in with Google, we receive your Google account email, name and a unique identifier.
3. How we use data
- to provide the Service — creating QR codes and links, showing you analytics, managing your account;
- to secure the Service — detecting fraud, abuse and unauthorized access;
- to communicate with you — account notices, security alerts, and (only if you opt in) product news;
- to comply with legal obligations.
We do not sell your personal data, and we do not use your content to train advertising profiles.
4. Analytics events of your visitors
If you distribute QR codes or short links, events from people who scan them are attributed to your account. You are the controller of that analytics data and must provide any notices and obtain any consents required under applicable law (for example, when scannable materials are used in regulated contexts). We process that data on your behalf to provide the analytics features.
5. Sharing
We share data only with: infrastructure and service providers that host and support the Service (for example cloud hosting and email delivery), payment processors for subscription billing, and law enforcement or regulators where legally required. Providers are bound to process data only on our instructions.
6. Retention
Account data is kept while your account is active and for a reasonable period afterwards to allow reactivation or export. Analytics events are retained while the related QR code or link exists. Security logs are kept for up to 12 months. Data is deleted or anonymized when it is no longer needed for the purposes above.
7. Your rights
Depending on your jurisdiction (including under the EU/UK GDPR), you may have the right to access, correct, export or delete your personal data, to restrict or object to processing, and to lodge a complaint with your supervisory authority. You can export or delete your data from your account settings, or contact us to exercise your rights. We respond to verified requests within statutory timeframes.
8. Cookies and similar technologies
We use a small number of strictly necessary cookies to keep you signed in and protect against cross-site request forgery. We do not use advertising or third-party tracking cookies.
9. Security
We apply industry-standard measures: passwords are hashed (never stored in plain text), traffic is encrypted in transit with TLS, and access to production systems is restricted. No system is perfectly secure — if you believe your account has been compromised, contact us immediately.
10. International transfers
Your data may be processed in countries other than your own. Where personal data leaves the EEA or UK, we rely on appropriate safeguards such as adequacy decisions or standard contractual clauses.
11. Changes to this policy
We may update this policy to reflect changes in the Service or law. Material changes will be announced through the Service or by email. The "Last updated" date above shows when the policy was last revised.
12. Contact
Privacy questions or requests: hello@scanitix.com.