Privacy
SQRL Code Privacy Policy
Effective Date: September 3, 2026
Last Updated: September 3, 2026
1. Introduction
SQRL Code (“SQRL Code,” “we,” “us,” or “our”) is operated by CedanoTech Inc.
This Privacy Policy explains how we collect, use, disclose, store, and protect information when you access or use SQRL Code, including sqrlcode.com, our QR code generator, Managed QR functionality, organizational workspaces, and related services (collectively, the “Services”).
SQRL Code includes both a browser-based QR code generator that can be used without an account and authenticated features that allow users and organizations to save, manage, organize, update, and repurpose QR codes.
By using the Services, you acknowledge the practices described in this Privacy Policy.
2. Information We Collect
The information we collect depends on how you use SQRL Code.
A. Free Static QR Generator
When you use the free static QR generator without creating an account, QR content such as URLs or plain text is processed in your browser for QR generation, preview, and export.
For ordinary static QR generation:
- the content encoded in the QR code is not uploaded to SQRL Code for generation;
- QR previews are generated in your browser;
- PNG and SVG exports are generated locally in your browser; and
- logos uploaded solely for ordinary static generation are processed locally.
If you choose to convert a QR into a Managed QR, certain QR configuration information may be temporarily stored in your browser so that your work can continue through account creation.
B. Account Information
If you create an account, we may collect:
- email address;
- password or authentication credentials;
- optional display name;
- authentication and session information; and
- information necessary to associate your account with an organization or workspace.
Authentication is provided using Supabase. Passwords submitted through SQRL Code are passed to the authentication service and are not stored as plaintext in SQRL Code's application database.
C. Organization and Workspace Information
When using an organizational workspace, we may process information including:
- organization name and identifier;
- workspace membership;
- user roles and permissions;
- departments;
- campaigns;
- collections;
- tags;
- templates;
- brand settings;
- saved views; and
- other workspace configuration information.
D. Managed QR Information
If you create or manage a Managed QR, we process information necessary to operate that QR, which may include:
- QR name and identifier;
- destination URL;
- short code;
- QR status and purpose;
- design and styling configuration;
- uploaded logos;
- ownership and organizational associations;
- tags, campaigns, collections, and departments;
- deployment notes;
- destination-change history;
- timestamps; and
- other information you choose to associate with the QR.
Unlike a static QR, a Managed QR requires SQRL Code to maintain its destination so that the same QR can redirect to the destination you configure.
E. Product and Operational Information
We may collect limited first-party operational information when authenticated users interact with the Services, such as:
- product actions;
- funnel or workflow events;
- the SQRL Code page from which a product workflow began;
- QR creation events;
- Managed QR actions; and
- other limited application events necessary to understand and operate the Services.
Our current product-event implementation is designed not to include QR destination content, uploaded logo content, or QR payloads in analytics event metadata.
4. How We Use Information
We may use information to:
- provide and operate the Services;
- authenticate users and maintain accounts;
- create and manage organizational workspaces;
- create, resolve, update, and administer Managed QR codes;
- preserve QR configuration during workflows you initiate;
- maintain destination history and operational records;
- enforce user roles and permissions;
- protect the Services against abuse, fraud, or unauthorized activity;
- troubleshoot and improve SQRL Code;
- understand authenticated product usage;
- respond to support or privacy requests;
- enforce our terms and policies; and
- comply with applicable legal obligations.
We do not use QR content to build advertising profiles.
5. QR Scans
When someone scans a Managed QR, SQRL Code resolves the QR's short code and redirects the scanner to the destination configured by the QR owner.
The SQRL Code application currently does not create scan-analytics records containing scanner IP addresses, user agents, referrers, geographic location, or device information.
IP addresses may be processed temporarily for security or rate-limiting purposes.
Our infrastructure providers may also process standard HTTP request and network information as part of providing hosting, security, logging, and infrastructure services.
6. How We Disclose Information
We do not sell personal information.
We do not share personal information with advertisers or data brokers for cross-context behavioral or targeted advertising.
We may disclose information in the following circumstances.
Service Providers
We use service providers that process information on our behalf to operate SQRL Code.
Current core infrastructure providers include:
- Supabase, for authentication, database services, and private file storage; and
- Vercel, for website and application hosting and infrastructure.
These providers may process information necessary to provide their services to us.
The current application does not contain third-party advertising networks, third-party behavioral analytics platforms, AI-model integrations, or payment processors.
Legal and Safety Reasons
We may disclose information where reasonably necessary to:
- comply with applicable law, regulation, subpoena, court order, or other lawful process;
- protect the rights, property, or safety of SQRL Code, CedanoTech Inc., our users, or others;
- investigate fraud, abuse, security incidents, or violations of our terms; or
- establish, exercise, or defend legal claims.
Business Transactions
If CedanoTech Inc. or SQRL Code is involved in a merger, acquisition, financing, restructuring, sale of assets, or similar corporate transaction, information may be transferred as part of that transaction subject to applicable law.
7. Sensitive Information
SQRL Code is not designed as a repository for sensitive personal information.
You should not encode or store information such as:
- passwords or authentication credentials;
- Social Security numbers or other government identification numbers;
- payment-card or financial-account information;
- medical records or protected health information;
- confidential personal records; or
- other highly sensitive information
in QR codes or associated fields unless you have independently determined that doing so is lawful, appropriate, and adequately protected.
SQRL Code does not currently technically prevent every type of sensitive information from being entered. The product's sensitive-information protections therefore include user warnings rather than comprehensive content detection.
SQRL Code is not represented as HIPAA compliant, HITRUST certified, SOC 2 certified, or suitable for storing protected health information.
8. Data Security
We use administrative and technical measures intended to protect information processed through SQRL Code.
Current technical measures include, where applicable:
- encrypted HTTPS connections;
- authentication and session controls;
- organization-level access controls;
- database row-level security;
- private storage for organization assets;
- authorization checks;
- destination and redirect validation;
- rate limiting;
- audit logging; and
- tenant isolation.
No method of transmission, storage, or security is completely secure, and we cannot guarantee absolute security.
FTC guidance emphasizes collecting only necessary information, protecting it appropriately and disposing of it securely, while New York's SHIELD Act requires covered businesses maintaining private information to implement reasonable safeguards.
9. Data Retention
We retain personal information for as long as reasonably necessary to provide the Services, maintain legitimate business and security records, comply with legal obligations, resolve disputes, and enforce agreements.
Generally:
- Account and workspace information may be retained while your account or organization remains active.
- Managed QR information may be retained while the QR or associated organization remains active.
- Archived QR records and destination history may be retained to preserve workspace history, integrity, security, and auditability.
- Security, audit, and product-event records may be retained for a reasonable period necessary for security, troubleshooting, product operation, and legitimate business purposes.
- Temporary browser-based drafts and logo handoff data remain on the applicable device until cleared through the workflow, application behavior, or browser/site-data controls.
- Information may be retained longer where reasonably necessary for legal compliance, fraud prevention, security, dispute resolution, or the establishment or defense of legal claims.
We may delete or anonymize information when it is no longer reasonably necessary for the purposes for which it was maintained.
10. Your Privacy Choices and Requests
Depending on where you live and applicable law, you may have rights concerning your personal information, which may include rights to:
- request access to personal information we maintain about you;
- request correction of inaccurate personal information;
- request deletion of personal information;
- obtain information about how personal information is collected, used, or disclosed; and
- exercise applicable privacy rights without unlawful discrimination.
SQRL Code does not currently provide self-service account deletion or comprehensive personal-data export functionality.
You may submit a privacy request by contacting:
We may need to verify your identity or authority before fulfilling certain requests. We may also retain information where permitted or required by law.
11. California Privacy
California residents may have additional rights under applicable California privacy laws.
Depending on whether those laws apply to CedanoTech Inc. and the particular request, these rights may include rights to know, access, correct, or delete personal information and rights concerning the sale or sharing of personal information.
CedanoTech Inc. does not sell personal information and does not share personal information for cross-context behavioral advertising.
Accordingly, SQRL Code does not currently provide a “Do Not Sell or Share My Personal Information” mechanism because we do not engage in those practices.
California currently identifies rights including knowing, deletion, correction, opt-out of sale/sharing, and non-discrimination, subject to the law's applicability and exceptions.
Requests may be submitted to privacy@sqrlcode.com.
12. Children's Privacy
SQRL Code is not intended for children under 13 years of age.
We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 in circumstances prohibited by applicable law, we will take appropriate steps to delete it.
If you believe a child under 13 has provided personal information through SQRL Code, contact privacy@sqrlcode.com.
The FTC identifies COPPA as the federal framework providing protections concerning online collection of information from children.
13. International Users
SQRL Code is operated by CedanoTech Inc. and is primarily intended for users and organizations in the United States, although the Services may be accessible from other countries.
If you access SQRL Code from outside the United States, information may be processed in jurisdictions other than the jurisdiction in which you reside.
We do not currently make a representation that user information will be stored exclusively in any particular country, state, or geographic region.
14. Third-Party Destinations
Managed and static QR codes may direct scanners to websites, applications, or services operated by third parties.
CedanoTech Inc. does not control the privacy, security, content, or practices of third-party destinations merely because a QR code created using SQRL Code points to them.
You should review the privacy practices of any third-party service you access.
15. Changes to This Privacy Policy
We may update this Privacy Policy as SQRL Code evolves, our data practices change, or legal requirements change.
When we make changes, we will update the Last Updated date at the top of this Policy. Where required by applicable law, we may provide additional notice of material changes.
We encourage users to review this Privacy Policy periodically.
16. Contact Us
For questions, privacy requests, requests to access, correct, or delete personal information, or concerns regarding this Privacy Policy, contact:
CedanoTech Inc.
SQRL Code Privacy
Email: privacy@sqrlcode.com
