Cookie Policy
Last updated July 13, 2026
This policy explains how Global QR Codes uses cookies and similar technologies, the optional per-QR-code advertising pixels a QR owner can enable, and how you can control your choices at any time.
1. About this Policy
This Cookie Policy explains how Global QR Codes uses cookies and similar technologies across:
- globalqrcodes.com
- app.globalqrcodes.com
- dynamic QR redirect pages operated through Global QR Codes, including routes such as /q/[code]
- authentication, account, dashboard, billing, and QR-management pages
Global QR Codes allows visitors to create, customize, and download QR codes without creating an account.
Registered users may also:
- save and organize QR codes;
- create and manage dynamic QR codes;
- change dynamic QR destinations;
- view scan analytics;
- use folders, tags, templates, and brand kits;
- export analytics;
- collaborate through workspaces;
- invite workspace members;
- purchase and manage paid subscriptions through Stripe;
- enable supported advertising pixels on specific dynamic QR codes.
Some QR code owners may choose to enable third-party advertising technologies on individual dynamic QR codes. Those technologies are not enabled on every QR code and are not used by Global QR Codes for its own advertising.
Global QR Codes is owned and operated by Globe Astral LLC.
This Cookie Policy should be read together with our:
3. Categories of Technologies We Use
3.1 Strictly Necessary Technologies
Strictly necessary technologies are required to operate the service, maintain security, provide features requested by users, and remember privacy choices.
They may be used for:
- authentication and secure sessions;
- keeping users signed in;
- refreshing authenticated sessions;
- protecting private dashboards and workspaces;
- processing login, signup, email confirmation, and password-reset flows;
- enforcing workspace roles and permissions;
- protecting forms and routes from abuse;
- maintaining account and subscription access;
- processing checkout and billing-portal sessions;
- preventing payment fraud;
- remembering website cookie preferences;
- remembering whether a scanner accepted or declined optional QR advertising tracking;
- preserving a QR configuration while a guest signs in or creates an account;
- enabling password-protected QR access;
- supporting core QR generation, saving, editing, redirecting, and dashboard functions.
These technologies are not used by Global QR Codes for behavioral advertising.
Where they qualify as strictly necessary to provide a requested service or maintain security, they generally do not require prior consent.
You may be able to delete or block these technologies through your browser. Doing so may prevent the relevant feature from functioning correctly.
You can change your optional advertising-tracking preference at any time. A minimal preference cookie may remain active after you decline tracking so Global QR Codes can remember not to load advertising providers during later eligible scans.
3.2 Functional Technologies
Functional technologies help remember optional product or interface preferences.
They may be used for:
- interface and display preferences;
- dismissed notices;
- generator settings;
- editor preferences;
- dashboard filters;
- grid or list views;
- sidebar or layout preferences;
- temporary QR configuration;
- other optional convenience features.
Where functional storage is not strictly necessary, it is used in accordance with the consent choices available to you.
3.3 Analytics Technologies
Analytics technologies help us understand how the Global QR Codes website and application perform and how they are used.
Analytics information may include:
- pages viewed;
- general navigation patterns;
- aggregate feature usage;
- browser or device category;
- approximate geographic region;
- traffic source;
- performance and reliability information.
Global QR Codes uses Vercel Web Analytics where enabled in production.
Vercel describes its Web Analytics service as cookie-free and based on anonymized data. It is used to understand aggregate website and application activity rather than to build advertising profiles.
Optional analytics technologies are handled according to their configuration and applicable consent requirements.
3.4 Marketing and Retargeting Technologies
Global QR Codes does not use customer-configured advertising pixels for Global QR Codes’ own advertising.
The owner of a particular dynamic QR code may, however, choose to connect supported third-party advertising technologies to that QR code.
Supported providers may include:
- Meta Pixel;
- Google Tag or Google Ads tag;
- TikTok Pixel;
- LinkedIn Insight Tag.
These technologies may be used by the QR code owner for:
- advertising measurement;
- conversion measurement;
- campaign attribution;
- audience creation;
- remarketing;
- retargeting;
- campaign performance analysis.
LinkedIn describes its Insight Tag as supporting conversion tracking, retargeting, and aggregate audience insights.
Marketing and retargeting technologies:
- are not enabled on every QR code;
- apply only to eligible dynamic QR codes;
- must be enabled individually by an authorized QR code owner;
- are not necessary to open the destination;
- may be blocked by consent choices, Global Privacy Control, browser settings, ad blockers, bot detection, or technical failure;
- do not have guaranteed delivery.
4. Cookies and Similar Technologies We Use
The precise cookie names, storage keys, durations, and provider behavior may vary depending on browser behavior, service configuration, authentication settings, region, and product updates.
| Name or technology | Where used | Provider | Category | Purpose | Duration |
|---|---|---|---|---|---|
| globalqrcodes_consent | globalqrcodes.com and, where configured, app.globalqrcodes.com | Global QR Codes | Strictly Necessary / Privacy Preference | Stores website cookie-category preferences so they do not need to be requested on every visit. | Up to 12 months |
| Authentication and session technologies | Login, signup, authentication callback, application, dashboard, and account pages | Global QR Codes / Supabase | Strictly Necessary | Authenticates users, refreshes sessions, keeps users signed in, protects private routes, and supports workspace access. | Session or as configured |
| Security and anti-abuse technologies | Website, application, authentication, forms, redirects, and protected routes | Global QR Codes / infrastructure providers | Strictly Necessary | Helps protect against unauthorized access, automated abuse, duplicate actions, malicious traffic, fraud, and bots. | Session or as configured |
| QR redirect tracking preference, such as qrpc_<scope> | Pixel-enabled dynamic QR redirect pages | Global QR Codes | Strictly Necessary / Privacy Preference | Remembers whether a scanner accepted or declined optional advertising tracking for a particular workspace or QR owner and provider set. | Up to 180 days |
| Temporary guest QR configuration | Browser session storage where used | Global QR Codes | Strictly Necessary or Functional, depending on context | Preserves a QR configuration while a visitor uses the generator or signs in to save the code. | Until the session ends, the configuration is restored, or storage is cleared |
| Generator and dashboard preferences | Application | Global QR Codes | Functional | Remembers optional interface, display, filter, workflow, or dismissed-notice preferences. | Until cleared or as configured |
| Vercel Web Analytics | Website and application where enabled | Vercel | Analytics | Provides aggregate website and application usage and performance information without traditional analytics cookies. | According to Vercel's configuration |
| Stripe checkout and billing technologies | Stripe Checkout, payment pages, subscription flows, and billing portal | Stripe | Strictly Necessary for the requested transaction | Operates checkout and subscription management, authenticates payment sessions, supports payment security, and helps detect and prevent fraud. | Session-based or longer-lived according to Stripe's configuration |
| Meta Pixel | Eligible pixel-enabled dynamic QR redirects | Meta Platforms | Marketing | Owner-configured advertising measurement, campaign attribution, audience creation, and retargeting. | According to Meta configuration, consent, and browser behavior |
| Google Tag / Google Ads tag | Eligible pixel-enabled dynamic QR redirects | Marketing | Owner-configured advertising measurement, attribution, remarketing, and audience-related functionality. | According to Google configuration, consent, and browser behavior | |
| TikTok Pixel | Eligible pixel-enabled dynamic QR redirects | TikTok | Marketing | Owner-configured conversion measurement, attribution, and audience creation. | According to TikTok configuration, consent, and browser behavior |
| LinkedIn Insight Tag | Eligible pixel-enabled dynamic QR redirects | Marketing | Owner-configured conversion measurement, campaign attribution, website audience creation, and retargeting. | According to LinkedIn configuration, consent, and browser behavior |
5. QR Redirect Consent Preference
The QR redirect preference may contain:
- an accepted or declined status;
- a consent version;
- a workspace or QR-owner consent scope;
- a fingerprint representing the enabled provider set;
- timestamp or expiry information.
It is not intended to contain:
- the QR destination URL;
- the QR code password;
- account passwords;
- authentication tokens;
- scanner email addresses;
- QR owner or workspace-member email addresses;
- raw IP addresses;
- advertising pixel IDs;
- precise geographic coordinates;
- full workspace details.
The cookie name or value may contain a workspace-scoped identifier so that consent for one QR owner is not automatically reused for another unrelated owner.
The preference cookie does not perform advertising tracking by itself. It exists to remember whether optional advertising providers should or should not load.
6. QR Code Retargeting Technologies
6.1 Retargeting Is Enabled Per QR Code
Retargeting is configured separately for each eligible dynamic QR code.
For example:
- one QR code may have Meta Pixel enabled;
- another QR code in the same workspace may have no advertising providers enabled;
- a different QR code may use Google and LinkedIn;
- static QR codes do not support redirect-based retargeting.
Enabling advertising pixels on one QR code does not automatically enable them on another QR code.
6.2 What Happens When a Pixel-Enabled QR Code Is Scanned?
When someone scans an eligible dynamic QR code with retargeting enabled:
- Global QR Codes resolves and validates the destination.
- A privacy-minimized first-party scan event may be recorded.
- Global QR Codes evaluates available regional information, bot status, Global Privacy Control, and the scanner’s stored preference.
- Where prior consent is required, no supported advertising provider loads before the scanner accepts.
- The scanner may choose "Accept and continue" or "Continue without tracking".
- The scanner is redirected after either choice.
- Supported providers load only where permitted by the visitor’s choice, applicable regional rules, provider configuration, browser settings, and technical availability.
Declining advertising tracking does not prevent the destination from opening.
Dynamic QR codes without enabled advertising pixels use the normal redirect flow and do not require an advertising-consent interstitial.
6.3 Scanner Disclosure
A pixel-enabled redirect may display wording such as:
“This QR code’s owner has enabled optional advertising tracking through selected third-party providers. You can continue with or without this tracking.”
The redirect page may also display:
- the destination hostname;
- a Privacy details link;
- a Manage tracking preferences control;
- a Continue to destination button or link.
7. Managing QR Tracking Preferences
Pixel-enabled redirect pages may include a Manage tracking preferences control.
A scanner may choose:
- Don’t track me
- Allow tracking
Choosing Don’t track me updates the stored preference for the relevant workspace or QR owner and provider set.
That decision prevents future supported advertising providers from loading for the same consent scope until:
- the choice expires;
- the scanner changes the choice;
- browser storage is deleted;
- the consent version changes;
- the enabled provider set materially changes.
Consent is scoped to the relevant workspace or QR owner. A preference for one workspace is not automatically treated as permission for an unrelated workspace.
If the QR owner adds or removes a supported advertising provider, the scanner may be asked again because the tracking scope has changed.
Correcting or replacing an identifier for an already-enabled provider may not require a new choice where the provider set and relevant purpose remain the same.
Withdrawal applies to future advertising tracking. It does not necessarily reverse or delete events that were already sent before the preference was changed.
Global QR Codes does not load an advertising provider solely to notify it of a later withdrawal.
8. Global Privacy Control and Do Not Track
8.1 Global Privacy Control
Where applicable and technically available, Global QR Codes honors Global Privacy Control signals, including signals such as Sec-GPC: 1.
When an applicable GPC signal is detected:
- owner-configured advertising providers do not load;
- a previous acceptance does not override the signal;
- the scanner continues to the destination;
- core service functionality remains available.
8.2 Do Not Track
Some browsers provide a separate Do Not Track signal.
There is no universally adopted technical standard governing how every service must respond to Do Not Track.
Global QR Codes does not currently treat Do Not Track as a replacement for its consent and preference controls.
We continue to honor:
- choices made through Global QR Codes consent controls;
- QR tracking preferences;
- applicable Global Privacy Control signals.
9. First-Party QR Scan Analytics
Global QR Codes may record privacy-minimized server-side analytics when an eligible dynamic QR code is scanned.
Depending on availability, the scan record may include:
- timestamp;
- country;
- city;
- device category;
- operating system;
- browser;
- referral domain;
- language;
- bot classification;
- scan result.
Global QR Codes does not intentionally store the following as part of scan analytics:
- raw IP addresses;
- precise latitude or longitude;
- full browser fingerprints;
- scanner email addresses;
- customer account emails;
- workspace-member emails;
- account passwords;
- authentication tokens.
First-party scan analytics are separate from optional Meta, Google, TikTok, or LinkedIn advertising pixels.
A privacy-minimized first-party scan event may still be recorded when a scanner declines third-party advertising tracking, subject to applicable law and the practices described in our Privacy Policy.
Bots and automated preview agents may be classified separately and excluded from ordinary customer analytics.
10. Stripe Payments and Subscription Billing
Global QR Codes uses Stripe to process subscription payments and manage billing.
Stripe may be used when a user:
- begins checkout;
- purchases a paid subscription;
- changes a subscription;
- updates a payment method;
- manages billing information;
- opens the Stripe billing portal;
- completes another payment-related action.
Stripe may use cookies and similar technologies to:
- operate checkout;
- authenticate payment sessions;
- process payments;
- maintain security;
- detect and prevent fraud;
- identify suspicious activity;
- remember information necessary during a transaction;
- provide and improve Stripe’s payment services.
Stripe states that its payment interfaces may collect information about interactions with checkout elements and may use cookies and IP addresses to provide services and prevent fraud.
Stripe may process information such as:
- browser and device information;
- IP address;
- checkout interaction data;
- payment-related identifiers;
- fraud-prevention and security signals;
- transaction and subscription information.
Global QR Codes does not receive or store complete payment-card numbers. Payment-card information is submitted to and processed by Stripe.
Technologies required to securely process a requested payment, authenticate checkout, prevent fraud, or operate a billing session are treated as strictly necessary for that transaction.
Stripe’s handling of personal data is also governed by Stripe’s own privacy and cookie notices.
11. Other Third-Party Services
11.1 Supabase
Global QR Codes uses Supabase for:
- authentication;
- session management;
- database services;
- storage;
- account functionality;
- workspace access controls.
Supabase may process cookies or session information necessary to:
- create accounts;
- authenticate users;
- refresh sessions;
- support email confirmation;
- support password reset;
- protect dashboard routes;
- enforce account and workspace access.
These technologies are treated as strictly necessary.
11.2 Vercel
Global QR Codes uses Vercel for hosting, deployment, and related infrastructure.
Where Vercel Web Analytics is enabled, Vercel may process anonymized aggregate information relating to website and application activity and performance. Vercel states that its Web Analytics product does not use cookies.
11.3 Meta
Where a QR owner enables Meta Pixel on a specific dynamic QR code, Meta may process information for advertising measurement, conversion tracking, attribution, audience creation, and retargeting according to:
- the QR owner’s configuration;
- the scanner’s consent or privacy choice;
- applicable regional rules;
- browser settings;
- Meta’s own terms and policies.
11.4 Google
Where a QR owner enables a Google advertising tag, Google may process information for advertising measurement, attribution, remarketing, or related advertising purposes.
Global QR Codes uses consent-aware loading and Google Consent Mode signals where implemented so Google tag behavior can respond to the scanner’s preference. Google describes Consent Mode as a way to adjust tag behavior based on user consent choices.
11.5 TikTok
Where a QR owner enables TikTok Pixel on a specific dynamic QR code, TikTok may process information for advertising measurement, conversion tracking, attribution, and audience-related purposes according to the owner’s configuration and the scanner’s applicable choices.
11.6 LinkedIn
Where a QR owner enables LinkedIn Insight Tag on a specific dynamic QR code, LinkedIn may process information for:
- conversion measurement;
- campaign attribution;
- website audience creation;
- retargeting;
- aggregate campaign insights.
LinkedIn notes that Insight Tag functionality can involve first-party cookies or identifiers depending on how the advertiser configures it.
11.7 Security and Infrastructure Providers
Global QR Codes may use hosting, security, logging, fraud-prevention, rate-limiting, and infrastructure services that process technical information necessary to keep the service secure, reliable, and available.
12. Managing Website Cookie Preferences
When you first visit Global QR Codes, you may see a cookie consent interface.
Depending on the technologies active in the relevant deployment, you may be able to:
- accept optional technologies;
- reject non-essential technologies;
- enable or disable Analytics;
- enable or disable Functional technologies;
- enable or disable Marketing technologies;
- reopen Cookie settings later.
Your website preference may be stored in globalqrcodes_consent for up to 12 months.
Where configured, that preference may be shared between:
- globalqrcodes.com
- app.globalqrcodes.com
The normal website preference is separate from the workspace-scoped QR redirect preference.
Accepting website cookies does not automatically authorize owner-configured advertising tracking for unrelated QR owners.
13. Browser Controls
Most browsers allow users to:
- view stored cookies;
- delete individual or all cookies;
- block third-party cookies;
- block cookies from selected websites;
- block all cookies;
- clear local storage;
- clear session storage.
Blocking all cookies or necessary browser storage may affect:
- signup and login;
- session persistence;
- email confirmation;
- password reset;
- account security;
- private dashboard access;
- workspace functionality;
- saved QR management;
- subscription checkout;
- billing-portal access;
- temporary QR configuration;
- QR tracking-preference storage.
Clearing cookies may cause Global QR Codes to request your preferences again.
14. QR Owner Responsibilities
A QR owner who enables supported advertising pixels is responsible for:
- using advertising identifiers they are authorized to use;
- complying with applicable privacy and advertising laws;
- providing notices required for their audience;
- maintaining an accurate privacy or cookie notice where required;
- selecting providers appropriately;
- using retargeting features only for lawful purposes;
- respecting visitor rights;
- complying with provider terms;
- responding appropriately to requests relating to their advertising activities.
Global QR Codes requires an authorized QR owner to provide an attestation before advertising pixels can be enabled or materially updated.
That attestation does not replace scanner consent where consent is legally required.
Global QR Codes provides consent-aware technical controls but does not determine every QR owner’s independent legal obligations.
15. Changes to this Policy
We may update this Cookie Policy when:
- product functionality changes;
- cookie or storage practices change;
- subscription or billing functionality changes;
- new providers are introduced;
- retargeting functionality changes;
- our infrastructure changes;
- legal or regulatory requirements change.
The “Last updated” date shows when this policy was most recently revised.
Where appropriate, material changes may be communicated through:
- the website;
- the application;
- the cookie banner;
- account notices;
- email;
- another reasonable method.
16. Contact
For questions about this Cookie Policy or our use of cookies and similar technologies, contact:
Globe Astral LLC
Email: legal@globalqrcodes.com
You may also review our:
