Privacy Policy

Last updated July 2026

This Privacy Policy explains how we collect, use, disclose and safeguard your information when you use Global QR Codes.

Global QR Codes ("Global QR Codes", "we", "us" or "our") is a product owned and operated by Globe Astral LLC, a Wyoming limited liability company. We are the controller responsible for your personal data. By using our website, generator and related services (the "Service") you agree to the practices described in this policy.

1. Information we collect

We collect only the information we need to provide the Service. The categories of personal data we may process are:

Information you provide

  • Account data — such as your name, email address and password (stored only in hashed form) when you create an account.
  • QR code content — the URLs, text, WiFi details, contact cards and other data you choose to encode. Static QR codes are generated in your browser; saved and dynamic codes are stored in your account.
  • Billing data — when you subscribe to a paid plan, your payment is processed by Stripe. We receive limited billing details such as your billing name, country, the last four digits of your card and subscription status. We never receive or store your full card number.
  • Communications — the content of messages you send us through support, email or forms.

Information collected automatically

  • Scan analytics — for dynamic QR codes we record aggregate scan events, including timestamp, approximate country or city (derived from IP, which is not stored in raw form), device type, operating system and browser. Individuals are not personally identified.
  • Usage and technical data — such as pages visited, referring pages, and general device and browser information, used to operate and improve the Service.
  • Cookies and similar technologies — see the Cookies section below.

2. How we use your information

We use personal data to:

  • Provide, operate and maintain the Service, including generating, saving and serving your QR codes.
  • Redirect dynamic QR codes and produce the scan analytics shown in your dashboard.
  • Process subscriptions, payments, invoices and renewals through our payment processor.
  • Authenticate you, secure your account and prevent fraud or abuse.
  • Respond to your enquiries and provide customer support.
  • Send service and transactional messages, and — where you have opted in — product updates.
  • Comply with our legal obligations and enforce our terms.

4. Cookies and tracking

We keep our use of cookies to a minimum. Only one strictly necessary first-party cookie is set without your consent, and optional analytics load only after you opt in through our consent banner. For the full list of cookies, their providers, purposes and retention periods, and to change your choices at any time, see our Cookie Policy.

5. Retargeting pixels on dynamic QR codes

Business users on our paid plans can choose to add their own third-party advertising pixels — currently Meta (Facebook) Pixel, Google tag, TikTok Pixel and the LinkedIn Insight Tag — to their dynamic QR codes. This is an optional feature that is switched off by default. We do not use these pixels on this website or for our own marketing.

When a code has retargeting pixels enabled, scanning it briefly loads a redirect page before forwarding to the destination. On that page, and subject to the consent rules below, the advertising pixels configured by the QR code's owner may load in your browser and send information to the relevant advertising platform. These pixels and any related cookies are set by the advertising platform, not by us. The information typically includes your IP address, device and browser details, the fact that you visited, and cookies or identifiers set by those platforms. This allows the QR code's owner to measure campaigns and build retargeting audiences on those platforms.

Who is responsible

Where a QR code owner enables pixels, that owner decides why and how this data is used and is the party responsible for it under data protection law. The advertising platforms process the data under their own privacy policies and terms as independent or joint controllers with that owner. We provide the technical means to enable pixels and to obtain your consent; we do not receive the resulting advertising data.

Your choices

  • If you are in the EEA, the UK or Switzerland, no advertising pixel loads until you select "Accept & continue" on the consent screen. If you choose "Continue without tracking", no pixels load and you are sent straight to the destination.
  • In other regions, you are shown a notice and can decline; where you decline, no pixels load.
  • We honour the Global Privacy Control (GPC) signal. If your browser sends GPC, advertising pixels are not loaded.
  • Automated traffic and bots are excluded, and your choice is remembered for that QR code owner so you are not repeatedly prompted.
  • For Google tags we use Google Consent Mode, so consent signals are passed to Google.

6. How we share your information

We do not sell your personal data, and we do not use advertising pixels for our own marketing. However, where a business user enables third-party retargeting pixels on their dynamic QR code, scanning that code may — with your consent, or where you have not opted out in regions that permit it — result in information being shared with advertising platforms such as Meta, Google, TikTok or LinkedIn. That sharing is controlled by the QR code's owner. Under certain US state privacy laws this may constitute "sharing" for cross-context behavioural advertising; you can opt out at any time by declining on the redirect screen or by sending a Global Privacy Control signal.

We otherwise share personal data only with:

  • Service providers (subprocessors) — including Stripe for payment processing, Vercel for hosting, content delivery and privacy-friendly analytics, and Supabase for database and authentication. These providers process data on our behalf under contract.
  • Legal and safety — where required by law, legal process, or to protect the rights, property or safety of Globe Astral LLC, our users or the public.
  • Business transfers — in connection with a merger, acquisition, financing or sale of assets, subject to this policy.

Our processing of personal data on behalf of business customers is governed by our Data Processing Addendum.

7. Payment processing

Paid subscriptions are handled by Stripe, Inc., a PCI-DSS Level 1 certified payment processor. When you subscribe, your card details are collected and processed directly by Stripe under its own privacy policy and terms. We never receive or store your full card number, CVC or expiry date — we retain only limited subscription and billing metadata needed to manage your plan and comply with tax and accounting rules.

8. Data retention

We retain personal data only for as long as necessary for the purposes described in this policy. Account and QR code data are kept while your account is active and deleted within a reasonable period after you delete your account or the data. Aggregate scan analytics may be retained in de-identified form. Billing and transaction records are kept for as long as required by tax and accounting laws.

9. Data security

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit (HTTPS), hashed passwords, access controls and reputable infrastructure providers. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your data and to notify you and regulators of qualifying breaches as required by law.

10. International data transfers

We are based in the United States and use service providers that may process data in the United States and other countries. Where we transfer personal data out of the EEA or the UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and equivalent UK mechanisms.

11. Your privacy rights

EEA / UK residents (GDPR)

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your personal data.
  • Restriction and objection — restrict or object to certain processing.
  • Portability — receive your data in a portable format.
  • Withdraw consent — where processing is based on consent.
  • Lodge a complaint — with your local data protection authority.

California residents (CCPA/CPRA)

  • Know what personal information we collect, use and disclose.
  • Request deletion or correction of your personal information.
  • Opt out of any sale or sharing of personal information — we do not sell your personal information. Where a QR code owner has enabled retargeting pixels, scanning that code may involve "sharing" for cross-context behavioural advertising; we honour Global Privacy Control signals and the choices you make on the redirect screen to opt out.
  • Non-discrimination for exercising your rights.

To exercise any of these rights, contact us using the details in the Contact section. We will respond within the timeframes required by applicable law.

12. Children's privacy

The Service is not directed to children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

14. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes we will update the "Last updated" date and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

15. Contact us

If you have questions about this policy or wish to exercise your rights, contact us at:

Globe Astral LLC (Global QR Codes)
Wyoming, United States
Email: privacy@globalqrcodes.com
Or use our contact page.