Privacy Policy
Last updated July 2026
This Privacy Policy explains how we collect, use, disclose and safeguard your information when you use Global QR Codes.
Global QR Codes ("Global QR Codes", "we", "us" or "our") is a product owned and operated by Globe Astral LLC, a Wyoming limited liability company. We are the controller responsible for your personal data. By using our website, generator and related services (the "Service") you agree to the practices described in this policy.
1. Information we collect
We collect only the information we need to provide the Service. The categories of personal data we may process are:
Information you provide
- Account data — such as your name, email address and password (stored only in hashed form) when you create an account.
- QR code content — the URLs, text, WiFi details, contact cards and other data you choose to encode. Static QR codes are generated in your browser; saved and dynamic codes are stored in your account.
- Billing data — when you subscribe to a paid plan, your payment is processed by Stripe. We receive limited billing details such as your billing name, country, the last four digits of your card and subscription status. We never receive or store your full card number.
- Communications — the content of messages you send us through support, email or forms.
Information collected automatically
- Scan analytics — for dynamic QR codes we record aggregate scan events, including timestamp, approximate country or city (derived from IP, which is not stored in raw form), device type, operating system and browser. Individuals are not personally identified.
- Usage and technical data — such as pages visited, referring pages, and general device and browser information, used to operate and improve the Service.
- Cookies and similar technologies — see the Cookies section below.
2. How we use your information
We use personal data to:
- Provide, operate and maintain the Service, including generating, saving and serving your QR codes.
- Redirect dynamic QR codes and produce the scan analytics shown in your dashboard.
- Process subscriptions, payments, invoices and renewals through our payment processor.
- Authenticate you, secure your account and prevent fraud or abuse.
- Respond to your enquiries and provide customer support.
- Send service and transactional messages, and — where you have opted in — product updates.
- Comply with our legal obligations and enforce our terms.
3. Legal bases for processing
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR:
- Performance of a contract — to provide the Service and manage your account and subscription.
- Consent — for optional analytics and marketing cookies, for marketing emails, and for third-party advertising/retargeting pixels that a QR code owner has enabled on a dynamic code. You may withdraw consent at any time, including by declining on the redirect screen or by sending a Global Privacy Control signal.
- Legitimate interests — to secure, maintain and improve the Service, provided your rights do not override those interests.
- Legal obligation — to comply with applicable laws, tax and accounting requirements.
5. Retargeting pixels on dynamic QR codes
Business users on our paid plans can choose to add their own third-party advertising pixels — currently Meta (Facebook) Pixel, Google tag, TikTok Pixel and the LinkedIn Insight Tag — to their dynamic QR codes. This is an optional feature that is switched off by default. We do not use these pixels on this website or for our own marketing.
When a code has retargeting pixels enabled, scanning it briefly loads a redirect page before forwarding to the destination. On that page, and subject to the consent rules below, the advertising pixels configured by the QR code's owner may load in your browser and send information to the relevant advertising platform. These pixels and any related cookies are set by the advertising platform, not by us. The information typically includes your IP address, device and browser details, the fact that you visited, and cookies or identifiers set by those platforms. This allows the QR code's owner to measure campaigns and build retargeting audiences on those platforms.
Who is responsible
Where a QR code owner enables pixels, that owner decides why and how this data is used and is the party responsible for it under data protection law. The advertising platforms process the data under their own privacy policies and terms as independent or joint controllers with that owner. We provide the technical means to enable pixels and to obtain your consent; we do not receive the resulting advertising data.
Your choices
- If you are in the EEA, the UK or Switzerland, no advertising pixel loads until you select "Accept & continue" on the consent screen. If you choose "Continue without tracking", no pixels load and you are sent straight to the destination.
- In other regions, you are shown a notice and can decline; where you decline, no pixels load.
- We honour the Global Privacy Control (GPC) signal. If your browser sends GPC, advertising pixels are not loaded.
- Automated traffic and bots are excluded, and your choice is remembered for that QR code owner so you are not repeatedly prompted.
- For Google tags we use Google Consent Mode, so consent signals are passed to Google.
7. Payment processing
Paid subscriptions are handled by Stripe, Inc., a PCI-DSS Level 1 certified payment processor. When you subscribe, your card details are collected and processed directly by Stripe under its own privacy policy and terms. We never receive or store your full card number, CVC or expiry date — we retain only limited subscription and billing metadata needed to manage your plan and comply with tax and accounting rules.
8. Data retention
We retain personal data only for as long as necessary for the purposes described in this policy. Account and QR code data are kept while your account is active and deleted within a reasonable period after you delete your account or the data. Aggregate scan analytics may be retained in de-identified form. Billing and transaction records are kept for as long as required by tax and accounting laws.
9. Data security
We implement appropriate technical and organisational measures to protect personal data, including encryption in transit (HTTPS), hashed passwords, access controls and reputable infrastructure providers. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your data and to notify you and regulators of qualifying breaches as required by law.
10. International data transfers
We are based in the United States and use service providers that may process data in the United States and other countries. Where we transfer personal data out of the EEA or the UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and equivalent UK mechanisms.
11. Your privacy rights
EEA / UK residents (GDPR)
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your personal data.
- Restriction and objection — restrict or object to certain processing.
- Portability — receive your data in a portable format.
- Withdraw consent — where processing is based on consent.
- Lodge a complaint — with your local data protection authority.
California residents (CCPA/CPRA)
- Know what personal information we collect, use and disclose.
- Request deletion or correction of your personal information.
- Opt out of any sale or sharing of personal information — we do not sell your personal information. Where a QR code owner has enabled retargeting pixels, scanning that code may involve "sharing" for cross-context behavioural advertising; we honour Global Privacy Control signals and the choices you make on the redirect screen to opt out.
- Non-discrimination for exercising your rights.
To exercise any of these rights, contact us using the details in the Contact section. We will respond within the timeframes required by applicable law.
12. Children's privacy
The Service is not directed to children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
13. Third-party links
The Service and the destinations that QR codes point to may link to third-party websites and services that we do not control. This policy does not apply to those third parties, and we encourage you to review their privacy policies.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes we will update the "Last updated" date and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
15. Contact us
If you have questions about this policy or wish to exercise your rights, contact us at:
Globe Astral LLC (Global QR Codes)
Wyoming, United States
Email: privacy@globalqrcodes.com
Or use our contact page.
