This Privacy Policy explains what personal data QR Code Connect processes, why we process it, and the choices you have. We wrote it to be read, not to be survived: plain language first, legal precision second.
If you simply scan a QR code and read a page, we never store your IP address. We store an irreversible hash of it, plus coarse technical facts (country, device type, browser, language) so that the institution behind the code knows how many people visited. Analytics and the AI Guide only run if you accept them in the cookie banner. If you let the map use your location, those coordinates stay in your browser and never reach us. We do not build advertising profiles and we do not sell data.
1. Who we are
QR Code Connect is a platform that lets cultural institutions, cities, tourism agencies and individual creators publish content behind QR codes placed on physical objects and locations.
The controller responsible for the personal data described in this policy is:
[COMPANY LEGAL NAME]
[REGISTERED ADDRESS]
[POSTAL CODE, CITY, COUNTRY]
Company / VAT registration number: [COMPANY REGISTRATION NUMBER]
Privacy contact: [PRIVACY CONTACT EMAIL] · [CONTACT PHONE]
Data Protection Officer: [DPO NAME AND CONTACT, OR "no DPO appointed"]
2. Two kinds of people, two different policies
This policy covers two very different relationships, and it matters which one applies to you.
- Visitors. You scanned a QR code on an exhibit, a monument or a street sign and landed on a public page. You have no account and you give us no name. Sections 3 to 8 apply to you.
- Account holders. You are a museum, a city, a tourism agency or an individual creator with a login on the platform. Sections 9 onwards apply to you in addition.
When an institution publishes content through QR Code Connect, that institution decides what to publish; we provide the technical platform.
3. What we collect when you scan a QR code
Every view of a public QR page can be recorded so the institution knows whether its codes are being used. Here is the complete list of what is stored.
3.1 Page views
For each view we store a record containing:
- A session hash — computed as
sha256(IP address | User-Agent | secret salt). The raw IP address is never stored. The hash lets us tell two visits apart without knowing who either visitor is, and it cannot be reversed back into an IP address. - Country (ISO two-letter code) and city, derived at the moment of the visit.
- Device type (mobile, tablet or desktop), operating system and browser.
- Browser language and referrer (the page you arrived from, if any).
- Timestamp of the view.
3.2 Interaction events
If you use a feature on the page, an event is recorded: its type (for example playing the audio guide, clicking a directions link, or opening an external link), an optional value, structured metadata, the page language and the time.
3.3 Daily aggregates
Overnight, individual records are rolled up into daily totals per QR code: views, unique visitors, breakdowns by country, language, device, operating system and hour of day, event counts, average time on page, the percentage of audio and video actually listened to or watched, and clicks on navigation and outbound links. These aggregates contain no identifiers at all.
| What is stored | Where | Contains an identifier? | Kept for |
|---|---|---|---|
| Page views (session hash, country, city, device, OS, browser, language, referrer, time) | qr_code_views | Pseudonymous hash only — never a raw IP | [RETENTION PERIOD] |
| Interaction events (type, value, metadata, language, time) | qr_code_events | Pseudonymous hash only | [RETENTION PERIOD] |
| Daily aggregates (totals and breakdowns per QR code) | qr_code_stats_daily | No | [RETENTION PERIOD] |
| Consent records (session hash, analytics yes/no, chatbot yes/no, user agent, time) | consent_logs | Pseudonymous hash only | [RETENTION PERIOD] |
| Account and profile data, uploaded media, QR content, invoices, credit balance | Account tables | Yes | For the life of the account, then [RETENTION PERIOD] |
| Your GPS coordinates from the map | Nowhere — never written to our database | — | — |
Retention periods are not yet fixed. The operator must decide, for each row above, how long records are kept before deletion or anonymisation, and replace [RETENTION PERIOD] with a concrete figure.
4. Location, the map and "Take me there"
Public QR pages and city maps show a map of nearby points, the distance to each one, and a "Take me there" link. To measure a distance from where you actually are, the page needs your position — and that is the one moment when your browser asks for permission to access your location.
4.1 When permission is asked
Only when you ask for it. The map does not request your location while the page is loading. The browser's standard location prompt appears after you press the "use my location" control on the map. If you never press it, no location request is ever made.
4.2 What your coordinates are used for
If you allow it, the browser hands your coordinates to the map script running on your own device. They are used for exactly two things:
- to centre the map on you and calculate the straight-line distance to each nearby point;
- to build the "Take me there" link, by placing your position as the starting point in the navigation URL.
Your GPS coordinates are never sent to our servers and never written to our database. The tables that record visits (qr_code_views) and interactions (qr_code_events) have no column for latitude or longitude, and the map sends nothing more than the fact that a directions link was clicked. The only location-like information we store is the country and city derived from the network request itself, alongside the irreversible hash described in Section 3 — and that happens whether or not you ever touch the map.
4.3 If you refuse — the map still works
Declining costs you nothing but precision. When there is no GPS position, the map falls back, in order, to the location of the QR code you are currently standing at (the reasonable assumption being that you are next to it), or to a point you tap on the map yourself. Distances and the "Take me there" link keep working from that starting point.
4.4 Withdrawing the permission
Location permission is granted to a website by your browser, not by us, so it is withdrawn in the browser. In most browsers you tap the padlock or the information icon next to the address bar and set Location back to "Ask" or "Block"; on mobile the same setting also exists under the browser app's site settings. We cannot see, change or retain that permission.
4.5 Leaving for a navigation service
Pressing "Take me there" opens Google Maps in a new tab or in the Google Maps app. At that point you have left our platform: what Google receives, stores and shows is governed by Google's own terms and privacy policy, not by ours. The link we hand over contains the destination and, if a starting point is known, that starting point.
4.6 Map tiles
The map images themselves are loaded from a third-party tile service (CARTO basemaps, built on OpenStreetMap data). As with any image loaded from another domain, that service receives the technical request data needed to deliver the tiles, including your IP address. It receives no account data and no analytics from us.
5. What we deliberately do not do
- We do not store raw IP addresses of visitors.
- We do not store your GPS coordinates, and we do not track your movement between QR codes.
- We do not build profiles of individual people and we do not attempt to identify visitors.
- We do not run advertising trackers, retargeting pixels or ad networks.
- We do not sell, rent or share visitor data with advertisers or data brokers.
- We do not use automated decision-making that produces legal or similarly significant effects on people.
6. Consent and cookies
The first time you open a public page you see a consent banner with three choices: Settings, Decline and Accept all.
- Analytics (the page views, events and aggregates described in Section 3) run only if you allow them.
- The AI Guide chatbot loads only if you allow it.
- If you decline, the page still works; you simply read it without analytics and without the chatbot.
Your answer is recorded in a consent log containing the session hash, whether analytics was allowed, whether the chatbot was allowed, your user agent and the time. That record is what proves your choice was respected.
You can change your mind at any time using the Manage cookies button at the bottom of this page.
7. Artificial intelligence
QR Code Connect uses OpenAI GPT-4o-mini in three places: the public AI Guide chatbot on QR pages, description and keyword generation inside the admin panel, and the AI Advisor in the statistics section. When you ask the AI Guide a question, your question and the relevant information about the object are sent to the OpenAI API so that an answer can be generated.
AI output can be wrong and must be checked by a human. AI suggestions are never published automatically, and AI is never used to make decisions about people.
A full, dedicated explanation is on our AI Transparency page.
8. The audio guide
The spoken audio guide uses SpeechSynthesis, the Web Speech API built into your browser. The speech is produced on your own device. The text is not sent to our servers for synthesis, and it is not sent to OpenAI. Voice quality and available languages depend on your browser and operating system, not on us.
9. Data we hold about account holders
Accounts on the platform are one of four types: institution, city, agency or individual. For each account we store:
- Profile information: name, address, contact details, logo and cover image.
- Media uploaded to the library.
- QR codes and all content attached to them, including collections.
- Invoices issued through the platform, generated as PDF documents.
- The credit balance and its transaction history.
This data exists because it is necessary to provide the service you signed up for. It is visible to the account owner, to users the owner has invited, and to platform administrators for support and billing purposes.
10. Legal bases
| Processing | Legal basis (GDPR Art. 6) |
|---|---|
| Analytics on public QR pages | Consent — Art. 6(1)(a) |
| AI Guide chatbot | Consent — Art. 6(1)(a) |
| Operating an account, publishing content, issuing invoices | Contract — Art. 6(1)(b) |
| Keeping invoices and accounting records | Legal obligation — Art. 6(1)(c) |
| Keeping the platform secure and abuse-free | Legitimate interests — Art. 6(1)(f) |
| Map location permission | No legal basis is needed on our side — the coordinates are processed only in your browser and are never received by us |
11. Service providers
We use a small number of external providers to run the platform. The one that processes content on our instruction is OpenAI, which generates AI responses as described in Section 7. Map tiles are served by CARTO and navigation links hand you over to Google Maps, both as described in Section 4.
The operator must list the remaining processors and the safeguards that apply to them, and replace the following placeholders with verified facts: [HOSTING PROVIDER, COUNTRY AND DATA CENTRE LOCATION], [EMAIL DELIVERY PROVIDER], [PAYMENT PROVIDER, IF ANY], and [TRANSFER SAFEGUARD FOR NON-EU PROCESSORS — e.g. Standard Contractual Clauses, adequacy decision]. Nothing about hosting location or transfer mechanisms should be published until it has been confirmed.
12. Your rights
If you are in the EU, the EEA, Switzerland or the United Kingdom, you have the right to request access to your personal data, correction, erasure, restriction of processing, portability, and to object to processing based on legitimate interests. Where processing rests on consent, you may withdraw that consent at any time without affecting what was done before.
For a visitor who only scanned a QR code, we hold no name, no email and no IP address — only an irreversible hash. That means we usually cannot connect a request to a specific record, and we are not obliged to collect additional data purely in order to identify you (GDPR Art. 11). If you want your data gone, declining analytics in the banner is the effective step.
To exercise a right, write to [PRIVACY CONTACT EMAIL]. You also have the right to complain to your national supervisory authority.
13. Security
The platform is served over HTTPS, passwords are stored hashed, administrative functions require authentication, and visitor IP addresses are hashed with a secret salt before they ever reach the database. No system is perfectly secure, but pseudonymising at the point of collection means a database compromise does not expose visitor IP addresses.
14. Children
The platform is not directed at children and we do not knowingly collect personal data from children. Content published through QR Code Connect may include a simplified "for kids" version of a description; that is a presentation choice made by the publishing institution and involves no additional data collection.
15. Changes to this policy
When this policy changes materially we update the "last updated" date at the top of the page and, for account holders, notify by email. Continued use after an update means the updated policy applies.
16. Contact
Questions about this policy, or about data we hold, go to:
[COMPANY LEGAL NAME] — [PRIVACY CONTACT EMAIL] — [REGISTERED ADDRESS]
Your cookie and AI choices
Analytics and the AI Guide run only with your consent. You can change your answer at any time.