Privacy Policy

Last updated: 1 January 2026

This policy explains what MakeTheQR collects, why, and what happens to it. If anything here is unclear, email contact@maketheqr.com and we will answer plainly.

What we collect

  • Account details. Your email address, and your name and profile photo if you sign in with a provider that supplies them. Authentication is handled by Google Firebase; we never see or store your password.
  • Content you create. The batches you make, the codes in them, and any images you upload.
  • Payment details. Handled entirely by Stripe. We store only the identifiers Stripe gives us (a customer id, a subscription id) and never card numbers.
  • Usage data. Pages viewed and actions taken inside the product, used to work out which parts are confusing. This is product analytics, not advertising profiling.
  • Technical data. IP address, browser and device type in server logs, retained short-term for security and debugging.

What we do with it

We use it to run the service: authenticate you, store and display your batches, take payment, send transactional email (receipts, password resets, account notices), and fix bugs.

We do not sell your data, and we do not advertise to your visitors. The people who open a batch you share are not profiled by us.

Anonymous batches

You can create a batch without an account. When you do, we store the batch and a token in your browser that proves you own it. If you clear your browser data before claiming the batch with an email, we have no way to link it back to you and it cannot be recovered.

What is public

A batch you share is public to anyone with the link, including search engines, unless you turn public access off in its settings. Anything you put in a public batch - names, images, numbers - should be treated as published.

Who else processes your data

  • Google Firebase — authentication
  • Stripe — payments
  • PostHog — product analytics
  • Cloudflare — CDN and file storage
  • Our hosting provider — servers and database

Each is a processor acting on our instructions, and each publishes its own privacy documentation.

Retention

Account and content data is kept while your account exists. Delete your account and we delete your batches and uploads. Records we are legally required to keep - invoices and tax records in particular - are retained for the statutory period.

Your rights

You can request a copy of your data, ask us to correct it, or ask us to delete it, by emailing contact@maketheqr.com. If you are in the UK, EU, or a US state with a comparable law, those statutory rights apply to you and we will honour them within the required time.

Children

MakeTheQR is not directed at children under 13, and we do not knowingly collect their data. Educators using it with a class should add codes themselves rather than have pupils create accounts.

Cookies

We use cookies and local storage for sign-in sessions, for remembering an anonymous batch you own, and for product analytics. We do not use advertising cookies.

Changes

If this policy changes materially we will update the date at the top and, where the change affects how your data is used, tell you by email.


See also our Terms of Service.