Legal

Privacy Policy

Last updated July 21, 2026

This policy explains what CQRG collects, why we collect it, who we share it with, and the choices you have. We have tried to write it in plain language rather than legalese.

1. Who we are

CQRG (“we”, “us”) operates this website and the QR code generator, analytics, and blog available on it. For any privacy question you can reach us at privacy@cloudqrgen.com. This policy applies to https://cloudqrgen.com and all of its subpages.

2. Information we collect

Information you give us

  • Account details. If you create an account, we store your email address and (optionally) your name. Passwords are never stored in readable form. We keep only a salted scrypt hash, which cannot be reversed back into your password.
  • QR code content. If you choose to save a QR code, we store the content you encoded (for example a URL or Wi-Fi name) and its visual settings so the code can be regenerated and, where applicable, tracked. QR codes you generate without saving are created entirely in your browser and never reach our servers.
  • Messages. If you email us for support, we keep that correspondence so we can answer you and follow up.

Information collected automatically

  • Scan analytics. When someone scans a tracked QR code, we record the time of the scan, the coarse device category (mobile, tablet, or desktop), the operating system name, and the country supplied by our hosting provider’s network layer. We do not store the scanner’s IP address, precise location, or any identifier that would let us recognise the same person across different scans.
  • Security and abuse prevention. Our servers process IP addresses transiently to apply rate limits and block automated abuse. These are held in memory only and are not written to our database or linked to your account.
  • Advertising data. Our advertising partner may collect data through your browser as described in section 5.

3. How we use your information

We use the data above only to:

  • provide the generator, saved QR codes, and scan analytics;
  • keep you signed in and secure your account;
  • respond to support requests;
  • detect, prevent, and investigate abuse, fraud, and security incidents;
  • display advertising that keeps the free tools free;
  • understand which pages and features are used, in aggregate, so we can improve them.

We do not sell your personal information, and we do not use your email address for marketing you did not ask for.

4. Cookies and similar technologies

We use a small number of cookies, in three categories:

  • Strictly necessary. A single session cookie (qr_session) keeps you signed in. It is httpOnly, cannot be read by JavaScript, and expires after 30 days or when you sign out. A second small cookie records your consent choice so we do not ask on every visit. These cannot be switched off, because the site cannot function without them.
  • Advertising. Set by our advertising partner, and only after you consent. See the next section.
  • Analytics. We use Google Analytics to count visits and see which pages people find useful. It is loaded only after you consent, sets its own cookies, and is configured to anonymise IP addresses. It tells us how many people visited a page, roughly where in the world they were, and which link brought them — never who they are. Google’s handling of that data is covered by its own privacy policy.

You can change or withdraw your consent for advertising and analytics cookies at any time using the Cookie settings link in the site footer, or by clearing cookies in your browser. Declining leaves the generator, your account and every saved code working exactly as before.

5. Advertising

This site is supported by advertising. We work with Monetag as our advertising partner. When ads are enabled for your session, Monetag and its downstream demand partners may set or read cookies and similar identifiers in your browser to select ads, cap how often you see the same ad, measure performance, and detect ad fraud. This may involve processing your IP address, browser and device characteristics, and the pages you view on this site.

We do not share your account email, password, or saved QR code content with advertising partners.

If you are in the EEA, the UK, or Switzerland, we ask for your consent before any advertising cookie is set, and no advertising script is loaded until you give it. You can review Monetag’s own practices in their privacy policy. You can also opt out of interest-based advertising industry-wide at optout.aboutads.info and youronlinechoices.eu.

6. Legal bases for processing (EEA/UK)

  • Contract. Providing your account, saved QR codes, and analytics.
  • Legitimate interests. Keeping the service secure, preventing abuse, and understanding aggregate usage.
  • Consent. Advertising and analytics cookies, and any other non-essential tracking. You may withdraw consent at any time without affecting the lawfulness of prior processing.

7. Sharing your information

We share data only with:

  • Infrastructure providers that host the site and database on our behalf, under contract and only to run the service;
  • Our advertising partner, as described in section 5;
  • Analytics, as described in section 4;
  • Authorities, where we are legally required to do so, or where it is necessary to protect our rights or someone’s safety.
  • A buyer or successor, if this service is ever sold, merged, or transferred to another owner. Your account, saved QR codes and their scan statistics would move with it, because the service cannot be handed over without them. We would tell you before that happened and give you a reasonable chance to export or delete your data first, and the new owner would be bound by this policy until they give you notice of any change to it.

8. Retention

  • Account data is kept until you ask us to delete your account.
  • Sessions expire automatically after 30 days.
  • Saved QR codes and their scan records are kept while the code is active, so your analytics stay meaningful, and are deleted when the code is deleted.
  • Support emails are kept for up to 24 months.

9. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict processing, and to withdraw consent. To exercise any of these, email privacy@cloudqrgen.com from the address on your account and we will respond within 30 days. If you are in the EEA or UK, you also have the right to complain to your local data protection authority.

If you are a California resident: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and you will never be discriminated against for exercising your rights.

10. Security

Passwords are hashed with scrypt and a per-user salt. Session cookies are httpOnly and are sent over HTTPS only in production. Uploads are restricted to verified image formats. No system is perfectly secure, but we take reasonable technical measures to protect your data and will notify affected users of any breach that legally requires it.

11. Children

This service is not directed at children under 13 (or under 16 in the EEA), and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.

12. International transfers

Our providers may process data in countries other than yours, including the United States. Where required, such transfers rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

13. Changes to this policy

If we make a material change, we will update the date at the top of this page and, where appropriate, notify you on the site. Continuing to use CQRG after a change means you accept the updated policy.

14. Contact

Privacy questions: privacy@cloudqrgen.com
Everything else: our contact page