Skip to content

Privacy

What we collect, why we have it, and how long it stays. We do not sell data, and raw scanner IP addresses are not stored in our scan database.

Last updated 12 September 2026. NUVIX STUDIO LIMITED is the data controller for everything described here. Write to hello@qrthatlasts.com about any of it.

If you only read one part

When somebody scans one of your codes, we need to know it happened so we can show you a count. We do not need to know who they are, and we have built it so we cannot. Their IP address is salted, hashed and truncated before it reaches storage, and the salt changes daily. No column holds the original, so there is nothing to hand over, leak or sell.

Visiting this website

Google Analytics counts visits and actions on this site after you accept measurement in the banner. That choice also allows us to share measurement data with our linked Google Ads account and Meta to see which adverts lead to signups or paid plans. We do not use this choice to personalise Google ads. Refuse, or ignore the banner, and the measurement tags stay off. The cookie notice explains which services this involves and how to change your choice, including the “Change your cookie choice” button that withdraws your consent and asks again. A cookie a provider already set before you changed your mind can still be on your device; clear it yourself in your browser if you want it gone straight away.

The app has its own privacy notice at app.qrthatlasts.com/privacy, including how it measures account creation and payments when you agree to measurement there.

Our host keeps ordinary web server logs, the sort every web server keeps, containing IP addresses and requested pages. They are used to keep the site up and to investigate abuse, and they age out on the host’s schedule.

Having an account

We hold what you give us and what the service needs to work:

  • Your name and email address.
  • A hash of your password. We cannot read your password and nobody here can recover it.
  • If you turn on two-factor authentication, the secret needed to check your codes and your backup codes, both stored encrypted.
  • Your codes: what each one is called, what it points at, and every address it has pointed at before.
  • Which plan you are on and when it renews.

The lawful basis is performance of a contract. You cannot have an account without an account.

Scans

When one of your codes is scanned we record:

  • Which code, and when.
  • The country and city, worked out from the request. Nothing finer.
  • Whether it was a phone, tablet or desktop, and which operating system family it runs, worked out from the browser’s user agent.
  • A daily-salted, hashed and truncated form of the IP address, used only to tell one scan apart from a hundred by the same person in a minute.

Individual scan records are removed in monthly partitions once the whole partition is older than 90 days, so a record can remain for up to about 122 days. What is kept after that is a daily total per code: how many scans, from which country, on what kind of device. A chart of last year is the reason people ask for the feature.

The lawful basis is legitimate interests: you need to know whether the thing you printed works. We have kept the data to the minimum that answers that, which is how we reached an IP address nobody can reverse.

Paying

Paddle takes payments as merchant of record. They hold your card details and your billing address; we never see them. We keep the identifiers Paddle gives us for your customer and subscription, and what plan they correspond to. Paddle’s own notice covers what they do with the rest.

Reporting a code

Anyone can report a code without an account. We keep the report: the code named, the reason, anything written in the details box, an email address if one is volunteered, and the same hashed form of the reporter’s IP address used for scans. Reports are part of the safety record and are kept. The lawful basis is legitimate interests: acting on abuse of printed codes is the reason the form exists.

Who else touches it

  • Neon hosts the database. It is in London.
  • Netlify hosts the site and the application.
  • Brevo sends transactional email: confirmations, invitations, password resets. No marketing email is sent to customers.
  • Paddle takes payments.
  • Google provides analytics on this marketing site and shares consented measurement with our linked Google Ads account. The account signup page asks separately. Google Web Risk also receives destination URLs for safety checks, separately from marketing analytics.
  • Meta receives advertising measurement events, such as that somebody used the demo or created an account, only after consent, on this marketing site and, under a separate consent decision, on the account signup page.

Nobody buys data from us. Google and Meta process measurement data under their own privacy notices. Where a supplier processes data outside the UK, it is covered by the transfer terms in their contract with us.

What survives retiring a code

Retiring a code removes it from use and stops it resolving. The record of what that code pointed at, and when, is kept. That record is what answers a complaint months later about where a printed code sent somebody. A destination URL may contain personal information even after account details are erased.

Your rights

You can ask for a copy of everything we hold about you, ask us to correct it, or ask us to delete it. You can erase your account yourself from the account page, or write to hello@qrthatlasts.com and we will do it rather than send you a form.

Erasure removes account names, email addresses, passwords and sessions from the live application database. Two things to know before you ask for it. Every code on the account stops resolving, permanently, because we will not keep redirecting printed material for somebody who has told us to stop acting for them. And the record of where each code pointed is kept, as above. Retained URLs may contain personal information; account erasure does not make those URLs anonymous.

You can also object to processing, ask us to restrict it, and ask for your data in a portable format. If you think we have got something wrong, tell us first, and if that goes nowhere you can complain to the Information Commissioner’s Office at ico.org.uk.

How long we keep things

  • Account details: until you close the account.
  • Individual scan records: up to about 122 days, due to monthly partition removal.
  • Daily scan totals: kept, because the point is the history.
  • Destination history: kept, as above.
  • Records of failed sign-ins: about a day, or until a temporary lock has expired. Counters used to rate-limit signups and reports: two days.
  • Abuse reports: kept, as part of the safety record.

Changes

If we change this in a way that affects you we will email the address on your account. The date at the top always says when it last changed.

Who you are dealing with

Company
NUVIX STUDIO LIMITED
Registered in England and Wales, number
16287603
Registered office
82a James Carter Road, Mildenhall, United Kingdom, IP28 7DE

Payments are taken by Paddle, who act as the merchant of record and appear as the seller on your receipt. The service itself is provided by NUVIX STUDIO LIMITED.