Legal
Last Updated: July 12, 2026 | Effective: July 12, 2026

Privacy Policy

Privacy Policy

1. Introduction

One More QR ("OMQR", "we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your information when you use our website, authentication pages, admin panel, QR-code guide pages, and related services (collectively, the "Service").

This policy applies to visitors of our public marketing website, registered account holders and authorized users of our admin panel, and anonymous end-users who scan a QR code created by one of our business customers and land on a guide page we host.

By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Service.

2. Scope of This Policy

One More QR operates several connected products, and this is the master privacy policy covering all of them:

• Marketing website (onemoreqr.com) — visited by prospective customers.

• Admin panel — used by our business customers ("tenants") to create and manage QR codes, guides, and brand settings.

• QR-code guide resolver ("guide product") — the page an end-user lands on after scanning a QR code created by a tenant. This may be served on onemoreqr.com or on a tenant’s own custom domain (e.g. a company like "Acme Furniture" pointing their own domain at our guide product).

Because the guide product has no separate privacy policy page of its own and links back to this page by default, this document is the privacy policy for that product too, regardless of which domain served it to you.

3. Information We Collect

We collect only the information needed to operate the Service, provide customer support, and improve our products.

2.1 Information You Provide

Account data: name, email address, organization name, and password when you register.

Profile data: optional details such as profile picture, phone number, or business information.

Payment data: billing is handled by our payment processor. We do not store full credit card numbers on our servers.

Communications: content of messages you send us through contact forms, email, or support channels.

2.2 Information Collected Automatically

Website usage data: on our public marketing website, limited analytics are collected only after you accept cookies in our banner. This may include pages viewed, time on page, browser type, and general location (city or country level) derived from IP address.

Cookies and local storage: essential cookies support site functionality and remember your cookie consent choice. Analytics cookies are set only through Google Tag Manager after you opt in.

Platform usage data: when you use the admin panel, we log product usage such as features accessed, QR codes created, and account actions to operate and improve the platform.

3.3 What We Do Not Collect on Our Marketing Website

This marketing website (onemoreqr.com landing pages) does not use advertising pixels, social media trackers, retargeting tools, or behavioral ad networks.

This marketing website does not use PostHog, Amplitude, Hotjar, Mixpanel, or similar third-party analytics platforms. Its only analytics technology is Google Tag Manager, described in Section 4 below.

This does not apply to our guide product (see Section 6, "QR Scan End-Users"), which does use PostHog and Amplitude to analyze scan activity on behalf of the tenant whose QR code was scanned.

We do not sell or rent website visitor data.

4. Website Analytics (Google Tag Manager)

Our public marketing website uses Google Tag Manager ("GTM") as its only analytics technology. Google Analytics 4 ("GA4") is configured inside GTM. We do not embed separate analytics scripts in our website code.

All website analytics data is used exclusively for internal purposes: understanding traffic, improving pages, and making product decisions. We do not use this data for advertising and we do not share it with third parties for their own marketing purposes.

4.1 What We Measure

Pages visited and navigation paths

Time spent on pages

Referring and exit pages

Device and browser type (aggregated)

General geographic region (country or city level)

4.2 Consent and How GTM Works

Google Tag Manager loads only after you click "Accept all" on our cookie banner.

Before you consent, Google Consent Mode keeps analytics storage denied. No analytics cookies are placed until you opt in.

If you click "Reject non-essential", GTM does not load and no analytics cookies are set.

We configure analytics without advertising or personalization signals. IP anonymization is enabled where supported.

4.3 Google as Our Analytics Processor

Google LLC processes website analytics data on our behalf when GTM and GA4 run after your consent.

Google acts as a service provider (data processor) under its terms and applicable data protection agreements.

Google may process data according to its own privacy policy: https://policies.google.com/privacy

4.4 Internal Use Only

Analytics reports are viewed only by authorized One More QR team members.

We do not sell, rent, or trade website analytics data.

We do not provide website analytics data to advertisers, data brokers, or other third parties for their independent commercial use.

4.5 Your Choices

Reject non-essential cookies in our banner to prevent GTM from loading.

Change your choice anytime by clearing site data for onemoreqr.com and revisiting the site.

Use the Google Analytics Opt-out Browser Add-on: https://tools.google.com/dlpage/gaoptout

See our Cookie Policy at /cookie-policy for more detail.

5. Admin Panel Data

The admin panel is our authenticated platform for business customers ("tenants"). Data collected here is used to deliver the Service and improve product quality.

5.1 What We Collect in the Admin Panel

Account and workspace activity: logins, feature usage, QR code management actions, and team administration events.

QR scan analytics: scan counts, general location, and device type for QR codes you create, as configured in your account.

Content metadata: information about guides, files, brands, and QR codes you manage through the platform.

5.2 How We Use Admin Panel Data

To provide, secure, and maintain the Service.

To generate analytics and reports for your organization.

To diagnose errors, prevent abuse, and improve performance.

To develop new features based on aggregated usage patterns.

5.3 Admin Panel Analytics

The admin panel does not use Google Tag Manager or marketing analytics scripts.

Admin authentication uses strictly necessary session cookies required to keep you logged in.

We do not sell admin panel usage data or share it with third parties for marketing purposes.

5.4 Exporting or Deleting Your Account Data

Logged-in admin panel users can export a copy of their own account data (profile, workspace memberships, invitations) or request deletion of their account directly from their profile settings.

Account deletion is a soft delete: your account is deactivated immediately and permanently and irreversibly erased after a 30-day grace period, unless you are the sole administrator of a workspace with other members, in which case you must promote another administrator first.

See Section 8 ("Your Privacy Rights") for details on rights that go beyond self-service account deletion.

6. QR Scan End-Users (Guide Product)

This section applies to you if you scanned a QR code created by one of our business customers and were taken to a product guide, digital passport, contact card, WiFi, or link page we host — whether at a onemoreqr.com address or at a custom domain owned by that business.

One More QR (the "platform") builds and operates the technology behind these guide pages. The business that created the QR code (the "brand" or "tenant" — for example, a furniture retailer publishing a product guide) decides what content the guide shows and is the data controller for the personal data collected when their customers scan their QR codes. One More QR acts as the data processor: we run the tracking and analytics infrastructure on the brand’s behalf, under their instructions, and do not use the data collected through their QR codes for our own independent purposes.

6.1 What Is Collected When You Scan a QR Code

Redirect and routing data (always collected, necessary to serve the guide): the QR code identifier, general location (country, region, city, timezone — derived from network-level headers, not GPS), device type, operating system, and browser, used to route you to the correct content and to enforce the brand’s scan quota.

Analytics data (collected only if you accept "measurement" cookies): the same location and device signals, plus a persistent identifier, sent to Amplitude and/or PostHog to help the brand understand how their guide pages are used.

We do not require you to create an account or provide your name, email, or any directly identifying information to scan a QR code or view a guide page.

6.2 Consent Is Opt-In

A cookie consent banner (built on the c15t consent platform) appears the first time you visit a guide page. Non-essential tracking — Amplitude, PostHog, Google Tag Manager/GA4, Meta Pixel, or any custom analytics script a brand has configured — does not run until you click "Accept."

If you decline or take no action, only the routing data described in Section 6.1 is collected, since it is necessary to serve you the correct guide content and cannot be made opt-in without breaking the redirect.

6.3 The Brand’s Own Privacy and Cookie Policies

A brand may configure and display its own Privacy Policy, Cookie Policy, and Terms of Service links on their guide pages, since they are the data controller for their end-customers. Where a brand has not configured its own links, this One More QR master policy applies by default.

6.4 Retention

Scan and analytics events are currently retained for approximately one year and deleted through a manual, periodic process. We do not yet have automated time-based deletion for this data; we disclose this so you understand our current practice.

7. How We Share Information

We do not currently sell your personal information, and we do not share your data with third parties for their own independent marketing or advertising purposes.

We may begin selling or sharing categories of personal information in the future. If that happens, we will update this policy, provide notice as required by applicable law (including a "Do Not Sell or Share My Personal Information" mechanism for California residents under the CCPA), and the change will only take effect going forward, not retroactively.

7.1 Service Providers and Sub-processors

We use the following categories of infrastructure and service providers to run the Service. Each processes data only under our instructions and contractual data protection terms:

• Cloud infrastructure and storage: Amazon Web Services (S3, DynamoDB), MongoDB Atlas, Aiven (managed PostgreSQL), Redis.

• Analytics (guide product, consent-gated): Amplitude, PostHog.

• Analytics (marketing website, consent-gated): Google Tag Manager / Google Analytics 4.

• Payments: Stripe.

• Transactional email: Brevo.

• Error monitoring: Honeybadger.

• Hosting and domain/SSL management: Vercel.

This list reflects our current production sub-processors and may change as our infrastructure evolves; material changes will be reflected in an updated version of this policy.

7.2 Legal and Safety Disclosures

We may disclose information if required by law, court order, or governmental request.

We may disclose information to protect the rights, safety, and security of One More QR, our users, or the public.

7.3 Business Transfers

If One More QR is involved in a merger, acquisition, or asset sale, user information may transfer as part of that transaction. We will notify affected users where required by law.

8. Data Security

We implement technical and organizational safeguards designed to protect personal information against unauthorized access, loss, or misuse.

8.1 Security Measures

TLS encryption for data in transit between your browser and our servers.

Access controls limiting personal data to authorized personnel.

Tenant isolation for customer data in our multi-tenant platform.

Regular review of security practices and infrastructure configuration.

8.2 Your Responsibilities

Keep your account credentials confidential.

Use a strong, unique password.

Notify us promptly at [email protected] if you suspect unauthorized access to your account.

9. Your Privacy Rights

Depending on your location and which part of the Service you use, you may have rights regarding your personal information, including the rights described below. Admin panel users can exercise the access, export, and deletion rights directly from their account (Section 5.4); everyone else can reach us at [email protected].

9.1 Access, Correction, and Deletion

Request access to the personal data we hold about you.

Request correction of inaccurate information.

Request deletion of your data, subject to legal or contractual retention requirements.

9.2 Data Portability

Request a copy of your data in a structured, commonly used, machine-readable format where applicable. Admin panel users can self-serve this via account export (Section 5.4).

9.3 Cookie and Analytics Choices

Reject non-essential cookies to prevent Google Tag Manager from loading on our marketing website, or to prevent Amplitude/PostHog/GTM from loading on a guide page (Section 6.2).

Withdraw consent at any time by reopening the cookie banner or clearing site data and revisiting the site.

Opt out of marketing emails using the unsubscribe link in any promotional message.

9.4 India DPDP Act

One More QR is incorporated in India. Under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), we act as a "Data Fiduciary" for personal data we collect directly (e.g. admin panel accounts) and, where applicable, help brands who use our guide product meet their own obligations as Data Fiduciaries for their end-customers' scan data.

You may exercise rights of access, correction, erasure, and grievance redress available under the DPDP Act by contacting [email protected].

9.5 GDPR (EEA / UK Visitors)

If you are located in the European Economic Area or United Kingdom, you have rights under the GDPR / UK GDPR, including the right to access, rectify, erase, or port your personal data; the right to restrict or object to processing; and the right to withdraw consent at any time without affecting the lawfulness of prior processing.

You also have the right to lodge a complaint with your local data protection supervisory authority.

Contact [email protected] to exercise these rights.

9.6 CCPA/CPRA (California Visitors)

If you are a California resident, you have the right to know what personal information we collect, use, and disclose; the right to request deletion; the right to correct inaccurate personal information; the right to opt out of the sale or sharing of personal information (we do not currently sell or share personal information, see Section 7); and the right to non-discrimination for exercising these rights.

Contact [email protected] to submit a request.

9.7 How to Exercise Your Rights

Contact us at [email protected] with your request. We will respond within a reasonable timeframe as required by applicable law.

10. Data Retention

We retain personal data only as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements.

When data is no longer needed, we delete or anonymize it in accordance with our retention practices.

QR scan and guide-analytics data (Section 6.4) is currently retained for approximately one year and deleted manually; we do not yet have automated time-based deletion for that data.

Website analytics data retained by Google is subject to our GA4 and GTM configuration and Google's retention settings.

11. International Data Transfers

One More QR is incorporated in India. Our infrastructure — including AWS, MongoDB Atlas, and Aiven-managed PostgreSQL — is currently hosted in the United States. This means personal data we collect, regardless of where you are located, is generally transferred to and processed in the United States.

Where required, we use appropriate safeguards for these international data transfers, consistent with the DPDP Act, GDPR, and other applicable data protection laws.

If you are located in the European Economic Area or United Kingdom, you may have additional rights under GDPR or UK GDPR regarding these transfers. Contact [email protected] to exercise those rights.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated "Last Updated" date.

Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

13. Contact Us

For privacy questions, requests, or complaints, contact:

Email: [email protected]

Website: https://onemoreqr.com/contact