Privacy policy
This page explains what personal data we process, what for and for how long. It is written in plain English and without cross-references: if a question is left over after reading it, the address below is the right place to ask it.
Data controller
- Controller
- Federico Vitali
- Registered address
- Viale Roma 158, Forlì (FC)
- VAT number
- IT04435880408
- contact@liveqr.app
1. Who this policy is for
It concerns two different groups of people, and it concerns them in different ways.
If you have a liveQR account, we process the data you gave us when you signed up and the data the service produces as you use it. If instead you simply scanned a QR code created by someone else, you have no relationship with us: we still record some technical data about that scan, and section 3 explains what and why.
We do not knowingly process data belonging to children under sixteen, and the service is not aimed at them.
2. Your account data
To create an account we collect your email address, a password, the name you want to display and the kind of work you do. We do not keep the password itself: we store a cryptographic derivation of it (scrypt) that cannot be reversed, not even by us.
If you choose to sign in with Google, we receive your email address and profile name from Google. We do not receive your password and we have no access to the rest of your Google account.
The «send me updates» box is off by default and stays your choice: if you leave it unticked we never write to you for commercial reasons, while service emails — address confirmation, password recovery, receipts — arrive anyway, because without them the service does not work.
The legal basis is the performance of the contract between us once you open an account (art. 6.1.b GDPR); for commercial updates it is your consent (art. 6.1.a), which you can withdraw at any time from your profile or from the link at the bottom of every email.
3. QR code scans
A dynamic QR code does not contain the final destination: it contains a short link of ours, which at scan time forwards to wherever the owner of the code has decided. That step is what makes the code editable without reprinting it, and it is also the moment when we record something.
For each scan we keep: the date and time, the device type and operating system derived from the user agent, the country and city, the referring site if any, and our server’s response time. The user agent and the referrer are truncated at 500 characters.
The IP address is never stored in the clear. We only keep an HMAC-SHA256 of it, computed with a secret key: it lets us estimate how many different people scanned a code and recognise bots, it cannot be reversed and it does not allow anyone to be identified.
Geolocation stops at country and city, never coordinates. Where the lookup happens on our internal microservice, the IP address never leaves our infrastructure: we query a database we have already downloaded, not a third-party service.
The redirect sends the «Referrer-Policy: no-referrer» header: the destination site does not get to learn which QR code its visitors came from.
The legal basis is our legitimate interest, and that of the code’s owner, in knowing whether the printed material works (art. 6.1.f GDPR). We balanced it by keeping the data to a minimum: no IP in the clear, no coordinates, and nothing that would allow the same person to be followed from one scan to the next.
4. How the site is used
We record how the site is used — which pages are opened, which QR type is chosen, when a code is downloaded — to understand what works and what does not. This is a different matter from the scans in section 3, and the two are never cross-referenced.
On this analytics we made a deliberate choice: we write no identifier at all onto your device. No analytics cookies, no localStorage, nothing. Who the visitor is, our server decides by computing an HMAC of the IP address, the user agent and the current day — recalculated on every request and never stored in the clear. The intended consequence is that we can tell two visitors apart within the same day, but cannot recognise the same person the day after.
This is also why we do not ask you to accept cookies before coming in: there is nothing to accept, because we store nothing on your device and the data is anonymous from the outset.
What does not go into that table: the full page path, the complete referring address (we keep only the site name) and the city. Requests we recognise as bots are discarded.
If your browser sends the «Do Not Track» or «Global Privacy Control» signal, we record nothing. It is not required for cookieless analytics, but an explicit objection strikes us as something to respect anyway.
If you have a session open at the time, the event carries your user identifier: that is personal data in the full sense, which is why it is declared here. Anonymous events stay anonymous forever, and there is no step that ties them back to an account opened later.
5. Files you upload
If your plan allows it, you can upload images, PDFs and videos to attach to a QR code. Those files are kept on storage operated by Cloudflare and remain reachable through an address on our domain.
We do not open them and we do not analyse them for purposes of our own. We do check the file type by reading its first bytes, to stop one format from hiding inside another.
Bear in mind that a file attached to a QR code is public by construction: anyone who scans that code can open it. Do not upload documents you would not want a stranger to see.
6. Payments
Subscriptions are handled by Stripe. Card details are collected and stored by Stripe: they never pass through our servers and we never see them.
What comes back to us is your Stripe customer identifier, the subscription identifier, the plan purchased, the billing period and the renewal date. We need them to show you the state of your subscription and to apply your plan’s limits.
The legal basis is the performance of the contract, and for accounting records a legal obligation (art. 6.1.b and 6.1.c GDPR).
7. The emails we send
Transactional emails — address confirmation, password recovery, subscription notices — are sent through Resend, which processes your address on our behalf and on our instructions.
Every non-transactional email carries an unsubscribe link that works without having to sign in.
8. Cookies
We use two cookies, and both exist to keep you signed in: one for the current session and one to renew it without asking for your password again. They are strictly necessary cookies, marked «httpOnly» — no script on the page can read them — and scoped to our site.
We use no profiling cookies, no third-party cookies, and we sell data to nobody. That is why you will not find a consent banner: there would be nothing to consent to.
You can delete them from your browser settings whenever you like. The effect is that you will have to sign in again.
9. How long we keep the data
Your account data stays for as long as the account exists.
Scan events belong to the QR code that produced them and live as long as it does: while that code exists in your account, so does its history. This is deliberate, because a QR code printed on a flyer can be in circulation for years, and its history is the reason you made it dynamic.
Data on how the site is used (section 4) is deleted automatically after 180 days.
If you ask us to close your account, we delete your data and your codes within thirty days of the request, save for records the law requires us to keep — invoices, for ten years.
10. Who we share data with
We do not sell personal data and we do not hand it to anyone for purposes of their own. It is processed on our behalf, as processors and under a contract, only by the suppliers we need in order to run the service:
- Stripe — payments and subscriptions
- Resend — sending emails
- Cloudflare — storage for uploaded files
- Google — only if you choose to sign in with your Google account
- the supplier hosting our servers and database
11. Transfers outside the European Union
Some of the suppliers listed above are based in the United States or may process data outside the European Union.
In those cases the transfer relies on the standard contractual clauses approved by the European Commission, or on the supplier’s certification under the EU–US Data Privacy Framework.
12. Your rights
Over your personal data you may exercise the rights set out in articles 15 to 22 GDPR:
- find out what data we process and obtain a copy of it
- have it corrected if it is wrong or incomplete
- ask for it to be erased
- ask for the processing to be restricted
- receive it in a machine-readable format, or have it transferred to another provider
- object to processing that rests on our legitimate interest
- withdraw a consent you gave at any time, without affecting what was done before
13. How to exercise them, and who else to turn to
Write to the email address shown at the top of this page. We answer within thirty days; if the request is complex we may take a further two months, but we will tell you so within the first.
If you believe the processing of your data breaches the GDPR, you may lodge a complaint with the Italian supervisory authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it) or with the supervisory authority of the country where you live.
14. How we protect the data
Traffic is always encrypted. Passwords are kept only in derived form, IP addresses only in irreversible form, and session tokens live in cookies no script can read.
No measure is perfect. Should a breach occur that poses a high risk to your rights, we will tell you without undue delay, as art. 34 GDPR requires.
15. Changes to this policy
If we change something, we update the date at the top of the page. When the change concerns a new purpose or a new supplier, we also tell account holders by email before it takes effect.