Privacy Policy
Effective date: August 17, 2026
1. Introduction
UnifiedQR ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website (qr.nxtgensec.org) and use our QR code generation and management services (the "Service").
By accessing or using our Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of the Service.
2. Information We Collect
2.1 Account Information
When you sign in via Google OAuth, we collect your email address, display name and profile picture. We do not store your Google password.
2.2 QR Code Data
We store the QR codes you create, including the encoded content (URLs, text, vCard data, etc.), customization settings and any associated short links.
2.3 Analytics Data
When a dynamic QR code is scanned, we record the scan timestamp, device type, referrer and IP-derived geolocation. This data is used to provide you with scan analytics.
2.4 Usage Data
We collect anonymised usage data including page views, feature interactions, browser type and operating system. This data is not linked to your personal identity.
2.5 Payment Information
Payment processing is handled by Cashfree Payments. We do not store your credit card number, CVV or bank details. We only retain a reference to your transaction for billing records.
3. How We Use Your Information
- To provide, maintain and improve the Service
- To process payments and manage your subscription plan
- To send you transactional emails (account verification, plan changes)
- To display scan analytics and QR code management tools
- To detect and prevent fraud, abuse and security incidents
- To comply with legal obligations
4. Data Sharing
We do not sell your personal information. We may share data with:
- Service providers: Supabase (database, auth), Cashfree (payments), Cloudflare (hosting) — strictly for operating the Service.
- Legal compliance: If required by law, court order or government request.
- Business transfers: In connection with a merger, acquisition or sale of assets, with appropriate notice.
5. Data Retention
We retain your account information for as long as your account is active. QR code data and analytics are retained until you delete them. After account deletion, we remove your personal data within 30 days, except where required by law.
6. Data Security
We implement industry-standard security measures including TLS encryption in transit, encrypted database storage and access controls. However, no method of transmission over the Internet is 100% secure.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Object to or restrict processing of your data
- Data portability — receive your data in a machine-readable format
To exercise these rights, contact us at unifiedqr@nxtgensec.org.
8. Cookies
We use minimal cookies for authentication sessions and user preferences. We do not use advertising or third-party tracking cookies. See our Cookie Policy for details.
9. Children's Privacy
The Service is not intended for users under the age of 16. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email or a notice on the Service. Continued use after changes constitutes acceptance.
11. Contact Us
If you have questions about this Privacy Policy, contact us at:
Email: unifiedqr@nxtgensec.org
Website: qr.nxtgensec.org/contact
