Privacy Policy
Your privacy is our priority. Learn how we protect your data and ensure GDPR compliance.
Last updated: Sat Apr 11 2026 00:00:00 GMT+0000 (Coordinated Universal Time)
GDPR Compliant
Full compliance with EU data protection regulations
EU Data Residency
All data stored and processed within European Union
Your Rights
Control your data with easy access and deletion
1. Introduction
QR2GO ("we," "our," or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, and protect your information when you use our QR code generation and analytics services in full compliance with the EU General Data Protection Regulation (GDPR).
2. Data Controller Information
Data Controller Details
Company: QR2GO
Responsible Person (§5 DDG): Ivan Adamov
Address: Silberbergerstraße 33, 49076 Osnabrück, Germany
Phone: +49 541 18584800
Email: privacy@qr2go.eu
Legal Status: Sole Proprietorship (Einzelunternehmen), Owner: Ivan Adamov
Note: QR2GO is operated by Ivan Adamov as a sole proprietorship (Einzelunternehmen) based in Osnabrueck, Germany. Payments are processed securely via Stripe.
Data Protection Officer
Email: dpo@qr2go.eu
Contact our Data Protection Officer for all privacy-related inquiries.
3. Data We Collect
Account Information
- Email address (required for account creation)
- Name (optional, for personalization)
- Profile picture (optional, via OAuth providers)
- Authentication provider information (Google, GitHub)
QR Code Data
- QR code content (URLs, text, etc.)
- QR code customization settings
- Creation and modification timestamps
- QR code usage statistics
Analytics Data (Matomo)
- QR code scan events and timestamps
- Aggregated geographic location (country/city level)
- Device type and browser information
- Referrer information (anonymized)
4. Legal Basis for Processing
Contract Performance
Processing necessary to provide our QR code generation and analytics services.
Legitimate Interest
Improving our services, security, and customer support.
Your Right to Object
When we process your data based on legitimate interests, you have the right to object to this processing. You can exercise this right by contacting us at privacy@qr2go.eu or by disabling analytics tracking in your cookie settings. For analytics specifically, you can opt out via the cookie banner or cookie settings page, which will disable Matomo tracking.
5. How We Use Your Data
- Provide QR code generation and management services
- Deliver privacy-first analytics through Matomo
- Manage your account and subscription
- Provide customer support
- Send important service updates and security notifications
- Improve our services and user experience
6. Data Sharing and Third Parties
We Do NOT Share Your Data With:
- Third-party analytics providers (we use self-hosted Matomo)
- Data brokers or marketing companies
- Any entities beyond the sub-processors listed below
EU Service Providers We Use:
- Matomo: Privacy-first analytics (EU-hosted)
- Payment Processing: Stripe (GDPR compliant)
- Email Service: Resend (EU processing)
- Database Hosting: Neon (EU regions)
Sub-Processors (Art. 28 GDPR)
We use the following sub-processors to provide our services. All transfers to third countries are safeguarded by the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCC).
Stripe, Inc.
- Location:
- USA (EU subsidiary: Stripe Payments Europe, Ltd., Dublin, Ireland)
- Purpose:
- Payment processing, subscription management, invoice generation
- Legal basis:
- Art. 6(1)(b) GDPR — contractual necessity
- Transfer mechanism:
- EU-US Data Privacy Framework + Standard Contractual Clauses (SCC)
- Data Processing Agreement:
- https://stripe.com/legal/dpa
Neon, Inc.
- Location:
- USA (data stored in EU region: aws-eu-central-1, Frankfurt)
- Purpose:
- Database hosting and management
- Legal basis:
- Art. 6(1)(b) GDPR — contractual necessity
- Transfer mechanism:
- EU-US Data Privacy Framework + Standard Contractual Clauses (SCC)
- Data Processing Agreement:
- https://neon.tech/dpa
Vercel, Inc.
- Location:
- USA (edge network with EU nodes: fra1, Frankfurt)
- Purpose:
- Application hosting and content delivery
- Legal basis:
- Art. 6(1)(f) GDPR — legitimate interest (reliable service delivery)
- Transfer mechanism:
- EU-US Data Privacy Framework + Standard Contractual Clauses (SCC)
- Data Processing Agreement:
- https://vercel.com/legal/dpa
Cloudflare, Inc.
- Location:
- USA (global edge network including EU nodes)
- Purpose:
- CDN, DNS resolution, DDoS protection, Turnstile CAPTCHA
- Legal basis:
- Art. 6(1)(f) GDPR — legitimate interest (security and availability)
- Transfer mechanism:
- EU-US Data Privacy Framework + Standard Contractual Clauses (SCC)
- Data Processing Agreement:
- https://www.cloudflare.com/cloudflare-customer-dpa/
DigitalOcean, LLC
- Location:
- Germany (Frankfurt / fra1 data centre)
- Purpose:
- Matomo analytics hosting (self-hosted Matomo origin server)
- Legal basis:
- Art. 6(1)(f) GDPR — legitimate interest (privacy-first analytics)
- Transfer mechanism:
- EU-US Data Privacy Framework + Standard Contractual Clauses (SCC)
- Data Processing Agreement:
- https://www.digitalocean.com/legal/data-processing-agreement
7. Your GDPR Rights
Access & Portability
- Request a copy of your data
- Export data in standard formats
- View all data processing activities
Control & Deletion
- Correct or update your information
- Delete your account and all data
- Opt-out of analytics tracking
Exercise Your Rights
Contact us at privacy@qr2go.eu to exercise any of your GDPR rights. We will respond within 30 days. In exceptional cases (complex requests), this period may be extended by up to 60 additional days, and we will inform you if an extension is needed.
Supervisory Authority:
You have the right to file a complaint with your local data protection authority. For Germany: Berliner Beauftragte für Datenschutz und Informationsfreiheit, Friedrichstr. 219, 10969 Berlin. For other EU countries, see: EU Data Protection Authorities
8. Data Retention
- Account Data: Retained until account deletion
- QR Code Data: Retained until manual deletion or account closure
- Scan Analytics: Subject to a 365-day retention cutoff; data past the cutoff is removed during the scheduled monthly cleanup cycle
- Product Analytics (Matomo): Raw visit data automatically deleted after 13 months; only aggregate statistics are retained
- Backup Data: Automatically deleted after 90 days
9. Data Security
We implement appropriate technical and organizational measures to protect your data:
- End-to-end encryption for data in transit (TLS 1.3)
- Encryption at rest for all stored data
- Regular security audits and vulnerability assessments
- Access controls and employee data protection training
- EU-only data processing and storage
10. Cookies and Tracking
Minimal Cookie Usage
We use only essential cookies for authentication and session management.
Matomo analytics respects Do Not Track headers and provides opt-out options.
QR2GO Analytics is a custom analytics environment based on the open-source Matomo platform. Matomo is an independent open-source project and is not owned by QR2GO or BitBau. Integration, configuration, branding and privacy setup: SaaS development and technical implementation by BitBau.
11. Children's Privacy
Our services are not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you become aware that a child has provided us with personal information, please contact us immediately.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and sending an email notification for significant changes. You are advised to review this Privacy Policy periodically.