MisterQR
FeaturesQR typesCompareFAQ
Log in

Privacy Policy

Last updated: 29 September 2026

MisterQR is a QR code service operated by Rexonn (“we”, “us”). This policy explains what we collect, why, and the choices you have.

1. What we collect

Your account

  • Your email address and a securely hashed password (we never see or store the password itself).
  • Whether your email is confirmed, and when you created your account.

What you put in your QR codes

  • Everything you enter when creating a code: links, names, categories, contact details, messages, locations, Wi-Fi details, uploaded images and folder names.
  • Contact-card, text, call, SMS and email codes are shown publicly to anyone who scans them. Don’t put anything in a code you don’t want scanners to see.

When someone scans a code

  • The time of the scan, the device type, operating system and browser (from the browser’s user agent).
  • An approximate location — country, region and city — provided by our hosting provider from the IP address. We do not store IP addresses.
  • A one-way “visitor” hash made from the day, IP address and browser, used only to count unique visitors per day. It changes every day and can’t be turned back into an IP address.
  • This scan data is shown only to the code’s owner (and to our administrators for security and abuse checks).

Our website

  • If you accept analytics cookies, Google Analytics measures which pages are visited. It runs in a mode that stores nothing until you accept, never runs on scan pages or on password-reset/confirmation links, and we strip QR codes’ identifiers from the page addresses it sees.

2. Cookies and local storage

  • Session cookie — keeps you signed in (essential).
  • Unlock cookie — remembers for 12 hours that you entered the password of a protected QR code (essential for that feature).
  • Your analytics choice — stored in your browser so we don’t ask again.
  • Google Analytics cookies — only if you click “Accept”. You can change your mind by clearing this site’s data in your browser.

3. How we use your data

  • To run the service: create your codes, redirect scans, show your analytics, and let you sign in.
  • To send essential emails: confirming your address, password resets and security notices. We don’t send marketing email.
  • To keep the service safe: rate limits, abuse reports and disabling codes that break our Terms. We don’t allow phishing, scam or malware codes (Terms, section 4).
  • To find and fix errors: when something breaks, an error report is sent to Sentry.
  • To understand and improve the website (only with your analytics consent).

We process your data to provide the service you asked for (performance of a contract), for our legitimate interests in keeping it secure and working, and — for analytics cookies — with your consent. Under India’s Digital Personal Data Protection Act, 2023, we process your data for the purposes above, which you consent to by using the service; you can withdraw consent at any time as described below.

4. Who we share it with

We don’t sell your data. We use a few providers to run the service, who process data on our behalf:

  • Supabase — database and file storage (servers in South Korea).
  • Vercel — website hosting and approximate scan location.
  • Resend — sending account emails.
  • Google — website analytics, only with your consent.
  • Sentry — error reports: what went wrong, the page address (with one-time links removed) and browser and device type. No passwords, cookies, form contents or IP addresses.

We may disclose data if the law requires it, or to protect people from fraud or harm. If a code is used for phishing, a scam or malware, we may share the details we hold about that code and the account behind it with CERT-In, the police, the National Cyber Crime Reporting Portal, Google Safe Browsing or the brand being impersonated.

5. How long we keep it

  • Your account and codes: until you delete them.
  • Scan data: until you delete the code or your account.
  • Codes we switch off for phishing, scams or other abuse: a record of the code, its link and content, the account’s email address and the reason is kept for up to 180 days, even if the account is deleted, so it can be given to the authorities.
  • Deleting your account (Settings → Delete account) immediately deletes your account, all your QR codes, their scan data, folders and uploaded images. Copies may remain in our providers’ backups for a limited time before being overwritten.

6. Your rights

You can see and correct your data in your dashboard and settings, and delete everything at any time. You can also ask us for a copy of your data, to correct or erase it, or to withdraw consent, by emailing hello@rexonn.com. If you are in the EU/UK you also have the right to object, restrict processing and complain to your data protection authority.

Grievances: for any concern about how we handle your personal data (including under the DPDP Act), contact our grievance contact at hello@rexonn.com. We aim to respond within 7 days.

7. Security

Passwords and QR passwords are hashed with scrypt, connections are encrypted (HTTPS), sessions are signed, only our servers can access the database, and access is limited to what each feature needs. No system is perfectly secure, but we work to protect your data and will notify you as required by law if a breach affects you.

8. Children

MisterQR is not intended for anyone under 18. Don’t create an account if you’re under 18.

9. Changes

We’ll update this page when our practices change and change the “Last updated” date. For significant changes we’ll notify account holders.

10. Contact

Rexonn · hello@rexonn.com · Contact page

MisterQR

Free dynamic QR code generator. Print once, change the link any time.

ProductFeaturesQR typesFAQ
CompareMisterQR vs QRfyMisterQR vs QR Forever
CompanyContactReport a QR codePrivacy PolicyTerms of Service
AccountCreate free accountLog in
© 2026 MisterQR · operated by RexonnPowered byRexonn