Privacy Policy
Last updated: July 21, 2026
QR Maker ("we", "us") takes your privacy seriously. This policy explains what data we collect, why, and your rights over it. It applies to all users globally and is designed to comply with the GDPR (EU), CCPA (California), and other applicable privacy laws.
Data controller: XANTICO CONSULTING SL (operating as QR Maker)
CIF: B26564195 · C/ Hermosilla 48, 1º Dcha., 28001 Madrid, Spain
1. What We Collect
Account data
Email address, name, and password (hashed) when you create an account. Collected to provide the Service and communicate with you.
Billing data
Payment is handled by Stripe. We store only your subscription status and plan tier — never your card number or banking details.
QR scan analytics
When someone scans your QR code we record: timestamp, approximate country (from IP, not stored), device type, and browser. We do not store the IP address of the scanner. This data is attributed to your account, not to the scanner.
Photo galleries (event hosts + guests)
When you create a photo gallery for a wedding or event, we store: gallery configuration, photos and short video clips uploaded by you or your guests, guest-uploaded email addresses if voluntarily provided, and shipping address if you purchase a printed Wedding Album. Photos and video files are stored on Supabase Storage in the EU region.
AI-derived features from photos
For the AI Curated Wedding Album product, we compute per-photo technical features to select the 30 best shots: a perceptual hash for near-duplicate detection, a CLIP embedding vector for similarity clustering, and — via OpenAI Vision — face count, an overall face-quality score (blur / eyes-open / expression), sharpness, and a wedding-scene label (ceremony / party / etc.). See Section 4b below for what is sent to which third party and why this is not biometric identification.
Usage & logs
API requests, feature usage, and error logs for operating and improving the Service. Server logs are retained for 30 days.
Cookies & local storage
Essential cookies for authentication and session management. Analytics cookies only with your consent. See our Cookie Policy.
2. Legal Bases (GDPR)
- Contract: Account data and billing, to fulfil our subscription agreement.
- Legitimate interests: Usage logs, security, fraud prevention, and product improvement.
- Consent: Analytics cookies and marketing emails (opt-in only).
3. How We Use Your Data
- To provide and maintain the Service
- To process payments and manage your subscription
- To show you scan analytics dashboards
- To send transactional emails (password reset, invoices)
- To detect and prevent fraud and abuse
- To improve the Service based on aggregate usage patterns
We do not sell your data to third parties.
4. Third-Party Services (Subprocessors)
We share data with these processors to operate the Service. Each is contractually bound (Data Processing Agreements or equivalent terms) to use data only for the specified purpose and to maintain appropriate security.
- Supabase (EU region) — Postgres database + Storage for photos, videos, and generated PDFs.
- Stripe (global) — payment processing, checkout sessions, subscription management. Card details never touch our servers.
- Vercel (global) — web frontend hosting.
- DigitalOcean (EU region) — backend API hosting (Kubernetes).
- Bunny CDN (global) — CDN for public short-link redirects and gallery photo delivery. Cache TTL kept short (minutes to hours).
- Cloudflare — DNS only (grey-cloud / no proxying). We migrated away from CF proxying to Bunny CDN in mid-2026.
- OpenAI (US) — text: AI chat assistant for landing-page authoring. images: photo analysis for AI Curated Album (see §4b). API zero-retention by default; inputs not used for training.
- Replicate (US) — hosted CLIP embedding model for photo similarity in the AI Curated Album pipeline. Photo URLs sent as public bytes; embeddings returned. See §4b.
- Gelato (Norway HQ, EU-US print centers) — physical fulfillment of Wedding Albums. Receives: shipping address, buyer name, buyer email, cover + interior PDF URLs.
- Resend (US) — transactional email delivery (order confirmations, magic links, notifications). Receives: recipient email + message content.
Transfers to US-based processors rely on Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework. A current subprocessor list is available on request at privacy@qr-maker.io.
4b. AI Processing of Photos (AI Curated Wedding Album)
When you (a paid wedding-gallery host) request an AI Curated Wedding Album, we run each approved photo in the gallery through an automated pipeline to select the best 30. Here is exactly what happens per photo:
- The photo's public URL is sent to OpenAI Vision (
gpt-4o-mini) with a fixed prompt. OpenAI returns a JSON object with: face count, an overall face-quality score, sharpness score, wedding-scene label (from a fixed 10-label vocabulary), and a short factual caption. The photo itself is not stored by OpenAI beyond the request lifetime (API zero-retention). - The photo's public URL is sent to Replicate to compute a 768-dimensional CLIP embedding used for near-duplicate detection and similarity clustering. Replicate retains prediction records for up to 1 hour by default for debugging.
- The resulting features (hash, embedding hash, face count, quality score, scene label, caption) are stored on our database and used to select the 30 photos that will appear in the printed album.
This is not biometric identification. We do not attempt to recognise, match, or identify any individual across photos or against any external database. We do not build face templates. Face count and face-quality are aggregate scene qualities used solely to pick photos that will look good in print (e.g. sharp, eyes open) — the same criteria a human photographer applies. Under GDPR Article 9, biometric data becomes special-category only when processed for the purpose of uniquely identifying a natural person; our processing has a different purpose (aesthetic quality scoring for album layout) and does not fall into that category.
Legal basis (GDPR): legitimate interests of the host (Art. 6(1)(f)), balanced against the interests of the guest photographers whose faces may appear in group shots. Guest email addresses are never sent to AI subprocessors; only the photo bytes.
Your rights: if you are a guest who does not want a photo you appear in to be processed by AI, email the host with the photo removed request, or contact privacy@qr-maker.io — we will remove specific photos or entire galleries on documented request. Deletion propagates: the photo is removed from our storage, and cached features are dropped.
5. Data Retention
- Account data: retained while your account is active, then 30 days after closure
- QR scan analytics: 2 years
- Billing records: 7 years (legal obligation)
- Server logs: 30 days
- Photo galleries (free tier): 7 days after gallery expiry
- Photo galleries (paid Memories tier): kept for the lifetime of your account or until you delete them
- AI-derived photo features (embeddings, face count, scene labels): kept alongside the source photo — deleted when the photo is deleted
- Wedding Album orders (physical): order + shipping details retained 7 years (accounting)
6. International Transfers
We are primarily based in the EU. Some processors operate in the US. Transfers from the EU to the US are covered by Standard Contractual Clauses (SCCs) and, where applicable, the EU-U.S. Data Privacy Framework.
7. Your Rights
Depending on your location, you may have the following rights:
EU/EEA (GDPR)
- Access — obtain a copy of your personal data
- Rectification — correct inaccurate data
- Erasure ("right to be forgotten")
- Restriction of processing
- Data portability
- Object to processing based on legitimate interests
- Withdraw consent at any time
- Lodge a complaint with your national supervisory authority
California (CCPA/CPRA)
- Know what personal information is collected and how it is used
- Delete your personal information
- Correct inaccurate information
- Opt out of sale/sharing (we do not sell data)
- Non-discrimination for exercising rights
To exercise any of these rights, email privacy@qr-maker.io. We will respond within 30 days.
8. Children's Privacy
The Service is not directed to children under 13. We do not knowingly collect data from children. If you believe a child has provided us data, contact privacy@qr-maker.io and we will delete it promptly.
9. Security
We use industry-standard measures including encryption in transit (TLS), encryption at rest, access controls, and regular security reviews. No system is perfectly secure — please use a strong, unique password and enable two-factor authentication where available.
10. Changes
We will notify you of material changes by email or by displaying a prominent notice on the Service before changes take effect.
11. Contact
Privacy questions or requests: privacy@qr-maker.io