Legal
Cookies
This page describes cookies and similar technologies for the QRowl marketing site and the hosted QRowl application operated by QRowl.
We do not use advertising cookies, analytics trackers, or ad networks. The cookies we set are needed to run the product: sign-in, security, and form protection. A short notice on our pages explains this. Choosing Accept stores that you have seen the notice. It does not turn on extra tracking.
1. Marketing website
The marketing pages are primarily static. They do not require login. As shipped, they do not set advertising or analytics cookies. If our hosting or content-delivery network adds a strictly technical cookie for security or performance, that cookie is not used to advertise to you.
The cookie notice on these pages stores an acknowledgement in your browser’s local storage (qrowl.cookie-notice). That value is not a tracking identifier.
2. Hosted QRowl application
When you use the hosted app (including sign-in, registration, the workspace, and public product pages on the QRowl host), we use first-party cookies that are needed to operate the service:
- Session cookie (typically
qrowl-session) — keeps you signed in while you use the app and remembers short-lived form state such as the plan you chose. - CSRF / XSRF cookie (
XSRF-TOKEN) — helps prevent cross-site request forgery on forms. - Remember me — only if you choose that option at sign-in, so you can stay signed in on that browser.
These are operational cookies for authentication and security, not advertising trackers. If you block them, sign-in and some forms will not work.
3. Public product pages and scans
Opening a published product page, batch page, or unit page is not done with a marketing cookie. We may record a scan event for the workspace that published the page. Scan records store a hashed IP address, a hashed user-agent string, a coarse country derived from request headers when available, a device class, timestamps, and the product/batch/unit that was opened. We do not store a raw IP address in scan records, and we do not use scans to advertise or to prove that a physical product is authentic.
On a verified custom domain, the same public pages are still QRowl-hosted content. Cookie and privacy links on those pages point back to this QRowl site so the notice is not trapped on the custom domain.
4. Payments
If you start a paid plan, checkout is handled by Polar on Polar’s domain. Polar may set its own cookies under its terms. We do not receive your full payment card details. Polar sends us the subscription and customer records we need to apply your plan.
5. Self-hosted installs
If you run QRowl yourself, cookie behavior follows your deployment and any changes you make. You are responsible for your own cookie notices where required.
6. Managing cookies
You can block or delete cookies in your browser. Clearing site data also removes the cookie-notice acknowledgement, so the notice can appear again. If you block required cookies on the hosted app, sign-in and some features may not work.
7. More information
See also our Privacy Policy and Terms of Service.
Questions: [email protected]