Legal
Privacy Policy
This Privacy Policy explains how QRowl (“QRowl”, “we”, “us”) handles personal information when you use this marketing website and, if you use our hosted application, the QRowl product service.
It is written to match how the product works today. It is not legal advice. If you need a contract for a specific jurisdiction or industry, talk to your counsel.
1. Who this covers
- Marketing site — the public pages that describe QRowl.
- Hosted QRowl — workspaces, product catalogs, QR codes, GS1 Digital Link resolution, and related features we operate for customers.
- Self-hosted installs — if you run QRowl on your own servers, you operate that installation. This policy does not replace your own privacy notice for that environment, unless we separately agree otherwise.
2. Information we collect
Account and workspace
When you register or join a workspace, we process information such as name, email address, password (stored hashed), organization/workspace details, role, and email verification status.
Product and brand content
Workspace users upload or enter business content so QRowl can publish product pages and codes. That can include product names and descriptions, brand details, images, GTINs and related identifiers, batch/lot/expiry/serial data, certifications, support contacts, and page theme settings. This content is provided by your organization. Your organization is responsible for having the right to use it.
Scan and usage activity
When someone opens a public product page or resolves a Digital Link, we may record a scan or visit event used for workspace analytics and basic risk signals. That record can include timestamps, product/batch/unit references, a hashed IP address, a hashed user-agent string, a coarse country derived from request headers when available, a device class, and derived summaries (for example totals or last-scan time). We do not store a raw IP address in scan records. We do not use scans as proof that a physical product is authentic, and we do not use them to advertise.
Billing
If you choose a paid plan, Polar processes checkout and payment details on Polar’s pages. We receive subscription status, customer identifiers, and related billing records needed to apply your plan. We do not store full payment card numbers.
Support and operations
If you contact us, we process the information you send. Server logs and security records may also include technical data needed to run and protect the service.
Marketing site
This marketing site is primarily static. It does not require an account. See the Cookies page for cookie details.
3. How we use information
- Provide, maintain, and secure QRowl
- Create and manage workspaces, roles, and publishing controls
- Generate product links, QR codes, and GS1 Digital Link URLs from identifiers you supply
- Show public product pages and related verification/recall notices you configure
- Send transactional email such as verification and password reset messages
- Provide scan activity summaries in the workspace
- Comply with law and enforce our Terms
Where a legal basis is required, we rely on: performance of a contract (accounts, workspaces, the hosted service you asked us to run); legitimate interests in operating, securing, and understanding use of the service (including hashed scan records and server logs); and consent where you tick the terms box at registration or acknowledge the cookie notice. We do not sell personal information.
4. Roles for hosted workspaces
For hosted QRowl, your organization typically decides what product and customer-facing content to store. We process that content to provide the service. For that customer content and for scan activity on your published pages, your organization is the controller and we are the processor. Account credentials, billing records we keep to run the subscription, and service operations data are processed so we can run authentication, hosting, and support; for that account and operations data we are the controller.
5. Sharing
We share information only when needed to operate QRowl. That includes infrastructure and hosting providers, email delivery for transactional messages, a content-delivery or reverse-proxy network in front of the site, and Polar for paid-plan checkout. Those parties act on our instructions or, for Polar checkout, under Polar’s own terms for the payment step. We also share when you ask us to (such as inviting a teammate) or when required by law. Public product pages show the content your workspace publishes.
6. Retention
We keep account and workspace data while the account/workspace is active and for a reasonable period afterward for backups, security, dispute handling, and legal requirements. You can request deletion of an account or workspace through the contact method below; some residual copies may remain in backups for a limited time.
7. Security
We use administrative and technical measures appropriate to a hosted application, including access controls, hashed passwords, and transport encryption for the hosted service. No method of transmission or storage is perfectly secure.
8. International transfers
If we host or process data in more than one country, we take steps intended to protect it in line with this policy and applicable law. Ask us where your hosted workspace data is stored if you need that for your own assessments.
9. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or restrict certain personal information, or to object to certain processing, and to lodge a complaint with a supervisory authority. Workspace owners can update or remove much of their catalog content directly in QRowl. For account or privacy requests, use the contact details below. We may need to verify the request.
10. Children
QRowl is a business service. You must be at least 16 and able to bind the organization you register. It is not directed at children.
11. Cookies
We use only cookies needed to run QRowl (sign-in, security, and form protection). We do not use advertising or analytics cookies. See the Cookies page for names, Polar checkout cookies on Polar’s domain, and how the on-page notice works.
12. GS1 identifiers
QRowl does not issue GTINs or GS1 company prefixes. If you enter GTINs or related identifiers, you are responsible for using identifiers you are authorized to use.
13. Changes
We may update this policy as the product or law changes. The effective date above will change when we do. Continued use of the hosted service after an update means the revised policy applies to that use.
14. Contact
Privacy questions: [email protected]