Legal
Privacy & Cookies
What VastQR stores, why it stores it, and for how long. This describes what the product actually does rather than what a template says a product might do.
Last updated 24 August 2026.
Cookies and similar technologies
| Name | Set by | Lifetime | What it is for |
|---|---|---|---|
vq_qid | VastQR (first party) | 30 days | Keeps one qualified journey joined together across pages, signing in, and the trip through our payment provider — so we can measure how the bulk QR workflow performs. See below. |
sb-…-auth-token | Supabase (our authentication provider) | Session | Keeps you signed in. Without it you would have to log in on every page. |
_ga, _ga_… | Google Analytics | Up to 2 years | Aggregate website analytics — which pages are read, roughly how people move through the site. |
VastQR does not use advertising cookies, does not build advertising audiences, and does not use browser or device fingerprinting.
We are telling you that plainly rather than leaving you to notice. Whether one is required depends on where you are and on rules we are not going to summarise for you here. If you want the cookies above gone in the meantime, your browser can block or clear them; the two product ones will simply stop working as described.
The vq_qid measurement cookie
When you paste or upload a batch and our parser finds at least one row it can turn into a QR code, our server issues a random identifier and stores it in a cookie called vq_qid. It is first-party, HttpOnly (pages cannot read it, including ours), SameSite=Lax, and it expires after 30 days.
Its one job is to keep a single journey joined together. Preparing a batch, creating an account and paying happen across several pages and a round trip through our payment provider’s website; without something carrying across, we could not tell whether the workflow works — only that some people arrive and some people pay.
What it is not
It is not an identifier for you. It identifies a browser for thirty days, which is not the same thing: several people can share a browser, one person can use several. We do not treat it as a person, a visitor count, or a unique user, and nothing in the product tries to work out who you are from it.
It is not used for advertising, is not shared with advertising networks, does not follow you to other websites, and is not combined with fingerprinting — we do not do fingerprinting at all.
What the measurement record contains
| Stored | Not stored |
|---|---|
|
|
We keep this for up to 12 months, or until the pricing experiment it exists for is finished — whichever comes first. After that we keep only totals per treatment per week, which describe no individual journey.
What we store when you use the product
Your batches and QR codes
We store the destination URLs and titles you give us, because that is the product: a dynamic QR code is a short link we keep pointing at a destination you can change. We also store any logo you upload and any name you give a batch.
While you are still preparing a batch and have not signed in, it stays in your own browser’s storage and is not sent to us. It is cleared when the batch is created, and expires by itself after 24 hours.
Scans of your QR codes
When someone scans one of your codes, the request reaches us before we forward it on, and we record that it happened. For each scan we store the code that was scanned, the time, and whatever context arrived with the request:
- the country and, where our edge network supplies it, an approximate city;
- approximate coordinates for that city, where supplied;
- the scanning browser’s user agent string, which is how we tell a person’s phone from a crawler or a link preview.
This is location to the resolution a network already knows, not a person’s position, and we do not ask for or receive GPS. Scan records belong to the account that owns the code and are deleted when the code is deleted.
Your account and payments
Signing up stores your email address, which is how you log in and how we reach you about your account. Authentication is handled by Supabase on our behalf.
Payments are handled by Stripe. Card details are entered on Stripe’s own payment page and never reach VastQR’s servers — we do not see, store or process a card number. What we keep is what we need to know whether your subscription is live: Stripe’s identifiers for your customer and subscription, its status, the renewal date, and — where it applies — trial dates. The plan is $19/month.
How long we keep things, and getting them removed
| Data | Kept |
|---|---|
| Prepared batch, before you sign in | In your browser only. 24 hours, or until the batch is created |
| QR codes, batches, logos | For as long as the account exists |
| Scan records | With the code they belong to; deleted when it is deleted |
vq_qid cookie | 30 days |
| Experiment measurement record | Up to 12 months, or until the experiment ends |
| Account and billing records | For as long as the account exists, and afterwards where we are required to keep billing records |
Deleting a QR code deletes its scan records with it. For anything else — a copy of what we hold, a correction, or deletion of your account — write to hello@vastqr.com and we will deal with it directly.
Who else is involved
| Provider | What they do for us |
|---|---|
| Supabase | Stores the database and handles signing in |
| Vercel | Runs the website and the redirect that makes dynamic QR codes work |
| Stripe | Takes payments. Card details go to Stripe, not to us |
| Google Analytics | Aggregate website analytics |
We do not sell your data, and we do not share it with advertising networks.
Contact
Questions about anything on this page: hello@vastqr.com.