Legal

Privacy & Cookies

What VastQR stores, why it stores it, and for how long. This describes what the product actually does rather than what a template says a product might do.

Last updated 24 September 2026.

Cookies and similar technologies

NameSet byLifetimeWhat it is for
vq_qidVastQR (first party)Up to 30 days, refreshed by each qualifying activityKeeps one qualified journey joined together across pages, signing in, and the trip through our payment provider — so we can measure how the bulk QR workflow performs. See below.
vastqr_first_touchVastQR (first party) — browser local storage, not a cookieUp to 30 daysRemembers, in your browser only, which page you first landed on, which website linked you, and — if a ChatGPT ad brought you here — OpenAI's reference for that ad click. The landing details are sent to us only if you go on to prepare a valid batch; the ad click reference only when you create an account, sign in or sign up with Google, or start checkout. See below.
sb-…-auth-tokenSupabase (our authentication provider)SessionKeeps you signed in. Without it you would have to log in on every page.
_ga, _ga_…Google AnalyticsUp to 2 yearsAggregate website analytics — which pages are read, roughly how people move through the site.

VastQR does not use advertising cookies or an advertising pixel, does not build advertising audiences, and does not use browser or device fingerprinting. We do measure, from our own servers, whether ChatGPT Ads lead to sign-ups and payments — see who else is involved.

There is no cookie consent banner on this site today

We are telling you that plainly rather than leaving you to notice. Whether one is required depends on where you are and on rules we are not going to summarise for you here. If you want the cookies above gone in the meantime, your browser can block or clear them; the two product ones will simply stop working as described.

The vq_qid measurement cookie

When you paste or upload a batch and our parser finds at least one row it can turn into a QR code, our server issues a random identifier and stores it in a cookie called vq_qid. It is first-party, HttpOnly (pages cannot read it, including ours), SameSite=Lax, and it is kept for up to 30 days from your most recent qualifying activity. That clock restarts each time you prepare another valid batch, so a browser that keeps coming back keeps the same identifier; one that stops sees it expire 30 days after the last time.

Its one job is to keep a single journey joined together. Preparing a batch, creating an account and paying happen across several pages and a round trip through our payment provider’s website; without something carrying across, we could not tell whether the workflow works — only that some people arrive and some people pay.

What it is not

It is not an identifier for you. It identifies a browser for as long as that browser keeps qualifying, and for 30 days after it stops — which is not the same thing: several people can share a browser, one person can use several. We do not treat it as a person, a visitor count, or a unique user, and nothing in the product tries to work out who you are from it.

It is not used for advertising, is not shared with advertising networks, does not follow you to other websites, and is not combined with fingerprinting — we do not do fingerprinting at all.

Where you came from

If you go on to prepare a valid batch, the record also notes the page you first landed on and, when there was one, the website name that linked you — for example a search engine or a blog. We keep the name of that site and never the full address of the page, because a full address can carry things that have nothing to do with us, such as what you searched for. If the link you followed carried campaign tags, we keep those three tags as written.

VastQR stores limited first-party attribution information in your browser so we can understand how visitors arrive at the service. This may include landing-page information, referral information, campaign parameters, and, when present, an advertising click reference supplied by OpenAI after a ChatGPT ad click. Most attribution fields use first-touch attribution. A later valid ChatGPT ad click may update only the OpenAI click reference. The OpenAI click reference expires after 30 days unless a new qualifying ChatGPT ad click supplies a new value.

When you begin checkout, the applicable advertising click reference may also be associated with the checkout or subscription record so that a later first paid subscription can be attributed to the advertising interaction. That copy is held with our billing records, not in your browser, so the 30-day expiry above does not apply to it — see how long we keep things.

The click reference is the code OpenAI adds to the link when one of our ChatGPT ads brought you here; it is not your name or contact details, and without such a click there is none.

This record is kept in your browser’s local storage under vastqr_first_touch, for up to 30 days from the moment it is recorded, or until you clear your browser storage. The landing details are sent to us only if you go on to prepare a valid batch; preparing one does not erase the copy in your browser, which stays until those 30 days are up. Within those 30 days the first page wins: coming back later, or arriving from somewhere else, does not overwrite it. After 30 days the stored copy is discarded, so a visit after that can record a new first touch. It describes how you arrived — not where you go on this site or any other.

The ad click reference is sent to us only when you create an account, when you sign in or sign up with Google, or when you start checkout. The same Google button is used on the sign-up and the log-in pages, so the reference also travels with an ordinary Google sign-in to an account you already have. Signing in is not a registration: we report a registration to OpenAI only when a genuinely new account has just been created, never when an existing account signs in — with Google or with a password, and whether or not an ad click reference is present.

What the measurement record contains

StoredNot stored
  • the random identifier
  • which pricing treatment you saw
  • when you reached a valid preview
  • when you clicked through to activate or to pay
  • how many valid rows your batch had
  • your account id, once you have an account
  • the page you first landed on, the website name that linked you, and any campaign tags in the link you followed
  • how many checkout sessions were created for you, and when the last one was
  • how many attempts to create one failed, when the last failure was, and a short technical category for it — one of four fixed words describing what went wrong on our side or Stripe’s, never the payment provider’s own error message
  • how many times you came back to our cancelled-payment page, and when the last one was
  • the contents of your CSV
  • any destination URL
  • your email address
  • your QR codes or their short links
  • your IP address
  • your browser’s user agent
  • any fingerprint
  • the full address of the page that linked you — only its website name
  • card or payment details of any kind
  • the payment provider’s raw error messages or payloads — only the short category described on the left

We keep this for up to 12 months, or until the pricing experiment it exists for is finished — whichever comes first. After that we keep only totals per treatment per week, which describe no individual journey.

What we store when you use the product

Your batches and QR codes

We store the destination URLs and titles you give us, because that is the product: a dynamic QR code is a short link we keep pointing at a destination you can change. We also store any logo you upload and any name you give a batch.

While you are still preparing a batch and have not signed in, it stays in your own browser’s storage and is not sent to us. It is cleared when the batch is created, and expires by itself after 24 hours.

Scans of your QR codes

When someone scans one of your codes, the request reaches us before we forward it on, and we record that it happened. For each scan we store the code that was scanned, the time, and whatever context arrived with the request:

  • the country and, where our edge network supplies it, an approximate city;
  • approximate coordinates for that city, where supplied;
  • the scanning browser’s user agent string, which is how we tell a person’s phone from a crawler or a link preview.

This is location to the resolution a network already knows, not a person’s position, and we do not ask for or receive GPS. Scan records belong to the account that owns the code and are deleted when the code is deleted.

If you print our codes, this applies to your scanners
People who scan your QR codes have no relationship with us, and the record above is created by their scan. If you are subject to obligations about the people who scan your printed material, that is a decision for you rather than something we can make on your behalf.

Your account and payments

Signing up stores your email address, which is how you log in and how we reach you about your account. Authentication is handled by Supabase on our behalf.

Payments are handled by Stripe. Card details are entered on Stripe’s own payment page and never reach VastQR’s servers — we do not see, store or process a card number. What we keep is what we need to know whether your subscription is live: Stripe’s identifiers for your customer and subscription, its status, the renewal date, and — where it applies — trial dates. The plan is $19/month.

How long we keep things, and getting them removed

DataKept
Prepared batch, before you sign inIn your browser only. 24 hours, or until the batch is created
QR codes, batches, logosFor as long as the account exists
Scan recordsWith the code they belong to; deleted when it is deleted
vq_qid cookieUp to 30 days from your most recent qualifying activity — the clock restarts each time
vastqr_first_touch (browser local storage)In your browser only. Up to 30 days from when it is recorded (an ad click reference: used for up to 30 days from that click), or until you clear your browser storage
Advertising conversion records — what we send to OpenAI, and the ad click reference copied to your subscription at our payment providerKept in our database and in that subscription record, alongside the billing records
Experiment measurement recordUp to 12 months, or until the experiment ends
Account and billing recordsFor as long as the account exists, and afterwards where we are required to keep billing records

Deleting a QR code deletes its scan records with it. For anything else — a copy of what we hold, a correction, or deletion of your account — write to hello@vastqr.com and we will deal with it directly.

Who else is involved

ProviderWhat they do for us
SupabaseStores the database and handles signing in
VercelRuns the website and the redirect that makes dynamic QR codes work
StripeTakes payments. Card details go to Stripe, not to us
Google AnalyticsAggregate website analytics
OpenAI AdsReceives limited server-side conversion measurement data relating to account registrations, checkout starts, and paid subscriptions so VastQR can measure the performance of ChatGPT Ads.

For this integration, measurement data may include the conversion event type and time, the relevant VastQR source URL, an OpenAI-provided advertising click reference when available, and subscription plan, value, and currency information when applicable. VastQR’s current server-side OpenAI Ads integration does not intentionally send payment-card details, names, email addresses or email hashes, phone numbers or phone hashes, IP addresses, user-agent strings, or OpenAI browser advanced-matching identifiers.

This measurement is sent from our servers only; there is no OpenAI pixel, script or cookie on this site. Each event also carries a reference that lets OpenAI discard duplicates, so the same registration, checkout or subscription is never counted twice. That reference is a one-way hash derived from our internal record number for the account, checkout or subscription, not the record number itself.

We do not sell your personal information. We may share limited conversion-measurement data with advertising measurement providers, such as OpenAI, to understand whether advertising leads to registrations, checkout activity, or paid subscriptions.

Contact

Questions about anything on this page: hello@vastqr.com.