Legal · Version 2026-08-05-v620
Privacy Policy
We collect account, upload, generated-work, log and payment metadata needed to operate Magic QR Studio. Uploaded images and generated outputs are stored according to the retention policy and are not sold to advertisers. Formal QR payloads are protected and private signed URLs are used for generated assets.
These policies govern use of Magic QR Studio SaaS, including accounts, uploads, generated works, checkout, credits, plans, private downloads, support and content safety.
1. Controller, scope and contact
The operator identified on the Contact Support page is the controller of personal data processed for the service. Current legal identity, trading name, address, country and contact details are published only on that page. Privacy questions and rights requests may be sent to [email protected].
This policy applies to the website, accounts, uploads, generated works, support, purchases and related security and operational systems. Creem and other providers may act as independent controllers for their own checkout, authentication or platform activities under their notices.
2. Sources of personal data
- Information you provide through account, upload, generation, profile, support, feedback, refund and privacy-request interfaces.
- Information generated by your browser, device, network, security controls and use of the service.
- Authentication information received from Google or email sign-in flows.
- Order, tax, payment-status, refund and dispute information received from Creem; full card data is not received or stored by Magic QR Studio.
- Safety, delivery and infrastructure information received from hosting, email, storage, security and content-safety providers.
3. Categories of data collected
- Identifiers and account data: email, display name, avatar, user ID, authentication provider, password hash if you enable a password, session and verification identifiers, locale and time zone.
- Content data: uploaded images and GIFs, QR/barcode payloads and links, generated works, thumbnails, crop choices, titles, descriptions, validation and safety results and download selections.
- Commerce data: selected product, credits, plan period, order and transaction identifiers, payment status, invoice/refund/chargeback information and purchase-consent evidence including legal versions, displayed text, timestamps and request identifiers.
- Technical and approximate location data: IP address, country/city supplied by the trusted edge, browser/user-agent hash, device and request metadata, cookies, login history, rate-limit, security, diagnostic, job, scan and performance records.
- Communications: support tickets, feedback, copyright complaints, privacy requests, attachments and related correspondence.
- Traceability data: work IDs and technical watermark data that may be linked to an account, work, timestamp and integrity record.
4. Purposes and legal bases
- Contract and requested steps: create and secure accounts; process uploads; generate, validate, store and deliver outputs; administer credits, plans, downloads, support and account deletion; and take steps requested before a purchase.
- Legal obligations: accounting, tax and payment records; responding to lawful requests; consumer, sanctions and regulatory compliance; and required notices.
- Legitimate interests: service security, fraud and abuse prevention, rate limiting, reliability, debugging, product integrity, enforcing terms, preserving evidence, handling claims and improving existing features. These interests are balanced against user rights and are not used to override mandatory consent requirements.
- Consent: only where a specific optional activity legally requires it, such as future non-essential cookies or marketing. You may withdraw consent prospectively. Purchase-policy acknowledgment is not consent to advertising or optional tracking.
- Legal claims and vital/public interests where applicable: establishing, exercising or defending claims and responding to serious safety or legal threats.
5. Required and optional information
Account identifiers, authentication data, selected product and the content needed for a requested output are contractually necessary. Without them, the relevant account, generation, purchase or support feature cannot be provided. Profile nickname, avatar, optional descriptions and identified feedback are generally optional. Do not provide more personal or sensitive information than necessary.
6. Recipients, processors and disclosures
We disclose only the data reasonably necessary to providers supporting hosting and databases, private object storage and edge security, authentication, transactional email, content or URL safety, payment/merchant-of-record services, error monitoring where enabled, professional advisers and lawful authorities. Depending on configuration, principal providers may include Cloudflare, Zeabur, Google, Zoho or Brevo, Sentry and Creem. The Trust Center identifies their roles and whether a service is optional.
Depending on the configured safety provider, a reduced or compressed copy of an uploaded image may be sent to Cloudflare Workers AI or Google Cloud Vision for safety classification. A submitted destination URL may be checked through Google Safe Browsing when that optional feature is enabled. When Sentry error monitoring is enabled, minimised error and performance metadata may be sent with default personal-data collection disabled; application logs and payloads should not intentionally include passwords or full payment-card details.
Provider processing is governed by the applicable service and data-processing terms, with additional agreements completed where required. We may disclose or transfer data in a lawful merger, acquisition, financing, reorganisation or asset sale, with appropriate confidentiality and notice where required. We do not sell personal data or share it for cross-context behavioural advertising.
7. Creem checkout and independent processing
Creem acts as merchant of record and legal seller for checkout transactions. It independently collects payment, billing and tax details, issues invoices and administers refunds or chargebacks under its buyer terms and privacy notice. Magic QR Studio receives only the transaction, entitlement, identity and dispute information needed to provide the product and reconcile the account.
8. International transfers and regional representatives
The controller is established in China and providers may process data in other countries. Those countries may have different data-protection laws. Before a restricted transfer is made where law requires safeguards, the operator must put an applicable mechanism in place. Depending on the provider and transfer route, this may be an adequacy decision, recognised contractual clauses, the UK Addendum or IDTA, or another lawful mechanism supported by organisational and technical measures. You may request information about the current mechanism.
If EU GDPR Article 27, UK GDPR Article 27 or another law requires a regional representative, verified representative details will be published on the Contact Support page and in this policy. Contacting the controller directly remains available and does not limit your right to contact a regulator.
9. Retention and deletion
Retention follows the Data Retention Policy. Works normally remain for the plan-specific period; orphan uploads and intermediate files are removed earlier; login and most operational records normally remain up to 90 days; rate-limit data normally up to 2 days; and billing, legal-consent, fraud and dispute records remain for applicable accounting, chargeback, limitation and legal periods.
Account deletion starts deletion or de-identification from active systems, but minimum transaction, consent, security and legal records and encrypted backups may remain where necessary or required. We do not retain personal data longer than reasonably necessary for the disclosed purpose.
10. Security and incident response
Measures include access controls, password hashing, HttpOnly sessions, transport encryption, private storage, short-lived signed URLs, encryption of formal payloads where stored internally, request validation, rate limiting, audit records and least-privilege operational access. No method is completely secure.
We investigate suspected personal-data incidents and notify affected people and regulators when applicable law requires it. Never send passwords, full card numbers or unnecessary identity documents to support.
11. Your privacy rights
Depending on location and applicability, you may request access, correction, deletion, restriction, objection, portability or a copy; withdraw consent; opt out of sale, sharing, targeted advertising or eligible profiling; limit certain sensitive-data uses; appeal a denied request; and complain to a supervisory authority or attorney general.
Right to object: where processing relies on legitimate interests, you may object based on your particular situation. We will stop that processing unless we demonstrate compelling lawful grounds or the processing is needed for legal claims. We do not currently process personal data for direct marketing; if that changes, a direct-marketing objection will be honoured as required by law.
Submit requests or data-protection complaints through the Data Requests page or [email protected]. We verify identity proportionately. Rights requests are normally answered within one month under EU/UK GDPR, subject to lawful extensions. Where California law applies, receipt of requests to know, delete or correct is normally confirmed within 10 business days and a substantive response is normally provided within 45 calendar days, subject to a lawful extension. UK data-protection complaints are accepted electronically, acknowledged within 30 days, investigated appropriately and answered without undue delay. Exercising rights does not result in unlawful discrimination.
12. United States and California notice
During the preceding 12 months, the service may have collected the identifier, customer-record, commercial, internet/network activity, approximate geolocation, professional or organisational, user-content and account-credential categories described above. Sources, purposes, retention criteria and recipient categories are described in sections 2–9. We disclose relevant categories to service providers and contractors for business purposes but do not sell them or share them for cross-context behavioural advertising.
Account login credentials may be treated as sensitive personal information under some US laws. They are used only for authentication, security, fraud prevention and requested service functions. IP-derived country and city are approximate and are not used to infer sensitive characteristics. Because we do not sell or share personal information, an opt-out-of-sale link is not currently required for our practices; recognised browser opt-out signals do not change that status. If practices change, required controls and notices will be provided before the change. CCPA rights apply only when statutory thresholds and scope requirements are met.
13. Adults only, automated decisions and marketing
The service is intended for adults aged 18 or older and is not directed to children. If we learn that a child provided personal data contrary to this rule, contact us so it can be reviewed and deleted where required.
We do not make solely automated decisions that produce legal or similarly significant effects about users and do not use account or uploaded content for behavioural advertising. Transactional account, security and purchase messages are not marketing.
14. Changes to this policy
We review this policy when products, providers or laws materially change. A new effective date and legal version are published, and additional notice or consent is obtained where required before materially different processing begins. We do not rely on a silent retroactive policy change to authorise a materially broader use of previously collected data.
Support: [email protected]
For privacy, copyright, data, billing or security requests, contact [email protected]. We may ask for job ID, code ID, order ID or account email to verify and investigate the request.