NodQR Privacy Policy
Last updated: 30 September 2026
This policy explains how NOD88 Ltd uses personal data in connection with NodQR, including the website at nodqr.com, the short link domain nqr.io, our API and our integrations.
1. Who we are
NodQR is provided by NOD88 Ltd, a company registered in England and Wales (company number 17381626). We are registered with the Information Commissioner's Office (ICO) under registration number ZC247875.
For anything about your personal data, email privacy@nodqr.com.
2. Two kinds of people, two different roles
NodQR involves personal data about two groups of people, and our role is different for each:
- Our customers: people who sign up for and use NodQR. For their account, billing and support data, we are the controller, which means we decide how and why the data is used. Sections 3 to 5 cover this.
- People who scan a QR code or open a short link: when someone scans a code or clicks a link created by one of our customers, we record basic information about the scan so our customer can see how their links perform. For this scan data, our customer is the controller and we act as their processor, handling it only on their behalf. Section 6 covers this. If you scanned a code and have questions, the business that created it is usually the best first contact, but you are welcome to contact us too.
3. Customer data we collect
Account details: your name, email address, password (stored only in scrambled, hashed form) and the organisations you belong to, with your role in each.
Organisation details: organisation names, plans, team members and invitations (including the email addresses of people you invite).
Your content: links, destinations, names, folders, tags, custom back-halves, logos and brand settings. This usually isn't personal data, but it can be, for example if a logo includes a person's photo.
Billing details: when paid plans are available, our payment provider collects your payment details. We receive limited information such as your billing name, country, the last four digits of your card and your payment history. We do not see or store full card numbers.
Communications: emails you send us and our replies.
Technical and security data: records of sign-ins, API key use and actions taken in your account, kept to keep the Service secure and to investigate problems. Our providers also process the IP addresses of people using the website and app to deliver and protect the Service.
Business search: when you search for a business to create a review code, what you type is sent to our mapping provider to find matching businesses. We store only the identifier of the business you choose, not the search itself.
Approximate country: when you visit our website, we use your approximate country, worked out from your connection, to show prices in your local currency. It is used only at that moment and is not stored.
4. How we use customer data, and our legal bases
| What we do | Legal basis under UK GDPR |
|---|---|
| Create and run your account and organisations, provide the Service, and send you essential emails (such as confirming your email, resetting your password, invitations and billing notices) | Performance of our contract with you |
| Take payments and keep accounting records | Contract, and legal obligation (tax and accounting law) |
| Keep the Service secure, prevent abuse (for example phishing links), and enforce our terms | Our legitimate interests in running a safe, reliable service |
| Answer your questions and support requests | Contract, or our legitimate interests |
| Understand how NodQR is used so we can improve it | Our legitimate interests |
| Tell you about new features and offers by email | Your consent, or our legitimate interests for existing customers where the law allows, and you can opt out at any time |
| Comply with the law and respond to lawful requests | Legal obligation |
Where we rely on legitimate interests, we have considered your interests and rights and concluded they are not overridden. You can ask us for more detail.
When you invite someone to your organisation, we use their email address to send them the invitation. Please only invite people who would expect to hear from you.
5. How long we keep customer data
- Account and organisation data: for as long as your account is active. If you close your account or an organisation is deleted, we delete the related data within 90 days, apart from the items below.
- Inactive organisations: if a paid plan ends and the organisation becomes inactive, we keep its data for up to 12 months so it can be restored if you resubscribe, then delete it. We email owners before deleting.
- Invitations: expire after 7 days, and we delete invitation records within 90 days.
- Billing and accounting records: 6 years, as required by UK tax law.
- Security logs: up to 12 months.
- Backups: deleted data may remain in encrypted backups for a short period, typically up to 30 days, until those backups expire.
6. Scan data (people who scan codes or open links)
What we record. When someone scans a NodQR QR code or opens a NodQR short link, we record:
- the date and time, and which link was used;
- approximate location (country and city), worked out from the network connection at the moment of the scan;
- device type (for example phone or computer), operating system and browser;
- the page the person came from, where their browser shares it; and
- a visitor identifier, used to count unique visitors.
What we do not store. We do not store the IP address of anyone who scans a code. The visitor identifier is created by combining the IP address and browser details with a random value, then scrambling them with a one-way hash. The random value changes every day and the old one is deleted, so identifiers cannot be reversed or linked from one day to the next, even by us.
No tracking cookies. Redirects do not set cookies, and we do not use scan data for advertising, profiling or tracking people across websites.
Why. To send the person to the right destination and to give our customer statistics about how their links perform. We do this as our customer's processor, under their instructions and our Data Processing Terms.
How long. For as long as our customer keeps the link. Deleting a link deletes its scan data, and scan data is also deleted when the customer's organisation is deleted.
Blocked links. If we disable a link because it breaks our terms, for example because it points to a phishing site, we may keep a record of the link and destination to prevent further abuse.
7. Cookies and similar technology
On nodqr.com we only use storage that is strictly necessary for the Service to work, such as keeping you signed in, remembering which organisation you last used and remembering the currency you chose for prices. These do not require consent. We do not use advertising or third-party analytics cookies. If that changes, we will update this policy and ask for your consent where required.
Redirects on nqr.io do not use cookies.
8. Who we share data with
We do not sell personal data. We share it only with service providers who help us run NodQR (our sub-processors), when the law requires it, or if our business is sold or restructured (in which case the new owner would be bound by this policy).
We use trusted providers for:
- Hosting and database: storing account and link data, sign-in and file storage. Our database is hosted in London, UK.
- Network and redirects: delivering the website and handling nqr.io redirects quickly and securely.
- Email delivery: sending sign-in emails, invitations and account notices.
- Payments: processing subscription payments. We never see or store full card details.
A current list of our providers is available on request from privacy@nodqr.com. We may add or change providers from time to time, and we only use providers who protect personal data to the standard the law requires.
9. International transfers
Some of our providers are based outside the UK or may access data from outside the UK. Where personal data is transferred outside the UK, we make sure it is protected, for example by relying on UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework, where a provider is certified) or the UK International Data Transfer Agreement or Addendum. You can ask us for details.
10. Keeping data secure
We use appropriate measures to protect personal data, including encryption in transit, hashed passwords and API keys, strict separation between each organisation's data, role-based access within organisations, and not storing the IP addresses of people who scan codes. No system is completely secure, but we will tell you and the ICO if a breach occurs where the law requires it.
11. Your rights
Under UK data protection law you have the right to:
- access the personal data we hold about you;
- correct data that is wrong or incomplete;
- delete your data in certain circumstances;
- restrict or object to how we use your data in certain circumstances, including objecting to direct marketing at any time;
- data portability: receive data you gave us in a common format; and
- withdraw consent where we rely on it.
To use any of these rights, email privacy@nodqr.com. We will respond within one month. You can update most account details yourself in the app.
If your request is about scan data, we will usually pass it to the customer who created the link, as they control that data, and help them respond.
Because we do not store IP addresses and scan identifiers change daily, we are usually unable to identify which scans belong to a particular person.
12. Complaints
If you are unhappy with how we have handled your data, please contact us first at privacy@nodqr.com. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113.
13. Children
NodQR is not intended for children. You must be 18 or over to create an account, and we do not knowingly collect children's data through accounts.
14. Changes to this policy
We may update this policy from time to time. If we make significant changes, we will tell customers by email or in the app. The current version will always be available at nodqr.com/privacy.