Privacy Policy
Effective August 3, 2026
1. Who we are
QR DNA (qrdna.io) is operated by Chase Conching. This policy explains what we collect, why, and what your options are. It covers two kinds of people: users who create codes and cards with an account, and people who scan a code or view a business card that a user published. Both are covered below, because the Service collects different things from each.
2. What we collect from account holders
Account information
Your email address and login credentials, managed through our authentication provider, Supabase. Passwords are stored hashed — we never see them in plain text.
Content you create
The QR codes you save, their styling, the destinations you configure, your projects, and anything you put on a digital business card — name, role, contact details, links, and photo. Note that business card pages are public by design: anyone with the link or the code can view the card and download the contact file.
Generating without an account
Static codes are generated in your browser. If you use the generator without signing in, the content of your code isn't saved on our servers.
3. What we collect when someone scans a code
When someone scans a dynamic code (or views a business card), we record a scan event so the code's owner can see how their code performs. A scan event contains:
- date and time of the scan;
- IP address;
- approximate location — country, region, and city — derived from the IP address by our hosting provider (never GPS; the scanning device's precise location is not accessed);
- device type, operating system, and browser, derived from the browser's user-agent string;
- the referring page, when the browser provides one.
Scan events are not linked to any account or identity of the person scanning — we don't know who scanned, only that a scan happened and roughly where and on what kind of device. Static codes never touch our servers when scanned, so scanning one sends us nothing.
4. How we use this information
- to operate the Service: accounts, redirects, hosted cards;
- to show code owners their analytics — scan counts, trends, device and location breakdowns;
- to prevent abuse of the redirect service;
- to communicate with you about your account or material changes to the Service.
We do not sell personal information, we don't run advertising or advertising trackers, and we don't use your content or scan data for marketing profiles.
5. Cookies and local storage
We use cookies only to keep you signed in (authentication session cookies set by Supabase). Your theme preference (light or dark) is kept in your browser's local storage. There are no third-party advertising or analytics cookies.
6. Who we share data with
We share data only with the infrastructure providers that run the Service, and only to the extent needed to run it:
- Supabase — database and authentication; stores account data, content, and scan events;
- Vercel — application hosting and content delivery; processes requests (including scans) and derives the approximate location used in analytics;
- Stripe — payment processing, if and when paid plans are offered. Card details would go directly to Stripe and never touch our servers. While the Service is free, no payment data is collected at all.
Beyond that, we disclose data only if required by law, or to protect the Service and its users from abuse.
7. Retention
Account data and content are kept for as long as your account exists. Scan events are kept so long as the code they belong to exists, to power its analytics history. Deleting a code deletes its scan events; deleting your account deletes your codes, cards, and their analytics.
8. Your rights
You can access and edit your content and account details from the dashboard and settings at any time. You can also ask us to export, correct, or delete the personal data we hold about you — email chase@chase.is and we'll respond within 30 days. If you scanned someone's code and have questions about a scan event, the same address works; include roughly when and where the scan happened so we can locate it.
9. Security
Data is encrypted in transit (TLS) and at rest by our providers. Access to production data is limited to the operator. Database access is governed by row-level security, so one account's data isn't readable by another's. No system is perfectly secure, but if a breach affects your personal data we'll notify you as required by law.
10. Children
The Service isn't directed at children under 13, and we don't knowingly collect personal information from them. If you believe a child has created an account, contact us and we'll delete it.
11. Changes to this policy
If this policy changes, we'll update the effective date above, and for material changes we'll make reasonable efforts to notify account holders by email before the change takes effect.
12. Contact
Privacy questions: chase@chase.is. For the rules that govern using the Service, see the terms of use.