100% Client-Side Engine
All QR matrix calculations, SVG rendering, and styling execute directly in your browser sandbox.
Zero Payload Storage
We never store, intercept, inspect, or sell your Wi-Fi passwords, contact details, URLs, or text.
Local Preferences Only
Browser localStorage is used solely on your device to remember your active UI theme and color presets.
GDPR & CCPA Aligned
Complete respect for global privacy standards with zero behavioral profiling and zero data broker sharing.
1. Identification of Data Controller & Scope
At GenerateCustomQR (accessible via generatecustomqr.com), we believe privacy is a fundamental human right, not an optional luxury. The internet has become oversaturated with tools that require intrusive user registrations, sneakily redirect your links through dynamic tracking servers, or monetize your confidential data.
We built GenerateCustomQR on a strict Zero-Knowledge Architecture. Our platform operates as a client-side graphic synthesis engine. When you create a QR code on our site, your data is converted into mathematical matrix points directly inside your web browser's volatile memory. What you type, upload, or generate remains strictly yours.
Privacy-First & Zero-Knowledge Architecture: For the purposes of the General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and global privacy legislation, the Data Controller responsible for the operation of this platform and the limited technical telemetry described herein is GenerateCustomQR Media & Software Technologies. You may contact our designated Data Protection desk at legal@generatecustomqr.com.
2. Zero-Knowledge Payload Guarantee (What We Never Collect)
We deliberately engineered our application so that sensitive user payloads never touch our backend databases or persistent storage servers. Specifically:
- Wi-Fi Network Credentials: When you generate a Wi-Fi QR code, your network SSID, WPA/WPA2/WPA3 password, and encryption type are processed locally. We have zero ability to view or store your home or corporate passwords.
- vCard & Contact Details: Personal names, phone numbers, email addresses, company titles, and physical street addresses remain entirely on your device.
- Confidential Messages & Plain Text: Any plain text, SMS messages, or email body copy you input is encoded directly into binary QR modules without transit logging.
- Custom Brand Logos & Images: When you upload a logo to embed in the center of your QR code, the image file is handled via browser memory Object URLs (Blob) or temporary client-side canvas buffers. It is never uploaded to cloud storage.
- Scan Tracking & Location Interception: We generate static QR codes according to ISO/IEC 18004 standards. We do not insert intermediary tracking redirects (e.g., short-URLs) that spy on your users' GPS locations, IP addresses, or scan times.
3. Technical Telemetry We Collect & Why
To ensure fast page delivery, mitigate automated DDoS attacks, and diagnose infrastructure health, our hosting network and edge CDN collect minimal, non-identifying technical telemetry:
- Infrastructure Edge Logs: Standard HTTP server headers (such as requesting IP address, user-agent string, referrer URL, and timestamp) are processed transiently by edge networks (e.g. Cloudflare) to prevent brute-force attacks and bot abuse. These logs are automatically rotated and purged within 30 days.
- Aggregated Anonymous Analytics: We utilize privacy-configured Google Analytics 4 to monitor platform stability, page load latencies, and macro-level usage trends (e.g., popular dot styles). IP anonymization is permanently enabled, advertising features and user-id cross-device tracking are disabled, and data is stored only in aggregate form.
4. Data Processing & Storage Matrix
For complete transparency, the following matrix outlines every category of data associated with our service:
| Data Category | Specific Elements | Legitimate Purpose | Storage Location | Retention Period |
|---|---|---|---|---|
| User QR Payloads | URLs, Wi-Fi keys, vCard info, Text, Email, SMS | 2D Barcode rasterization | Browser Memory (Client-Side) | Purged immediately when tab closes |
| Uploaded Logo Images | PNG, JPG, SVG, WebP graphic assets | Center emblem canvas compositing | Client Browser Memory / Blob URL | Purged when session ends |
| Studio UI Preferences | Theme (dark/light), selected colors, dot preset ID | User convenience & design persistence | Local Device (localStorage) | Until cleared by user |
| Infrastructure Logs | Anonymized IP, User-Agent, HTTP Status Code | DDoS mitigation & edge security | Edge CDN Security Buffers | 14 to 30 days (Auto-purged) |
| Usage Telemetry | Page views, country-level aggregate visits | Platform performance optimization | Google Analytics 4 (Anonymized) | 14 months (Standard aggregate) |
5. Local Browser Storage (localStorage)
GenerateCustomQR does not use persistent tracking cookies or invasive device fingerprinting. We utilize standard Web Storage (localStorage) solely to enhance your design workflow:
- Theme Preference: Remembers whether you prefer Dark Mode or Light Mode across visits.
- Custom Palette Presets: Saves your customized foreground, background, and gradient color codes so you don't have to re-enter hex codes every time.
- Last Selected Configuration: Preserves your chosen dot shapes, eye frame geometries, and error correction settings for quick iteration.
You can clear all saved studio preferences at any time by opening your browser's Developer Tools (F12) > Application > Local Storage > Clear All, or by clicking the 'Reset' button in the Studio toolbar.
6. Third-Party Service Providers & Subprocessors
We rely on reputable infrastructure partners to deliver high-performance static web pages. Each provider complies with strict data protection standards:
- Cloudflare, Inc.: Global CDN delivery, DNS routing, and DDoS / WAF bot defense. (Privacy Policy)
- Google Analytics (Google LLC): Anonymized web traffic metrics with IP masking and disabled ad profiling. (Privacy Policy)
- Google Fonts: Optimized web font stylesheets for modern typography rendering. (Privacy Policy)
7. Cross-Border & International Data Transfers
Because our platform utilizes global Content Delivery Networks (CDNs) and anonymized analytics infrastructure, minimal technical telemetry (such as masked IP addresses) may be routed through or processed on servers situated in the United States and other jurisdictions outside the European Economic Area (EEA) and the United Kingdom:
- EU-U.S. Data Privacy Framework (DPF) & UK Extension: Our primary infrastructure service providers (Cloudflare, Inc. and Google LLC) are certified under the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF as administered by the U.S. Department of Commerce.
- Standard Contractual Clauses (SCCs): Where transfers are not covered by an adequacy decision or DPF certification, cross-border data flows are safeguarded by European Commission approved Standard Contractual Clauses (SCCs) providing enforceable data subject rights and effective legal remedies.
8. Do Not Track (DNT) & Global Privacy Control (GPC) Signals
Under California law (CalOPPA / CPRA) and global privacy conventions, websites must disclose how they respond to browser 'Do Not Track' (DNT) and Global Privacy Control (GPC) signals. Because GenerateCustomQR operates on a strict Zero-Knowledge model—we never track users across third-party websites, never create behavioral profiling databases, and never sell personal data—our platform inherently honors the spirit and protections of DNT and GPC signals by default.
9. European Privacy Rights (GDPR & UK GDPR)
For individuals residing in the European Economic Area (EEA) and the United Kingdom, our data handling complies strictly with Regulation (EU) 2016/679 (GDPR) and the UK Data Protection Act 2018:
- Legal Bases for Processing: Our processing of transient edge logs relies on Art. 6(1)(f) GDPR (Legitimate Interests in maintaining website security, uptime, and fraud defense).
- Right to Access & Rectification (Articles 15 & 16): Because we do not maintain user accounts or personal profiles, we do not store searchable databases of your personal data.
- Right to Erasure & Forgottenness (Article 17): No personal records exist on our servers. You hold total sovereignty over your local data by clearing your browser cache.
- Right to Restrict & Object to Processing (Articles 18 & 21): You may disable local storage and block script telemetry at any time via browser settings or content blockers without losing core QR generator functionality.
10. California Privacy Notice (CCPA / CPRA)
Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), California residents are entitled to specific disclosures:
- No Sale or Sharing of Personal Information: GenerateCustomQR has never sold, rented, or traded personal information to data brokers or advertising exchanges, and we will never do so in the future.
- No Profiling or Cross-Context Behavioral Ads: We do not track you across third-party websites or construct consumer profiles for targeted advertising.
- Non-Discrimination: We provide identical, 100% free QR generation capabilities to all users regardless of whether they exercise their privacy rights.
11. Brazilian Privacy Rights (LGPD)
In accordance with Brazil's Lei Geral de Proteção de Dados (LGPD - Law No. 13.709/2018), users located in Brazil enjoy complete autonomy over their data. Because GenerateCustomQR executes QR synthesis locally on your device without transmitting personal data to remote databases, your personal data is safeguarded by default.
12. Children's Privacy Protection (COPPA & Global Standards)
Our service is not directed to children under 13 years of age (or under 16 in the European Union). We do not knowingly solicit, collect, or retain personal data from children. Because GenerateCustomQR does not require account creation or email verification, no child's personal identity is ever requested or stored.
13. Data Security & 72-Hour Breach Notification Protocol
We implement defense-in-depth technical measures and maintaining comprehensive incident response procedures:
- End-to-End TLS 1.3 Encryption: All traffic between your browser and our edge servers is encrypted using modern TLS 1.3 protocols with Perfect Forward Secrecy.
- Strict Content Security Policy (CSP): We enforce robust CSP headers to prevent Cross-Site Scripting (XSS), data injection, and malicious third-party script execution.
- 72-Hour Security Incident Protocol: In the unlikely event of a security incident affecting our edge infrastructure providers that compromises transient technical server logs, we maintain procedures to notify relevant data protection supervisory authorities within 72 hours in full compliance with Article 33 of the GDPR and applicable global breach notification standards.
14. Business Transfers & Corporate Transactions
If GenerateCustomQR or substantially all of its assets are acquired, merged, or transferred to another legal entity in the course of a corporate restructuring or asset sale, the limited technical telemetry and server logs described in this policy would be included among the transferred assets. Any acquiring entity will remain bound by the provisions of this Privacy Policy, and our foundational Zero-Knowledge architecture commitment shall remain fully binding on any successor.
15. External Links & Third-Party Websites Disclaimer
Our website, technical documentation, and blog articles may contain links to external websites, software tools, and technical resources that are not owned or operated by GenerateCustomQR. We exercise no control over, and assume no responsibility for, the content, privacy practices, or data collection policies of any third-party websites. We encourage you to read the privacy policy of any external website you visit.
16. Policy Revisions & Legal Inquiries
We may update this Privacy Policy periodically to reflect technological advancements, regulatory changes, or platform enhancements. When modifications occur, the 'Last Updated' timestamp at the top of this page will be revised. For any privacy inquiries, legal notifications, or data protection questions, please reach out to our legal desk at legal@generatecustomqr.com or via our Contact Page at /contact.
Frequently Asked Privacy Questions
Who is the legal Data Controller for GenerateCustomQR?expand_more
GenerateCustomQR Media & Software Technologies acts as the legal Data Controller for the platform. For legal inquiries or regulatory questions, contact legal@generatecustomqr.com.
Can GenerateCustomQR or third parties see what I encode into my QR codes?expand_more
No. All QR code generation is executed client-side directly in your browser's memory. Your URLs, text, passwords, or vCard details never touch our backend databases.
Do you store the custom logos or images I upload?expand_more
No. When you upload a custom logo, it is loaded into your browser's temporary memory (Blob URL) and drawn directly onto the canvas. The file is never sent to our servers or saved in cloud storage.
Does GenerateCustomQR track when or where people scan my QR codes?expand_more
No. We generate static QR codes that directly encode your destination payload. There are no intermediary redirect servers or tracking pixels, so scan events are completely private.
How does GenerateCustomQR handle international data transfers?expand_more
All QR generation runs on your device. Edge telemetry is routed through certified US infrastructure providers under the EU-U.S. Data Privacy Framework (DPF) and Standard Contractual Clauses (SCCs).
Is GenerateCustomQR compliant with GDPR, CCPA, and global privacy standards?expand_more
Yes. By operating on a Zero-Knowledge, client-side model, we ensure zero PII collection, zero data sales, and full compliance with European GDPR, California CCPA/CPRA, and Brazilian LGPD regulations.
Have Questions About Our Privacy Architecture?
We believe in total transparency. If you need technical verification or have questions regarding data security, our legal team is here to assist.
contact_supportContact Privacy Team