Privacy Policy
Last Updated: August 19, 2026 • Effective Immediately
1. Overview & Purpose
Tap2QR ("we," "our," or "us") provides dynamic QR code generation, customized visual branding, and scan analytics tools for merchants and business owners integrated via website applications (including Wix App Market and upcoming e-commerce platforms).
This Privacy Policy explains how we collect, use, store, and protect information when you install our application on your site or when end-users scan a QR code powered by Tap2QR.
2. Information We Collect
A. Merchant & App Account Information
When a merchant installs Tap2QR through an app store (e.g. Wix App Market), we receive platform-provided authentication metadata required to establish the merchant session:
- App Instance Identifier (
instanceId) - Site ID, store URL, and display site name
- Merchant contact email address (as provided by the host platform)
- App subscription status and billing tier metadata
B. QR Code Campaign Configurations
We store data explicitly configured by merchants within the Tap2QR dashboard to generate functional QR codes:
- Destination URLs, redirect targets, and custom plain text payloads
- Contact business card fields (vCard 3.0: name, phone, email, organization, job title)
- WhatsApp phone numbers and optional pre-filled greeting text
- Visual styling parameters (dot patterns, corner frame styles, custom brand colors, uploaded logo image URLs)
C. End-User Scan Analytics Data (Cookie-less & Privacy-First)
When an end-user scans a Dynamic QR Code generated by Tap2QR, our redirect edge server processes minimal technical HTTP headers to provide campaign analytics:
- Timestamp of scan event
- Device category (Mobile vs. Desktop) and Operating System (iOS, Android, Windows, macOS)
- Web browser type (Safari, Chrome, Firefox, etc.)
- Approximate location derived from coarse IP data (country/city level)
- HTTP Referrer header (if provided by scanner device)
3. How We Use Collected Information
We process collected data exclusively for the following operational purposes:
- Dynamic Redirection Service: Resolving short QR code identifiers to merchant-specified target destination URLs or vCard downloads.
- Analytics Reporting: Presenting aggregated scan metrics, device breakdowns, and daily performance charts to merchants in their secure dashboard.
- Customer Support: Responding to merchant inquiries, support tickets, and service notification requests.
- Subscription & Billing Management: Syncing subscription status and plan tiers with the host app store.
4. Data Sharing & Third-Party Service Providers
We do not sell, rent, trade, or monetize merchant data or end-user scan data to third-party advertising networks or data brokers.
Data is processed strictly through essential infrastructure partners required to operate the service:
- Host E-Commerce Platforms (e.g., Wix): Synchronizing OAuth session validation, instance status, and app store webhooks.
- Database & Hosting Infrastructure: Encrypted PostgreSQL database storage hosted on secure cloud providers.
- Support Webhooks: Transmitting support ticket form inquiries submitted by merchants to internal operational notification webhooks (e.g. Discord).
5. Data Retention & Security
We implement industry-standard administrative, physical, and technical safeguards to protect your information against unauthorized access, loss, or alteration:
- All HTTP data transmissions are encrypted using Transport Layer Security (TLS 1.2+ / SSL).
- Database connections enforce SSL encryption and restricted network access controls.
- If a merchant uninstalls the application, session records and associated QR codes are removed in accordance with platform uninstall lifecycle webhooks.
6. Your Data Rights (GDPR & CCPA Compliance)
Depending on your jurisdiction, merchants and end-users may possess rights under applicable data protection laws (such as GDPR or CCPA):
- Right to Access: Request a copy of stored merchant account metadata.
- Right to Rectification: Edit or update QR code targets and merchant contact info directly within the dashboard.
- Right to Erasure ("Right to be Forgotten"): Request full deletion of your account and associated scan log history upon app uninstallation.
7. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements or platform features. The revised policy will be posted on this page with an updated "Last Updated" timestamp.
8. Contact Us
If you have any questions or data privacy requests regarding this Privacy Policy, please contact our support team: