Privacy Policy

Last updated 8 October 2026. Steadfast QR is run by Firstname Lastname, 1 Example Street, London, AB1 2CD, United Kingdom. Contact: hello@example.com.

This explains what personal data Steadfast QR collects, why, and your rights. Firstname Lastname is the controller of this data under UK data protection law (UK GDPR and the Data Protection Act 2018).

People who scan a code

When someone scans a code, we record only the time and the type of device (phone, tablet or computer), worked out from the browser's "user agent" and then discarded. We do not store their IP address, location, or anything that identifies them, and we don't use cookies or trackers on scan or menu pages. Website owners see only these anonymous counts.

Account holders: what we collect

DataWhyLegal basis
Email address and password (stored only as a secure one-way hash)To run your account, log you in and send password-reset emailsContract
Your codes, links, uploaded menus, logo and brand coloursTo provide the serviceContract
Subscription status and Stripe customer IDTo give you Pro features and manage billingContract
IP address and email for failed log-ins, sign-ups and reset requests (see retention below)To stop password guessing and abuseLegitimate interests (security)
A login cookieTo keep you signed in. It's strictly necessary, so it doesn't need consent. We use no advertising or analytics cookies.Legitimate interests

Card details go directly to Stripe; we never see or store them. Photos you upload have their location (GPS) data removed.

Who we share it with

Our server is in the United Kingdom. Stripe and Google may process data outside the UK under the UK's approved safeguards. We never sell your data or use it for advertising.

How long we keep it

Your rights

You can ask to see, correct, delete or receive a copy of your personal data, and you can object to or ask us to restrict how we use it. Email hello@example.com; we'll reply within one month. If you're unhappy with how we've handled your data, you can complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113).

Security

Everything is served over HTTPS. Passwords are hashed with scrypt, password-reset links work once and expire after an hour, log-in attempts are rate-limited, and backups are encrypted.

Changes

If we change this policy in a way that matters, we'll email account holders before it takes effect.