Privacy Policy
Last updated 8 October 2026. Steadfast QR is run by Firstname Lastname, 1 Example Street, London, AB1 2CD, United Kingdom. Contact: hello@example.com.
This explains what personal data Steadfast QR collects, why, and your rights. Firstname Lastname is the controller of this data under UK data protection law (UK GDPR and the Data Protection Act 2018).
People who scan a code
When someone scans a code, we record only the time and the type of device (phone, tablet or computer), worked out from the browser's "user agent" and then discarded. We do not store their IP address, location, or anything that identifies them, and we don't use cookies or trackers on scan or menu pages. Website owners see only these anonymous counts.
Account holders: what we collect
| Data | Why | Legal basis |
|---|---|---|
| Email address and password (stored only as a secure one-way hash) | To run your account, log you in and send password-reset emails | Contract |
| Your codes, links, uploaded menus, logo and brand colours | To provide the service | Contract |
| Subscription status and Stripe customer ID | To give you Pro features and manage billing | Contract |
| IP address and email for failed log-ins, sign-ups and reset requests (see retention below) | To stop password guessing and abuse | Legitimate interests (security) |
| A login cookie | To keep you signed in. It's strictly necessary, so it doesn't need consent. We use no advertising or analytics cookies. | Legitimate interests |
Card details go directly to Stripe; we never see or store them. Photos you upload have their location (GPS) data removed.
Who we share it with
- Stripe, our payment processor, receives your email, billing address and card details when you subscribe. See Stripe's privacy policy at stripe.com/privacy.
- Google (Gmail) delivers the emails we send you, such as password resets.
- MEGA stores our off-site backups. They're encrypted before they leave our server, so MEGA can't read them.
- Our cloud storage provider holds the append-only security-log archive described below.
Our server is in the United Kingdom. Stripe and Google may process data outside the UK under the UK's approved safeguards. We never sell your data or use it for advertising.
How long we keep it
- Account data: until you delete your account. You can do that yourself at any time on the Account page; it removes your codes, menus, logo and stats immediately.
- Encrypted backups: up to 6 months, after which they're automatically overwritten.
- Security records: failed log-in, sign-up and reset attempts (with the IP address) are kept for 24 hours in our database for rate-limiting. The IP addresses of failed log-ins also appear in our server's security logs, kept for 1 month on the server and up to 12 months in an append-only security archive used to investigate attacks.
- Payment records: Stripe keeps these as long as the law requires (generally 6 years for UK tax).
Your rights
You can ask to see, correct, delete or receive a copy of your personal data, and you can object to or ask us to restrict how we use it. Email hello@example.com; we'll reply within one month. If you're unhappy with how we've handled your data, you can complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113).
Security
Everything is served over HTTPS. Passwords are hashed with scrypt, password-reset links work once and expire after an hour, log-in attempts are rate-limited, and backups are encrypted.
Changes
If we change this policy in a way that matters, we'll email account holders before it takes effect.