Privacy Policy
Last updated: July 2026
1. Who we are
QrLinkWave ("we", "us", "our") operates qrlinkwave.com and its products, QrWave and SocialWave. This policy explains what information we collect, why, and how you can control it.
2. What we collect
- Account data: your email address, and — if you set them — a display name and avatar.
- Content you create: QR code destinations, OneLink routing rules, and bio-page content (links, theme, bio text).
- Scan & visit data: for dynamic QR codes and bio pages, we log scan/view counts. On paid plans, this includes a hashed visitor identifier (SHA-256 of IP address + device/browser signature) used to distinguish unique visitors from repeat scans — we never store your raw IP address alongside this hash.
- Payment data: if you subscribe to a paid plan, payments are processed by Razorpay. We store the subscription status, plan, and transaction reference — never your card or bank details, which Razorpay handles directly.
- Technical data: standard web server logs (timestamps, error logs) kept only as long as needed for security and debugging.
3. How we use it
- To operate your account, dashboard, and the QR/bio-page redirect service itself.
- To send transactional email — magic-link sign-in, receipts, and service notices. We don't send marketing email unless you opt in separately.
- To enforce plan limits and gate features that require an active subscription.
- To detect abuse and keep the redirect service reliable.
4. What we don't do
We don't sell your data. We don't share bio-page or QR destination content with third parties except the infrastructure providers needed to run the service (hosting, email delivery, payment processing), each bound to protect your data under their own terms.
5. Your controls
- You can edit or delete any QR code, OneLink, or bio page from your dashboard at any time.
- You can request account deletion by emailing info@qrlinkwave.com — we'll remove your account data, including associated codes and pages, within a reasonable timeframe.
- You can sign out of every device at once by requesting a new magic link, which invalidates prior sessions tied to the old token.
6. Cookies
We use one essential, httpOnly session cookie to keep you signed in. We don't use third-party advertising or tracking cookies.
7. Changes to this policy
If this policy changes materially, we'll update the date at the top of this page and, where appropriate, notify account holders by email.
8. Contact
Questions about this policy or your data: info@qrlinkwave.com.