Privacy Policy
Last updated: 18 June 2026
DropQR ("we", "us") operates the QR redirect service at drop-qr.com.au. We are privacy-first by design: we collect the minimum data needed to run the service and we never sell it.
This is a plain-language summary and not legal advice — have it reviewed by a lawyer before relying on it.
Two kinds of people, two kinds of data
DJs (account holders)
- Email address — to create and secure your account.
- Payment details — handled entirely by Stripe. We never see or store your card number.
- Your codes and destinations — the link names and URLs you create.
People who scan a code
When someone scans a DropQR code we record the absolute minimum to count the scan:
- A scan count per code.
- Coarse country (e.g. "AU"), derived from the IP address and then the IP is immediately discarded — we do not store IP addresses.
- Device type (mobile / tablet / desktop).
We do not use cookies on scans, do not fingerprint devices, and do not track individuals across sites. Scanning a code does not identify you.
Legal basis for processing
For EU/EEA residents, our legal bases under the GDPR are:
- Contract — processing your account data (email, codes, destinations) is necessary to deliver the service you signed up for.
- Legitimate interests — aggregate scan analytics (country, device type) help account holders understand their audience; we balance this against privacy by discarding IP addresses immediately and not identifying individuals.
- Legal obligation — we may retain certain billing records as required by applicable law.
How long we keep it
Raw scan records (country + device type) are automatically deleted after 90 days. Only aggregate counts are kept beyond that. Account data (email, codes, destinations) is retained for as long as your account is active and for up to 30 days after deletion to allow recovery; after that it is permanently purged. Billing records are kept for 7 years as required by Australian tax law.
Who processes data for us
- Vercel — hosting (servers in the US and globally via CDN).
- Supabase — database and authentication (US-based).
- Stripe — payments (US-based).
International data transfers
Our service is operated from Australia, but our infrastructure providers (Vercel, Supabase, Stripe) are based in the United States. If you are in the EU/EEA, your personal data may therefore be transferred outside the EEA. These providers rely on standard contractual clauses approved by the European Commission, or equivalent safeguards, to legitimise such transfers. You can request a copy of the relevant transfer mechanism by contacting us via the Instagram handle below.
Your rights
Depending on where you live, you may have the following rights over your personal data:
- Access — receive a copy of the data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — ask us to delete your account and associated data.
- Portability — receive your account data in a structured, machine-readable format.
- Restriction — ask us to pause processing your data while a dispute is resolved.
- Objection — object to processing based on legitimate interests.
To exercise any of these rights, message us on Instagram at @dropqr_au. We will respond within 30 days. We do not sell personal data to anyone. EU/EEA residents also have the right to lodge a complaint with their local data protection authority (e.g. the Irish DPC, the CNIL, or the ICO in the UK) if they believe we have mishandled their data.