Privacy Policy
What QRLynx collects, why it is used, who processes it, and the choices available to you.
Last updated: September 8, 2026
Jorbox LLC, located at 1209 Mountain Road Pl NE, Ste N, Albuquerque, New Mexico 87110, United States, operates QRLynx. This policy explains how QRLynx handles personal information when you visit qrlynx.com, create or manage an account, use QRLynx QR features, scan a QRLynx dynamic code, submit a QRLynx-hosted form, or contact support.
Who this policy covers
This policy covers QRLynx account holders, team members, public-site visitors, Figma plugin users, QR scanners, lead-form submitters, and support contacts. A QRLynx customer controls the content and purpose of their QR campaigns. When a customer uses a QRLynx Lead Form or another hosted collection feature, that customer is responsible for the notice, legal basis, and choices offered to the people whose information they collect. QRLynx processes that customer-directed data to provide the service.
Information QRLynx collects
Account and authentication information
QRLynx stores details such as your email address, name, avatar, chosen sign-in method, provider identifier, verification state, account status, country, device type, signup and recent login IP addresses, and account timestamps. Optional profile fields can include company, website, address, phone, job title, city, and country. OAuth sign-in can provide basic profile details from Google, Microsoft, LinkedIn, or Apple. QRLynx's current OAuth scopes do not request access to Google Drive or Microsoft OneDrive. Email magic-link sign-in provides the email address used for the request.
Billing information
Stripe processes card and payment details. QRLynx stores subscription and transaction references, plan and billing status, billing interval, and limited payment-method details needed to show and support the subscription. QRLynx does not store the full card number.
QR content, files, and workspace data
QRLynx stores the QR content and settings you submit, including destinations, designs, rules, custom domains, uploaded images or documents, folders, team membership, audit activity, and feature configurations. API credentials are stored as one-way hashes after the secret is issued. Some hosted QR experiences can contain contact, business-card, menu, catalog, or consent content supplied by the account holder.
Figma plugin data
When you authorize QR Code Generator by QRLynx in Figma, QRLynx uses Figma's current_user:read permission to confirm your identity. The backend converts the Figma user identifier into a keyed hash and stores that pseudonymous identifier to keep your plugin workspace separate from other users. This sign-in flow does not store the raw Figma identifier or Figma access and refresh tokens, import your Figma email address, or receive your Figma password.
The plugin does not upload existing Figma files, layers, selections, or design contents to QRLynx. The QR destinations and design settings you enter in the plugin are sent to QRLynx to create and manage your codes. QRLynx stores this QR data and the plugin's workspace and session records using Cloudflare. Dynamic QR scans are processed as described under Scan and usage data.
The plugin saves a QRLynx session token in Figma's local plugin storage to keep you signed in. It also attaches a QRLynx code identifier to inserted QR artwork so that the artwork can be associated with its saved code. QRLynx plugin sessions expire after 30 days; session expiry does not delete your QR codes or workspace records.
Connecting an existing QRLynx account is optional and requires account sign-in and consent. Disconnecting that account removes the plugin's connection to it; it does not delete the account or its QR codes. For access or deletion requests, including a plugin workspace without a linked QRLynx account, contact support@qrlynx.com and mention that you use the Figma plugin. We will verify your connection to the workspace before acting. The retention and deletion provisions below also apply.
Google Workspace data
The QRLynx Google Slides add-on uses Google authorization to identify the editor and insert requested QR codes into the current presentation. QRLynx does not read, store, or transfer existing slide content, files, or designs.
QRLynx handles Google API data under the Google API Services User Data Policy, including its Limited Use requirements. Google Workspace data is not shared with AI services or used to train AI models. QRLynx AI Insights is separate and does not receive Google Workspace data.
Scan and usage data
When a dynamic QRLynx code is scanned, QRLynx processes the scan time, QR identifier, referring page when available, device category, browser, operating system, country, region, city, and approximate location signals available from the edge network. The request IP address and user agent are used transiently for bot filtering, device parsing, security, rate limiting, and daily unique-visitor detection. The daily unique-visitor key expires after about 24 hours. Long-lived scan analytics do not store the request IP address or raw user agent.
QRLynx also records product interactions, page routes, device type, performance timings, expected errors, security events, and operational logs needed to run and improve the service.
Forms, contacts, and communications
A customer-created Lead Form can collect the fields selected by that customer, such as name, email, phone, company, job title, or website, along with an IP address used for abuse controls. Contact and support requests contain the name, email, message, and any material you choose to send. Email delivery records can include recipient, template, status, provider identifiers, and short-lived message content.
Why QRLynx uses this information
QRLynx uses personal information to provide accounts, workspaces, QR creation, redirects, hosted content, analytics, billing, support, email delivery, security, fraud prevention, abuse response, service monitoring, and legal compliance. It is also used to remember preferences, enforce plan and feature limits, troubleshoot incidents, and improve product reliability.
Where European data-protection law applies, the legal basis depends on the activity. QRLynx relies on performance of a contract to provide the service, legitimate interests to secure and improve it, consent for optional tags or communications when consent is required, and legal obligations for records that must be retained. You can withdraw consent for future processing where an activity relies on consent.
Service providers and disclosures
QRLynx does not sell personal information. Microsoft Advertising and Meta Pixel are currently enabled for conversion and remarketing measurement. For visitors in the EU, EEA, and UK, these tags do not load unless the visitor accepts optional tags.
QRLynx uses service providers for defined operational purposes:
- Cloudflare provides application hosting, edge delivery, redirects, databases, object storage, queues, analytics infrastructure, bot protection, and AI processing. QRLynx AI Insights sends structured analytical output for language polishing, not raw scan rows.
- Stripe processes payments, subscriptions, invoices, fraud signals, and billing support.
- Microsoft Azure Communication Services delivers account, support, and lifecycle email.
- Google, Microsoft, LinkedIn, and Apple provide OAuth sign-in when you select one of those options.
- Figma provides identity authorization when you connect the QRLynx Figma plugin.
- Microsoft Advertising and Meta process page-view and conversion-event data for conversion and remarketing measurement when their tags are enabled and the applicable consent controls allow them to load.
- Google Web Risk can receive a destination URL for a safety check when QRLynx verifies an external URL.
- Telegram carries restricted internal operational alerts that can include the account or billing details needed to investigate an event.
- Apple Wallet and Google Wallet receive pass data only when an eligible Digital Business Card user asks to create a wallet pass.
QRLynx may also disclose information when required by law, to respond to valid legal process, to protect users or the service, to investigate abuse, or as part of a merger, financing, acquisition, or sale of assets with appropriate notice and safeguards.
Retention and deletion
| Data | Current retention approach |
|---|---|
| Account, profile, QR content, files, and workspace records | Kept while the account or workspace needs them. The account-deletion workflow removes primary user-owned records, sessions, QR files, and analytics ownership records, subject to the exceptions below. |
| Product interaction events | Normally removed after 30 days. |
| Lead Form submissions | Normally removed 90 days after submission. |
| Daily unique-scan key | Expires after about 24 hours. |
| Detailed scan analytics and rollups | Reporting access depends on the account plan and available campaign history. QRLynx keeps recent event detail and longer-lived aggregate reporting data for the applicable reporting window. Account deletion starts dedicated analytics deletion and retry controls. |
| Email records | Message bodies are normally removed after 3 days. Limited delivery and suppression records can remain longer for deliverability, safety, and communication preferences. |
| Billing and legal records | Kept as required for payment processing, accounting, fraud prevention, disputes, and applicable law. Stripe applies its own retention duties. |
| Security, audit, and recovery records | Kept only as long as reasonably needed for security, incident response, legal claims, workspace accountability, and recovery. Deleted data can remain temporarily in access-controlled provider backups. Dedicated analytics backup generations are designed not to exceed 90 days. |
You can request account deletion from account settings. An active paid subscription must be cancelled before the account can be deleted. Primary account data is removed through the deletion workflow. Some provider backups, security records, billing records, unresolved incident records, or data required by law can remain until their applicable retention period ends.
Your privacy rights and choices
Depending on where you live, you may have rights to know or access personal information, correct it, delete it, restrict or object to certain processing, receive portable data, withdraw consent, or appeal a decision. You may also have the right to complain to a privacy or data-protection authority. QRLynx will verify the requester before acting and can retain information when a legal exception applies.
To make a privacy request, email support@qrlynx.com from the account address or use the QRLynx contact page. Account holders can also update profile information, manage email preferences, export available account data, and request deletion from account settings.
Cookies and tracking choices
The QRLynx Cookie Policy lists the current first-party cookies, browser storage, consent behavior, and optional tags. Microsoft Advertising and Meta Pixel are currently enabled for conversion and remarketing measurement. Microsoft Clarity and Google Ads are disabled.
Security
QRLynx uses modern TLS in transit, Cloudflare-managed encryption for hosted storage, HttpOnly session cookies, origin checks for account-changing requests, rate limits, bot controls, URL safety checks, scoped API keys, access controls, and operational monitoring. No internet service can guarantee complete security. If you believe a QRLynx account or link is being abused, email abuse@jorbox.com.
International processing
Jorbox LLC is based in the United States, and QRLynx service providers operate in multiple countries. Information can therefore be processed outside your country. QRLynx uses contractual and provider safeguards required for applicable international transfers.
Children
QRLynx is a general-audience business service and is not directed to children under 13. QRLynx does not knowingly collect personal information from a child under 13. A parent or guardian who believes a child provided personal information can contact support@qrlynx.com so the information can be reviewed and removed where appropriate.
Changes to this policy
QRLynx may update this policy when its data practices, providers, product behavior, or legal obligations materially change. The date at the top will reflect a substantive update. Material changes may also be communicated through the service or by email when appropriate.
Contact
Privacy questions and requests can be sent to support@qrlynx.com. Postal correspondence can be sent to Jorbox LLC, 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States.
By Ahmad Tayyem · Last updated: