Skip to content

Privacy Policy

What QRLynx collects, why it is used, who processes it, and the choices available to you.

Last updated: July 29, 2026

Jorbox LLC, located at 1209 Mountain Road Pl NE, Ste N, Albuquerque, New Mexico 87110, United States, operates QRLynx. This policy explains how QRLynx handles personal information when you visit qrlynx.com, create or manage an account, use QRLynx QR features, scan a QRLynx dynamic code, submit a QRLynx-hosted form, or contact support.

Who this policy covers

This policy covers QRLynx account holders, team members, public-site visitors, QR scanners, lead-form submitters, and support contacts. A QRLynx customer controls the content and purpose of their QR campaigns. When a customer uses a QRLynx Lead Form or another hosted collection feature, that customer is responsible for the notice, legal basis, and choices offered to the people whose information they collect. QRLynx processes that customer-directed data to provide the service.

Information QRLynx collects

Account and authentication information

QRLynx stores details such as your email address, name, avatar, chosen sign-in method, provider identifier, verification state, account status, country, device type, signup and recent login IP addresses, and account timestamps. Optional profile fields can include company, website, address, phone, job title, city, and country. OAuth sign-in can provide basic profile details from Google, Microsoft, LinkedIn, or Apple. QRLynx's current OAuth scopes do not request access to Google Drive or Microsoft OneDrive. Email magic-link sign-in provides the email address used for the request.

Billing information

Stripe processes card and payment details. QRLynx stores subscription and transaction references, plan and billing status, billing interval, and limited payment-method details needed to show and support the subscription. QRLynx does not store the full card number.

QR content, files, and workspace data

QRLynx stores the QR content and settings you submit, including destinations, designs, rules, custom domains, uploaded images or documents, folders, team membership, audit activity, and feature configurations. API credentials are stored as one-way hashes after the secret is issued. Some hosted QR experiences can contain contact, business-card, menu, catalog, or consent content supplied by the account holder.

Scan and usage data

When a dynamic QRLynx code is scanned, QRLynx processes the scan time, QR identifier, referring page when available, device category, browser, operating system, country, region, city, and approximate location signals available from the edge network. The request IP address and user agent are used transiently for bot filtering, device parsing, security, rate limiting, and daily unique-visitor detection. The daily unique-visitor key expires after about 24 hours. Long-lived scan analytics do not store the request IP address or raw user agent.

QRLynx also records product interactions, page routes, device type, performance timings, expected errors, security events, and operational logs needed to run and improve the service.

Forms, contacts, and communications

A customer-created Lead Form can collect the fields selected by that customer, such as name, email, phone, company, job title, or website, along with an IP address used for abuse controls. Contact and support requests contain the name, email, message, and any material you choose to send. Email delivery records can include recipient, template, status, provider identifiers, and short-lived message content.

Why QRLynx uses this information

QRLynx uses personal information to provide accounts, workspaces, QR creation, redirects, hosted content, analytics, billing, support, email delivery, security, fraud prevention, abuse response, service monitoring, and legal compliance. It is also used to remember preferences, enforce plan and feature limits, troubleshoot incidents, and improve product reliability.

Where European data-protection law applies, the legal basis depends on the activity. QRLynx relies on performance of a contract to provide the service, legitimate interests to secure and improve it, consent for optional tags or communications when consent is required, and legal obligations for records that must be retained. You can withdraw consent for future processing where an activity relies on consent.

Service providers and disclosures

QRLynx does not sell personal information. QRLynx does not currently share personal information for cross-context behavioral advertising because the supported advertising tags are disabled.

QRLynx uses service providers for defined operational purposes:

  • Cloudflare provides application hosting, edge delivery, redirects, databases, object storage, queues, analytics infrastructure, bot protection, and AI processing. QRLynx AI Insights sends structured analytical output for language polishing, not raw scan rows.
  • Stripe processes payments, subscriptions, invoices, fraud signals, and billing support.
  • Microsoft Azure Communication Services delivers account, support, and lifecycle email.
  • Google, Microsoft, LinkedIn, and Apple provide OAuth sign-in when you select one of those options.
  • Google Web Risk can receive a destination URL for a safety check when QRLynx verifies an external URL.
  • Telegram carries restricted internal operational alerts that can include the account or billing details needed to investigate an event.
  • Apple Wallet and Google Wallet receive pass data only when an eligible Digital Business Card user asks to create a wallet pass.

QRLynx may also disclose information when required by law, to respond to valid legal process, to protect users or the service, to investigate abuse, or as part of a merger, financing, acquisition, or sale of assets with appropriate notice and safeguards.

Retention and deletion

DataCurrent retention approach
Account, profile, QR content, files, and workspace recordsKept while the account or workspace needs them. The account-deletion workflow removes primary user-owned records, sessions, QR files, and analytics ownership records, subject to the exceptions below.
Product interaction eventsNormally removed after 30 days.
Lead Form submissionsNormally removed 90 days after submission.
Daily unique-scan keyExpires after about 24 hours.
Detailed scan analytics and rollupsReporting access depends on the account plan and available campaign history. QRLynx keeps recent event detail and longer-lived aggregate reporting data for the applicable reporting window. Account deletion starts dedicated analytics deletion and retry controls.
Email recordsMessage bodies are normally removed after 3 days. Limited delivery and suppression records can remain longer for deliverability, safety, and communication preferences.
Billing and legal recordsKept as required for payment processing, accounting, fraud prevention, disputes, and applicable law. Stripe applies its own retention duties.
Security, audit, and recovery recordsKept only as long as reasonably needed for security, incident response, legal claims, workspace accountability, and recovery. Deleted data can remain temporarily in access-controlled provider backups. Dedicated analytics backup generations are designed not to exceed 90 days.

You can request account deletion from account settings. An active paid subscription or trial must be cancelled before the account can be deleted. Primary account data is removed through the deletion workflow. Some provider backups, security records, billing records, unresolved incident records, or data required by law can remain until their applicable retention period ends.

Your privacy rights and choices

Depending on where you live, you may have rights to know or access personal information, correct it, delete it, restrict or object to certain processing, receive portable data, withdraw consent, or appeal a decision. You may also have the right to complain to a privacy or data-protection authority. QRLynx will verify the requester before acting and can retain information when a legal exception applies.

To make a privacy request, email support@qrlynx.com from the account address or use the QRLynx contact page. Account holders can also update profile information, manage email preferences, export available account data, and request deletion from account settings.

Cookies and tracking choices

The QRLynx Cookie Policy lists the current first-party cookies, browser storage, consent behavior, and optional tags. Microsoft Clarity, Google Ads, and Microsoft Advertising tags are disabled sitewide as of July 29, 2026.

Security

QRLynx uses modern TLS in transit, Cloudflare-managed encryption for hosted storage, HttpOnly session cookies, origin checks for account-changing requests, rate limits, bot controls, URL safety checks, scoped API keys, access controls, and operational monitoring. No internet service can guarantee complete security. If you believe a QRLynx account or link is being abused, email abuse@jorbox.com.

International processing

Jorbox LLC is based in the United States, and QRLynx service providers operate in multiple countries. Information can therefore be processed outside your country. QRLynx uses contractual and provider safeguards required for applicable international transfers.

Children

QRLynx is a general-audience business service and is not directed to children under 13. QRLynx does not knowingly collect personal information from a child under 13. A parent or guardian who believes a child provided personal information can contact support@qrlynx.com so the information can be reviewed and removed where appropriate.

Changes to this policy

QRLynx may update this policy when its data practices, providers, product behavior, or legal obligations materially change. The date at the top will reflect a substantive update. Material changes may also be communicated through the service or by email when appropriate.

Contact

Privacy questions and requests can be sent to support@qrlynx.com. Postal correspondence can be sent to Jorbox LLC, 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States.

By · Last updated: