Privacy Policy

Last updated: 1 August 2026

1. Controller

Julius Ziesmann, Panoramastraße 22, 72144 Dußlingen, Germany
Phone: +49 7072 126 21 00 · Email: support@qr4.live

2. Website delivery and security logs

We operate qr4.live on a server provided by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. IP addresses, technical connection and log data, account data, QR content, uploaded files, statistics and backups may be processed on this hosting infrastructure. STRATO processes this data on our behalf under a data processing agreement pursuant to Article 28 GDPR. Processing for our server takes place in Germany. The legal bases are Article 6(1)(b) GDPR for contractual functionality and Article 6(1)(f) GDPR for secure and reliable operation. Further information: STRATO Privacy Notice.

The server processes IP address, time, requested URL, HTTP status, transferred volume, referrer, browser and operating-system information to deliver and secure the service and diagnose faults. The basis is Article 6(1)(f) GDPR. Logs are normally erased after no more than 14 days unless a security incident requires longer retention.

3. Accounts, login and sessions

We process email, internal customer number, password hash, security and confirmation data, role, language, time zone, login/activity times and optional profile, company and address data to provide the contract (Article 6(1)(b) GDPR) and secure accounts (Article 6(1)(f)). Active-session records contain a session identifier, activity times, path and device/browser/OS category and are automatically erased after 7 days. Essential authentication, security, language and time-zone cookies are required under section 25(2)(2) TDDDG.

Google login

If selected, Google supplies the provider identifier and email released for login. Google login is optional. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Processing outside the EEA cannot be excluded. See Google Privacy Policy.

4. QR codes, cards and uploads

We process entered card content, design and destination data and uploaded images, PDFs, audio and video to provide requested functions (Article 6(1)(b) GDPR). Published cards and authorised files can be accessed without login by anyone possessing the QR code or URL. Upload only material you are entitled to publish. Drafts and management functions remain account-protected.

5. QR scan statistics and local geolocation

For published QR destinations we process time, QR code, anonymised IP address, shortened user-agent/device information, referrer and approximate country, region or city. IP addresses are anonymised before permanent storage. Location is determined locally with GeoLite2 and is not sent to an external IP service. The basis is Article 6(1)(f) GDPR for privacy-preserving product statistics and abuse prevention.

If the QR Code owner has enabled optional precise GPS analytics, we display a separate consent screen before redirecting. Only when you select “Share precise location” and then allow the browser permission do we process coordinates, accuracy and the permission time supplied by your device. These values supplement that scan and are shown to the QR Code owner as GPS-based. The nearest place name is determined on our server with the local GeoNames database; coordinates are not sent to an external geocoding service. If you decline, an error occurs or the request times out, redirection continues without GPS data and only the approximate IP-based position remains. The basis for GPS data is your consent under Article 6(1)(a) GDPR. Sharing is voluntary and is not required to access the QR destination. Scan statistics including GPS data are automatically erased after the plan retention period, currently no later than one year.

6. Subscriptions, Stripe and payments

Stripe processes billing and payment details. We store amount, currency, status and Stripe customer, checkout, invoice, payment and subscription identifiers; card data is not stored on our servers. Provider: Stripe Payments Europe, Limited, Dublin, Ireland. Bases: Article 6(1)(b) and (c) GDPR. See Stripe Privacy Policy. When an account is deleted, legally required payment records remain but their direct local account link is removed. Statutory retention is generally eight or ten years.

7. Email

We process email address, message and delivery metadata for confirmations, password recovery, contractual/security messages and enquiries under Article 6(1)(b), (c) or (f) GDPR.

8. Consent and cookies

Essential cookies support login, security, language, time zone and your privacy selection. The consent choice is retained for six months. Analytics starts only after consent under section 25(1) TDDDG and Article 6(1)(a) GDPR. You can withdraw it at any time through “Privacy settings” in the footer.

9. Self-hosted Umami analytics

After consent, the Umami instance operated by us on our STRATO-hosted server in Germany processes page views, referrer, browser, OS, device type and approximate location. Search parameters and URL fragments are excluded. Umami uses no analytics cookies, no cross-site profile and does not store the IP address used technically to calculate location and an anonymous rotating session hash. We do not use user identification or session replay. Analytics data is retained for 24 months and is not provided to an external analytics operator.

10. Recipients and transfers

Recipients may include STRATO GmbH as our hosting processor, other IT and email providers, Stripe, Google when voluntarily selected, advisers and public authorities. Processors are bound under Article 28 GDPR. Transfers outside the EEA comply with Articles 44 et seq. GDPR. Umami, GeoLite2 and GeoNames run locally on our server in Germany.

11. Erasure and retention

Account data and private content are normally erased when the account is deleted, except where law, open contracts, security or legal claims require retention. Backups disappear through scheduled overwriting. Required payment records are separated from the active account and erased after the applicable period.

12. Your rights

Subject to law, you have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent under Articles 7, 15–18, 20 and 21 GDPR, and may complain to a supervisory authority under Article 77. Contact: support@qr4.live. No solely automated decision with legal or similarly significant effects is used.

13. Changes

We update this policy when functions, providers or legal requirements change. The version published here applies.

14. Google Wallet

When you actively choose the optional Google Wallet feature, QR ④ LIVE creates digital Wallet objects for the QR codes you select. The QR code title and type, its public qr4.live redirect URL and technical object identifiers are transmitted to Google. We do not transmit the content behind the QR code or your login credentials, nor do we request access to your Google account.

The recipient is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. A Google account is required to store and use passes in Google Wallet. Google processes data under its own responsibility and processing outside the EEA may occur. See Google’s Privacy Policy.

The legal basis for creation initiated by you is Art. 6(1)(b) GDPR. We retain local assignment and synchronization data while the Wallet pass or associated QR code exists, or until it is no longer required to provide the feature. You may remove a pass in Google Wallet at any time. Do not include special-category personal data in pass titles or public destinations unless an express legal basis and any required approval exist.