Pinqr policies
Privacy policy
This draft describes the account, public-content, payment, delivery, and security information used to run Pinqr. The provider settings and unresolved retention and rights procedures still require final review.
Draft updated: . This is a draft revision date, not an approved effective date.
Cookies and appearance preference
Authentication uses browser session information and cookies to keep you signed in. Clearing those cookies can sign you out. Security checks can also process browser information as described below.
Appearance follows your device until you choose Light or Dark. We save your choice in a cookie on this browser for up to one year. It is not linked to your account or used for tracking. You can change the preference or remove it by clearing site cookies.
Information account owners provide
We process account details such as an email address and display name, plus public-page content including names, biographies, images, links, appearance choices, and QR definitions. Public page content is visible to anyone who opens its published URL. Visitors, search engines, and other services may copy or cache that content; unpublishing a page does not remove copies held by others. Links you choose to follow lead to services with their own privacy practices.
Billing information
Stripe handles checkout, payment methods, invoices, and receipts.Pinqr stores account-linked customer, subscription, and price references; billing and paid-through dates; subscription status; Checkout coordination records; and webhook-processing records needed to provide and reconcile paid features. The app does not receive full card details. Refund and cancellation information is described in the terms.
Page, link, and QR analytics
We count page views, link clicks, and QR scans. Analytics may include coarse country or region, device category, browser family, referrer domain, and bot classification. Raw visitor IP addresses are not permanently retained by the application, and we do not create invasive device fingerprints. Hosting and security providers may process request information under their own retention and security arrangements; the application database description is not a claim that no provider ever receives an IP address.
Security and abuse prevention
We process limited request information to protect authentication, uploads, reports, redirects, and other abuse-sensitive features. Short-lived rate-limit records use one-way fingerprints rather than storing the raw address in the application database.
Service providers and email
- Supabase provides authentication, the database, and file storage.
- Vercel hosts and delivers the site and processes requests to the application.
- Resend delivers configured transactional email, including authentication mail sent through Supabase. Delivery involves recipient addresses, message contents, and delivery information.
- Stripe processes payments and manages billing information.
- Cloudflare Turnstile provides abuse checks using information from the browser and the verification request.
Email delivery is separate from public-page analytics. Optional email-open and click-tracking settings have not been verified as part of this draft. They must be checked and any actual tracking described before the privacy policy is finalized; the presence of a tracking DNS record alone does not establish what is collected.
Provider agreements, processing locations, international-transfer arrangements, and the complete data inventory still require review. This list describes the configured service providers, not a certification of compliance.
Retention, account closure, and requests
Owners can edit or unpublish public content, and deleted pages, links, and QR definitions can remain in a recoverable state. Downgrading a plan preserves content while applying the new allowances. These actions are not immediate permanent erasure from the database, backups, or a service provider.
Contact mayharsadik@yahoo.com to ask about access, correction, an export, or account deletion. This is a support request process, not an automated export or deletion tool. We may need to verify that a request concerns your account. Do not send passwords, full payment-card details, or authentication links.
Retention schedules for account data, analytics, security records, billing records, and backups are not finalized in this draft. Applicable privacy rights, request deadlines, and any information that must be retained for legal or security reasons must be reviewed before these policies are approved. No fixed deletion deadline or unsupported self-service capability is promised here.
Contact
Privacy questions can be sent to mayharsadik@yahoo.com.