Privacy Policy
Effective: June 28, 2026
1. Who we are
OmniQR is operated by Golden Eagles Tech LLC, a US limited liability company (“we”, “us”, or “our”). Our service is accessible at www.omniqr.link. Questions about this policy can be sent to support@omniqr.link.
2. Information we collect
Account data — When you register, we collect your name, email address, workspace name, and a hashed password.
Billing data — Payments are processed by Stripe. We store your Stripe customer ID. We never see or store full card numbers.
Usage data — We log each QR scan and short-link redirect, recording: timestamp, IP address (used for geo-country lookup, then discarded), user-agent, device type, OS, and browser. Raw IPs are not retained in analytics.
Support data — If you contact us, we retain the content of those communications.
3. How we use your information
- To provide, operate, and improve the OmniQR service.
- To process payments and send receipts via Stripe.
- To send transactional emails (verification, password reset, team invitations). We do not send marketing emails without your consent.
- To aggregate scan analytics for the dashboards you access.
- To detect and prevent abuse, fraud, and security incidents.
4. Data sharing
We do not sell your personal data. We share data only with:
- Stripe — for payment processing.
- Railway — our cloud infrastructure provider (US West region).
- Microsoft — for transactional email delivery via Outlook SMTP.
- Law enforcement or regulators when required by applicable law.
5. Cookies and tracking
We use only strictly necessary session cookies for authentication. We do not use third-party advertising trackers or retargeting pixels.
6. Data retention
Account data is retained until you delete your account. Scan analytics events are retained for the lifetime of the associated QR code. When you delete a QR code or close your account, the associated analytics data is deleted within 30 days.
7. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data. To exercise these rights, email support@omniqr.link. We will respond within 30 days.
If you are in the European Economic Area, you have rights under the GDPR. Our lawful basis for processing is contract performance (providing the service you signed up for) and legitimate interests (security and fraud prevention).
8. Security
All data is transmitted over HTTPS. Passwords are stored as bcrypt hashes. Access tokens use short-lived JWTs. We apply rate limiting on authentication endpoints and follow OWASP security guidelines. No system is 100% secure — please notify us immediately if you discover a vulnerability at support@omniqr.link.
9. Children
OmniQR is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has provided us with personal information, contact us and we will delete it.
10. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email or a prominent notice on our website at least 14 days before taking effect. Continued use of the service after that date constitutes acceptance of the updated policy.
11. Contact
Golden Eagles Tech LLC
support@omniqr.link