Privacy Policy

Last updated: September 3, 2026

Scantrail (“we”, “us”) helps you create branded QR codes and understand how they are scanned. This policy explains what we collect, why, and the choices you have. We designed our scan analytics to be privacy-first: we never store the IP addresses of people who scan your codes.

1. Information we collect

Account information. When you sign up we store your email address, an optional name and phone number, and a securely hashed password. We never store your password in plain text.

QR codes you create. The name, destination URL, and styling (colors, logo) of each code you make.

Scan analytics. When someone scans one of your codes we record anonymous, aggregate-friendly data: approximate location (country, region, city, derived from network signals), device type, operating system, browser, preferred language, and referrer. We do not store the scanner’s IP address. A random device identifier is stored in a cookie on the scanner’s browser solely to avoid counting the same device twice within a short window.

Billing. Payments are processed by Stripe. We do not see or store full card details; we keep only Stripe’s customer and subscription identifiers and your current plan.

Account usage milestones. When activation measurement is enabled for new accounts, we associate account creation and the first recorded QR creation, download initiation, scan receipt, analytics view, checkout start, and active paid subscription with your account. We use these limited markers to understand where setup needs improvement. This is account-associated data, separate from scanner analytics, not anonymous data. The markers contain no scanner identity, IP address, destination URL, or export filename. Download initiation does not prove a file was saved, and a scan may be your own test.

ScanTrail Feedback. A feedback stand records a private 1–5 experience rating, an optional comment, the stand and QR/NFC medium, and workflow timestamps. We keep contact details only when you explicitly agree that the business may follow up. A separately consented reminder email is used only to send one Google-link reminder after 24 hours and is not shared with the business unless you also consent to follow-up. We record a Google-link click, but cannot tell whether a review was posted. Feedback visits do not store IP addresses, precise location, advertising identifiers, or raw user agents.

2. How we use information

To provide and secure the service, generate the analytics shown in your dashboard, process subscriptions and enforce plan limits, prevent abuse (rate limiting), and communicate with you about your account.

3. Cookies

We use a strictly-necessary, HTTP-only session cookie to keep you signed in. On scan redirects we set a random device-identifier cookie used only for deduplicating scan counts. We do not use advertising or cross-site tracking cookies.

4. Service providers

We rely on a small set of processors to run Scantrail: PocketBase/PocketHost (data and account authentication), Vercel (hosting), Stripe (payments), Resend or our configured transactional-email provider, and Sentry (error monitoring). Each processes data only to provide its service to us.

5. Data retention & your rights

We keep your account and QR data while your account is active. Account usage markers are retained with the account and removed when the account is erased. Feedback visit records are scheduled for deletion after 90 days and private feedback content and consented contact data after 12 months by default. You may request access to, correction of, or deletion of your personal data, including an exact Feedback submission, and you can delete QR codes at any time from your dashboard. Contact us to exercise these rights.

6. Contact

Questions about this policy? Email support@scantrail.io.