Privacy Policy
Updated 18 September 2026
This is a courtesy translation. The Finnish version is legally binding.
1. Data controller
IoTera Oy (Business ID 3454475-1)
Tampere, Finland
qrleap@iotera.fi
This policy covers the QRLeap service (qrleap.app). It describes what data we process about both users of the service and people who scan QR codes created with it.
2. Users: what data we process
- Account details: the email address and name we receive from our sign-in provider, Clerk, when you register.
- Service content: the QR codes you create, their destination addresses, names, labels, design settings, routing rules, any passwords (stored as a hash), and any logos you upload.
- Subscription details: if you purchase the paid add-on, we store the subscription's identifier, status, and period end date. Payment card details are handled exclusively by Lemon Squeezy. We neither see nor store them.
- Technical data: server logs, which store an IP address and browser details for a short period for troubleshooting and security purposes.
3. Scanners: what data we process
When someone scans a QR code created with QRLeap, we store the following data about the scan so the code's owner can see statistics:
- A hash of the IP address: the IP address itself is not stored. A shortened SHA-256 hash is computed from it and used only to link repeated scans from the same device within 30 seconds.
- Browser identification data (user agent) and the device type (phone, tablet, computer), operating system, and browser derived from it.
- Country and city inferred from the IP address by our infrastructure provider (Vercel). No more precise location is collected.
- A timestamp.
We do not collect a scanner's name, email, or any other direct identifier. Password attempts on a password-protected code are rate-limited by IP address, and this data is kept only in server memory for a few minutes.
4. Purpose and legal basis for processing
- Providing the service (contract): maintaining accounts, routing and reporting on QR codes, managing the paid add-on.
- Preventing misuse and ensuring security (legitimate interest): countering phishing and spam, rate-limiting scans, logs.
- Improving the service (legitimate interest): analysing usage in aggregate, not at the level of an individual person.
- Statutory obligations: bookkeeping for payment transactions.
5. Cookies and local storage
- Strictly necessary cookies: our sign-in provider, Clerk, sets session cookies, without which signing in does not work.
- Local browser storage: we remember that you have dismissed the cookie notice and seen the introductory splash. Neither tracks you across other sites.
We do not use advertising cookies, Google Analytics, or other third-party tracking services. No cookies are set for scanners.
6. Recipients and processors
We use the following providers, who process data on our behalf under data processing agreements:
- Clerk (Clerk, Inc., United States): sign-in and user accounts.
- Vercel (Vercel, Inc., United States): the application's runtime and content delivery, including country and city inference.
- Neon (Neon, Inc., United States): the database holding account, QR code, and scan data. The database is hosted in the EU (AWS, Frankfurt), so this data does not leave the EU.
- Lemon Squeezy (Lemon Squeezy LLC, United States): payment processing and subscription management, only if you purchase the paid add-on.
We do not sell or disclose data for marketing purposes. We disclose data to authorities only when legally required.
7. International data transfers
Account, QR code, and scan data are stored in the EU (Frankfurt). The sign-in provider Clerk, the hosting provider Vercel, and the payment provider Lemon Squeezy are US companies that also process data in the United States. These transfers rely on standard contractual clauses approved by the European Commission and, where applicable, the EU–US Data Privacy Framework. You can request further information about these safeguards from qrleap@iotera.fi.
8. Retention periods
- Account details and QR codes: for as long as the account exists. After account deletion, data is removed within 30 days.
- Deleted QR codes: marked deleted immediately and permanently removed within 30 days.
- Scan events: retained for 12 months, after which they are deleted or converted into aggregate figures from which an individual scan cannot be distinguished.
- Payment transactions: the 6 years from the end of the accounting period required by Finnish bookkeeping law.
- Server logs: at most 30 days.
9. Security
Connections are encrypted (TLS). Passwords are stored as salted hashes, and IP addresses only as hashes. Access to production data is limited to people involved in operating the service.
10. Your rights
Under the GDPR, you have the right to:
- find out what data we process about you, and receive a copy of it
- request correction of inaccurate data
- request deletion of data, unless we have a statutory obligation to retain it
- request restriction of processing and object to processing based on legitimate interest
- receive the data you provided in a machine-readable format.
You can view and delete most of your data yourself from the Service's settings. For other requests, contact qrleap@iotera.fi. We respond within one month.
If you believe we are processing your data unlawfully, you may file a complaint with the Office of the Data Protection Ombudsman: tietosuoja.fi.
11. Changes
We update this policy as needed. Changes are published on this page, and the update date is shown at the top. We will also announce material changes in the Service.