ExeQRCode

Seller and data controller details

Information we process

QR and barcode content, uploaded logos and files selected for scanning are processed in your browser and are not uploaded to ExeQRCode servers during normal tool use.

  • QR history and preferences stored in your browser
  • Email, optional WhatsApp number, order note and transaction references for package purchases
  • IP address, device, browser, request time and error logs needed for security and operation
  • Information you voluntarily provide in support requests

Sources and required fields

We receive order and support information directly from you, and payment status, transaction references and limited card information (such as brand and last four digits) from the payment provider. Email is required to form and fulfil the order. WhatsApp number and order note are optional. If required information is not provided, the order cannot be created or fulfilled.

Purposes and legal bases

  • Creating the order, verifying payment, fulfilment and support: contract performance
  • Invoices, tax, accounting, fraud prevention and official requests: legal obligations
  • Keeping the site secure and operational: legitimate interests and information security
  • Non-essential analytics, advertising or marketing: prior consent where required

Payment processing

Card number, expiry date and security code are entered into Stripe's embedded encrypted payment field. This card data does not pass through ExeQRCode servers and is not stored by us. Stripe, banks and card networks may process data for payment, authentication, fraud prevention and compliance under their own responsibilities.

WhatsApp communication

Providing a WhatsApp number is optional and it is used only to contact you about the relevant order, support or digital fulfilment. When an administrator starts a WhatsApp conversation, the number and message content may be processed by WhatsApp/Meta under its own privacy terms.

Sale of data and marketing

We do not sell personal data. Order contact details are not used for advertising or unrelated marketing without consent or another valid legal basis.

Recipients and international transfers

Data may be shared only as necessary with hosting and infrastructure providers, Stripe and payment partners, accountants, authorised public bodies and legal advisers. These providers may operate in different countries. Where an international transfer occurs, we use adequacy decisions, contractual safeguards or another transfer mechanism required by applicable law.

Retention

Order, invoice, tax and accounting records are kept for the applicable statutory period; support records for resolution and a reasonable dispute period; and security logs only as long as needed to investigate risk. Data is deleted, anonymised or access-restricted when the period ends. Browser QR history can be removed by clearing browser data.

Automated decisions

ExeQRCode does not make solely automated decisions about you that produce legal or similarly significant effects. Banks, card networks and the payment provider may apply automated risk checks for fraud, authentication or compliance under their own privacy notices.

Cookies and local storage

We currently do not run advertising or behavioural analytics cookies for general visitors. QR history may be kept in local storage on your device. An essential security cookie is used only for admin sessions. If non-essential tools are introduced, a preference panel and consent will be provided before they load where required.

Your rights and complaints

Depending on applicable law, you may have rights to access, correct, delete, restrict or object to processing, data portability and withdraw consent. Send requests to qr@exeqrcode.com; identity verification may be required for security. If you are dissatisfied with our response, you may complain to the UK Information Commissioner's Office (ICO, ico.org.uk/make-a-complaint) or the competent data protection authority where you live.

Security, children and changes

We use appropriate technical and organisational safeguards, but no internet transmission is risk-free. The service is not directed to children and we do not intend to knowingly collect children's data. Material policy changes are published here with a new date.

Back to ExeQRCode