Privacy & Cookie Policy
Last updated: August 7, 2026
This Privacy & Cookie Policy ("Policy") explains how OrizonQR ("Provider", "we", "us") collects, uses, stores, and protects personal information when you visit orizonqr.app, use the Service, or interact with our marketing.
It applies globally to visitors, customers, and dashboard users regardless of where you access the Service. We follow a transnational data-protection framework (GDPR/UK GDPR, CCPA/CPRA, LGPD, PIPEDA and equivalents). Where local law grants you stronger rights, those rights prevail.
By using the Service you acknowledge the practices described here, without prejudice to the optional consents requested by our cookie banner for analytics and advertising.
1. Data controller
The controller of personal data processed through the website and the Service is OrizonQR.
You may contact us via the support or legal contact channels published on orizonqr.app. Where legally required, we will appoint an EEA or other regional representative and disclose it in this Policy or on the site.
2. Scope
This Policy covers the marketing website, registration and sign-in, the customer dashboard, QR redirects we operate, account-related communications, and Google measurement and advertising tags we load on the site (Google Analytics 4 and, when enabled, Google Ads).
We do not control processing by your customers or third parties at destinations your QR codes open outside our infrastructure. You are responsible for complying with applicable law for your campaigns and for people who scan your codes.
3. Data we collect
Account and profile data: name, email, password (stored securely/hashed by the auth provider), language preferences, and workspace or company details you provide.
Billing and license data: plan or tier, subscription status, payment processor identifiers, marketplace redemption history, and data needed for billing and fraud prevention.
Product usage data: QR codes, destinations, styles, scans, device/browser/OS signals, approximate geo derived from IP when enabled, and campaign metrics and marketing intelligence generated by the Service.
Site technical data: IP address, user-agent, pages viewed, referrers, device or cookie identifiers, and security/diagnostic logs.
Marketing and advertising data (only with consent when required): Google Analytics and Google Ads cookie identifiers, ad interactions and attributed conversions, and measurement events configured in our tags.
4. Purposes of processing
Provide and improve the Service: authentication, workspaces, dynamic QR codes, product analytics, OrizonIndex™, support, and security.
Perform contracts and legal duties: billing, accounting, fraud prevention, and responses to lawful requests.
Service communications: email verification, password reset, quota alerts, material Service changes, and support replies.
Site and product analytics (Google Analytics 4) when you grant analytics consent: understand site usage, performance, and funnels.
Advertising and ad measurement (Google Ads and related features) when you grant advertising consent: conversion measurement, remarketing, and ad personalization to the extent permitted.
Legitimate interests: protect the platform, prevent abuse, improve reliability, and produce aggregated or pseudonymized statistics where law allows without non-essential cookie consent.
7. Google Consent Mode v2
We implement Google Consent Mode v2 with gtag.js. By default, worldwide, analytics_storage, ad_storage, ad_user_data, and ad_personalization are set to "denied" until you choose otherwise in the banner.
If you accept Analytics, we set analytics_storage to "granted". If you accept Advertising, we set ad_storage, ad_user_data, and ad_personalization to "granted". You may combine categories (e.g. analytics only).
While storage consent is denied, Google tags limit or adapt their behavior (including conversion modeling where Google provides it). We also enable ads data redaction when advertising is not granted.
8. Legal bases
Contract performance: creating and managing your account, delivering the Service, and related support.
Legitimate interests: security, abuse prevention, Service improvement, and strictly necessary measurements where permitted by law.
Consent: non-essential analytics and advertising cookies, and optional marketing communications when we request them separately.
Legal obligation: tax retention, responses to competent authorities, and other applicable compliance duties.
10. International transfers
OrizonQR operates globally. Your data may be processed in Colombia, the United States, or other countries where we or our vendors run infrastructure.
When transferring from the EEA/UK/Switzerland to countries without an adequacy decision, we apply appropriate safeguards (such as standard contractual clauses or other recognized measures) as required by law.
11. Retention
We keep account and billing data while the account is active and for necessary legal or contractual periods afterward (e.g. accounting and disputes).
Scan and product analytics data are retained according to your plan, product retention policies, and legal duties. Technical logs are kept as needed for security and diagnostics.
Cookie preferences are stored in your browser (localStorage) to remember your choice; you may clear or change them at any time.
12. Security
We apply reasonable technical and organizational measures: encryption in transit (HTTPS), access controls, multi-tenant isolation as designed into the product, and secure development practices.
No system is 100% secure. Please notify us promptly if you suspect unauthorized access to your account.
13. Your rights
Depending on your jurisdiction, you may have rights to access, rectify, erase, restrict or object to processing, data portability, withdraw consent, and not be subject to certain automated decisions with legal or similarly significant effects where applicable.
To exercise rights related to your account, use in-product controls where available or contact support. You may also lodge a complaint with your local data protection authority.
For non-essential cookies, withdraw or change consent via the banner or preferences link; withdrawal does not affect the lawfulness of prior processing.
14. Children
The Service is aimed at professionals and businesses. It is not intended for children under 16 (or the higher digital consent age in your country). If you believe a child has provided us data, contact us so we can delete it where appropriate.
15. Changes to this Policy
We may update this Policy to reflect changes to the Service, measurement tags, or the law. We will post the updated version with a revised effective date on this page.
If changes are material to personal data processing, we will take additional notice steps when required by law.
16. Contact
For privacy, cookies, or data rights: use the support or contact channels published on orizonqr.app and mention privacy in the subject.
Controller email: customercare@orizonqr.app
Privacy questions or rights requests: write to customercare@orizonqr.app. OrizonQR operates the Service globally. This controller email is the contact point and does not limit your rights under the law of your country of residence.
