Logo alpha
  • Home
  • About
  • Plans
  • Login
  • Register

Privacy Policy

Effective date: TODO: set effective date

This Privacy Policy explains what information TODO: legal entity name, e.g. "QRComp LLC" ("QRComp", "we", "us") collects through QRComp.com (the "Service"), how we use it, and the choices you have. By using the Service you agree to the practices described here.

1. Information We Collect

Account information

When you create an account we collect your name, email address, and a hashed password (or, if you sign in with Google, the basic profile information Google shares with us — name, email, and avatar). We also track basic account status such as whether your email is verified and whether your account is active.

Your collections and inventory

Content you enter to use the Service — collection names, item descriptions, prices, quantities, and similar inventory data — is stored so we can generate your labels, QR codes, and analytics. This is your data; we don't use it for anything beyond operating the Service for you, except where noted under "AI Features" below.

Card photos

If you attach a photo to an item, where it lives depends on how you added it:

  • Camera capture or a photo you edit in our photo editor: uploaded directly to a folder ("QRComp Card Photos") in your own connected Google Drive. We don't keep a permanent copy on our servers. The uploaded file is set to "anyone with the link can view" so it can be displayed on your labels and item pages.
  • Picked from Google Photos: we request a short-lived, direct link to the photo you picked from Google's API — we don't copy it into our own storage.
  • A pasted image URL: we fetch and temporarily cache the image bytes (roughly one hour at a time) so your item pages load reliably, then let the cache expire.

Payment information

Subscription payments are processed by Stripe. We store your Stripe customer ID and subscription status so we know what plan you're on — we never see or store your card number. Stripe's own privacy policy governs the payment details you give them directly.

QR code scan activity

Each label we generate includes a QR code. When it's scanned, we log which item was scanned, which collection it belongs to, and when — so you can see scan activity in your dashboard. We do not collect the identity, IP address, or device information of the person scanning the code.

Cookies and session data

We use a session cookie to keep you signed in. Like most web servers, our session storage records the IP address and browser user-agent associated with your active session for security purposes.

Waitlist / "Notify Me" signups

If you sign up to be notified about a feature, we store the name, email, and (optional) company you provide, solely to send you that notification.

2. AI Features

If you use the "optimize search terms" feature, the item descriptions you select are sent to Anthropic's API to generate improved search terms, and the result is saved back to your item. No other account or personal information is sent as part of this request.

3. Third-Party Services We Use

We share the minimum data necessary with the following providers to operate the Service:

  • Google (Sign-In, Drive, Photos Picker) — authentication, and, if you connect it, uploading/selecting card photos.
  • Stripe — subscription billing and payment processing.
  • eBay — if you connect your eBay account, publishing listings you choose to create from your collection items.
  • Anthropic — AI-assisted search term optimization (see above), and cross-collection duplicate detection.
  • Postmark / Amazon SES — delivering transactional email (verification, password resets, receipts).
  • Google Analytics — aggregate site usage analytics. You can opt out using a browser extension or your browser's Do Not Track / privacy settings.

We do not sell your personal information to anyone.

4. How We Use Information

We use the information above to:

  • Provide, maintain, and improve the Service (generating labels, QR codes, and analytics);
  • Process payments and manage subscriptions;
  • Send account-related and transactional email;
  • Detect and prevent abuse or unauthorized access; and
  • Respond to support requests.

5. Data Retention

We retain account and collection data for as long as your account is active. If you delete your account, we delete your account and collection data within TODO: set retention window, e.g. "30 days", except where we're required to keep records for legal or accounting purposes (e.g. billing history). Photos uploaded to your own Google Drive are yours — deleting your QRComp account does not delete them from your Drive.

6. Your Choices & Rights

  • You can disconnect Google Photos/Drive or eBay at any time from your profile settings.
  • You can update your name and password from your profile.
  • You can request deletion of your account and associated data by contacting us below.
  • You can opt out of Google Analytics tracking as described in Section 3.

TODO: add any state/region-specific rights language you need (e.g. CCPA/GDPR) once you know your user base.

7. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

8. Security

We use industry-standard measures (encrypted connections, hashed passwords, access controls) to protect your information. No method of transmission or storage is 100% secure, so we can't guarantee absolute security.

9. Changes to This Policy

We may update this policy from time to time. If we make material changes, we'll update the effective date above and, where appropriate, notify you directly.

10. Contact Us

Questions about this policy or your data? Contact us at TODO: support/contact email.

Privacy Policy · © 2026 QRComp.com