QR Boost
Log in
Legal

Privacy policy

Last updated: 2026-09-17

This policy explains what personal data QR Boost processes, why, on what legal basis, who we share it with, how long we keep it and how to exercise your rights. We process the bare minimum.

1. Data controller

Diego Manuel Béjar Santiago (Wandary) · Tax ID 10880184B · C/ Cardenal Benlloch, 74, esc. izq., 1-1, 46920 Mislata (Valencia), Spain · qrboost@wandary.com.

2. What data we process and why

Data Purpose Legal basis
Email, name, language Create your account, let you log in and manage your QR codes Performance of a contract (art. 6.1.b GDPR)
Sessions: device (browser and OS), usage dates and a pseudonymised IP identifier Keep you logged in and protect your account (attempt limits) Contract and legitimate interest in security (art. 6.1.b and 6.1.f)
Google account (identifier, email and name), if you log in with Google Let you log in with Google Performance of a contract (art. 6.1.b)
Your QR content: destinations, rules, UTM parameters, contact, Wi-Fi, email, SMS or location details you enter, logos and design Provide the service: redirect and show the information to people who scan your QR codes Performance of a contract (art. 6.1.b)
Record of accepting the terms and, if ticked, marketing communications (version, date, language, pseudonymised IP and browser) Prove your acceptance Legal obligation and consent (art. 6.1.c and 6.1.a)
Email for marketing communications Send you news and offers from QR Boost and Wandary, only if you agree Your consent (art. 6.1.a); withdraw it in My account or in any email
Scan stats: country, device type and day Show you how often your QR codes are scanned Performance of a contract (art. 6.1.b)
QR code reports (anonymous): reported code, reason, any details you write and a pseudonymised IP identifier Review abuse (phishing, scams) and prevent mass reporting Legitimate interest in the security of the service (art. 6.1.f)
Web analytics (Google Analytics) Learn which public pages are visited to improve them Consent for cookies; without it, anonymous cookieless measurement (legitimate interest, art. 6.1.f)

People who scan your QR codes. When someone scans a QR code, we use their country (from their connection), device type, browser language and the time at that moment to choose the destination. We don't store their IP or any identifier: we only add one scan to the day, country and device-type counter. Bots and link previews don't count.

Third-party data in your QR codes. If a QR code includes other people's data (e.g. in a contact card), you're responsible for having their permission. That data is shown to whoever scans the code, which is its purpose.

3. Who we share data with (processors)

Provider Purpose Location and safeguards
Amazon Web Services EMEA SARL (Paris region, EU) Servers, database and file storage EU
Twilio SendGrid Sending emails (codes, welcome, account closure) USA: EU-US Data Privacy Framework and standard contractual clauses
Google (Google Analytics, Google sign-in and Web Risk) Web analytics; if you choose, sign-in; and checking that QR code destinations aren't dangerous sites (only the destination addresses are sent) USA: EU-US Data Privacy Framework and standard contractual clauses

We don't sell your data or share it with third parties for their advertising.

4. How long we keep it

  • Account, profile and QR codes: while you have an account.
  • Sessions: until they expire (24 hours without use, or 30 days if you choose to stay signed in) or you close them.
  • Login codes: valid for 10 minutes; deleted the next day.
  • Security and consent records: while you have an account. When you close it, we only keep a pseudonymised record that the request was handled.
  • Scan stats: they're anonymous and kept while the QR code exists.

5. What happens when you close your account

We immediately and permanently delete your account, name, email, sessions, consents, associated records, logos and your QR codes' downloadable files. Your QR codes are not deleted: they're no longer linked to anyone and keep redirecting to their last destination, so nothing already printed breaks. Since no data remains linking them to you, we can't give you back control of them. If any of them contains personal data (e.g. a contact card) and you want it no longer shown, change or delete that QR code before closing your account.

6. Your rights

You can exercise your rights of access, rectification, erasure, objection, restriction and portability, and withdraw your consents at any time, by writing to qrboost@wandary.com. You can close your account yourself from My account.

If you think we haven't handled your request properly, you can complain to the Spanish Data Protection Agency (www.aepd.es) or your local authority.

7. Security

We use encrypted connections (HTTPS and TLS to the database), secure session cookies whose token we only store hashed, one-time codes instead of passwords, attempt limits and IP pseudonymisation.

8. Children

QR Boost is not aimed at children under 14. If you're under 14, don't create an account.

9. Changes

If we change this policy significantly, we'll let you know on the website or by email.