← Back to InsightQR

Privacy Policy

Last updated: September 15, 2026

1. Who we are

InsightQR is operated by SouquetConsulting ("we", "us"). If you have questions about this policy, contact us at privacy@leosouquet.com.

2. What data we collect

a) QR code creators (authenticated users)

When you sign in with Google, we store:

  • Your name, email address, and profile picture (provided by Google)
  • A unique user ID
  • The QR codes you create (destination URLs, creation date)
  • Session data to keep you logged in

Legal basis: Contract performance (Art. 6(1)(b) GDPR) — we need this data to provide the service you signed up for.

b) QR code scanners (people who scan a QR code)

When someone scans a dynamic QR code, we collect:

  • Scan time, country and city when available — location is derived from CloudFront headers, not GPS
  • Device type — Mobile, Desktop, or Tablet
  • Browser family — e.g. Chrome, Safari, Firefox
  • Operating system — e.g. iOS, Android, Windows
  • Referrer header — the referring URL when supplied by the browser; the dashboard groups referrers into categories

Our scan event records do not store:

  • IP addresses
  • GPS coordinates (latitude or longitude)
  • Raw user-agent strings (we parse them into categories and discard the original)
  • Cookies or tracking pixels on the redirect

Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) — scan analytics help QR code owners understand how their codes perform. Referrer URLs may contain information supplied by the referring website.

3. How long we keep data

  • Scan analytics: the dashboard provides up to 90 days of history, depending on your plan. Older records may remain in storage pending deletion.
  • User accounts and QR codes: kept until you delete your account
  • Session data: expires automatically when your session ends

4. Where data is processed

QR records, QR images and scan analytics use backend storage in AWS eu-west-3 (Paris). This is not a claim that all processing by every provider takes place in the EU. We use:

  • Amazon DynamoDB — stores user accounts, QR codes, and scan analytics
  • Amazon S3 — stores QR code images
  • AWS Lambda — runs the API
  • Amazon CloudFront — a global delivery network that serves requests and supplies approximate location headers
  • Vercel — website hosting and Web Analytics

Authentication is provided by Google OAuth. When you sign in, Google shares your name, email, and profile picture with us per their privacy policy.

5. Your rights (GDPR)

As an EU resident, you have the right to:

  • Access your data — request a copy of everything we store about you
  • Rectify inaccurate data
  • Delete your account and all associated data
  • Export your data in a portable format
  • Object to processing based on legitimate interest
  • Lodge a complaint with your local data protection authority

To exercise any of these rights, email privacy@leosouquet.com. We will respond within 30 days.

6. Cookies

We use essential authentication cookies managed by NextAuth.js for sign-in and session security. Vercel Web Analytics measures website visits and generator actions without analytics cookies. Generator action events contain language and download format, not the URL entered into the generator.

7. Third-party services

  • Google OAuth — sign-in, subject to Google’s processing and privacy policy
  • Amazon Web Services — backend storage in Paris and global request delivery via CloudFront
  • Vercel — hosting and website analytics
  • Stripe — payment processing for paid subscriptions

These providers process information needed to deliver their services. Network providers receive IP addresses to handle requests; the API also uses the viewer IP for rate limiting. IP addresses are not stored in the scan event records described above.

8. Changes to this policy

We may update this policy from time to time. The "last updated" date at the top will change accordingly. For significant changes, we will notify authenticated users by email.