Privacy policy
This page explains which data qr-code-world.com processes, what for and for how long. We use Google Analytics and Google Ads only with your consent; without it the site loads nothing from third-party servers. In case of doubt, the German version applies.
As of 3 October 2026
1. Controller
bequ GmbH, Pestalozzistraße 25, 22305 Hamburg, Germany, represented by its managing director Leonard Saltzwedel.
Email: service@bequ.io
2. Server and hosting
The site, its database and the short links of the codes run on a server that we rent from Hostinger (Hostinger International Ltd., Cyprus) in a data centre in Frankfurt am Main, Germany. Hostinger processes the data on our behalf under a data processing agreement (Art. 28 GDPR); where Hostinger uses service providers outside the European Economic Area for this, the agreement safeguards it in line with Art. 44 et seq. GDPR.
For every request the web server writes a log: IP address, time, requested address, status code, amount of data transferred, the previously visited page and the browser identifier. We need this to run the site securely and to detect errors or attacks (Art. 6(1)(f) GDPR). The logs are deleted after 14 days.
3. Cookies
Without your consent we only set cookies that are strictly necessary for the respective function (Section 25(2) no. 2 TDDDG); none of them is used for advertising or analytics, and none is shared with third parties. This includes the cookie that stores your choice in the cookie notice. Cookies for statistics and marketing are only added with your consent (section 11).
| Cookie | Purpose | Duration |
|---|---|---|
| __Host-qcw_sitzung | Keeps you signed in. Contains a random value; we only store a checksum of it. | 30 days, earlier after 14 days without a visit |
| __Host-qcw_google | Protects “Sign in with Google” against misuse (signed random value). | 10 minutes |
| __Host-qcw_statisch | Counts your static codes without an account (up to 3). Contains only signed check values of the codes you created; no content can be worked out from them. | 1 year from the last new code |
| bequ_einwilligung | Stores your choice in the cookie notice (statistics and marketing, yes or no) with time and version so that we do not ask again on every visit. | 12 months |
4. QR codes without an account
When you design and create a static code without an account, your browser sends the content of the code (a target, a text, contact details or Wi-Fi access), the chosen look and, if you pick one, your logo to our server. The server checks web addresses in the content for dangerous sites (section 8), creates the image and sends it back to you. We neither store the content or the logo nor write them to logs.
Without an account you create up to 3 static codes. Your browser does the counting: the cookie __Host-qcw_statisch holds signed check values of the codes you created; no content can be worked out from them, and we store nothing for this on the server. To prevent misuse, the server also keeps in memory until midnight your IP address in shortened form (for IPv4 without the last number) and one check value per code; at midnight or on a restart both are deleted. The legal basis is our legitimate interest in protecting the free service against misuse (Art. 6(1)(f) GDPR).
5. Your account
For an account we store your email address, your password as an argon2id hash (never in plain text), the time your address was confirmed, your language, the time of your last sign-in and, if you use “Sign in with Google”, the permanent identifier of your Google account. Sessions and links from our emails are only stored as a checksum.
We need this data to provide your account and your codes (Art. 6(1)(b) GDPR). Confirmation links are valid for 48 hours, links for a new password for 60 minutes; we delete expired links and sessions automatically.
You are not obliged to give us any data. Without an email address and password or signing in with Google, however, we cannot set up an account for you; you can create static codes without an account and without any details about yourself (section 4).
6. Your codes and content
For each code we store what you enter: target address, text and image of a page, contact details of a business card including a photo, design, title and note, plus a log of changes. We store images without their metadata such as camera or location. The legal basis is Art. 6(1)(b) GDPR.
If you save a design as a template, we store its name, the design including any logo, and the time. Only you can see your templates; a code you create from a template gets its own copy of the design. The legal basis is Art. 6(1)(b) GDPR. If you delete a template under “Templates”, it is deleted permanently right away; if you delete your account, we delete all your templates immediately together with the account. In both cases your codes keep their design.
The content stays stored as long as your account and the code exist. If you delete a code under “My codes”, it is switched off immediately; its content (target, texts, images, contact details and statistics) is deleted permanently 30 days later. After “Delete account” your account data is deleted immediately and your codes are switched off; their content is likewise deleted permanently 30 days later. In both cases the short codes stay blocked so that a printed code never leads to someone else’s target.
7. Paid plans and payments
If you take out a paid plan, we process the payment through Stripe: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland (“Stripe”). For this we send Stripe your email address, the language of your account, the country of your billing address and an internal identifier of your account. You enter your payment details (such as card number or IBAN), your name and your billing address directly at Stripe; we do not receive them, except for the country of the billing address and, if you provide it, your VAT identification number. Stripe creates the invoices on our behalf and provides the customer portal in which you manage your payment method and invoices.
To calculate VAT correctly, Stripe determines which tax applies based on your billing address and, if you provide it, your VAT identification number (Stripe Tax); the legal basis is our legal obligation to tax correctly (Art. 6(1)(c) GDPR).
For each contract we store the plan, the term, start and end, the status, amount and VAT, the country of the billing address, whether the purchase was made with a VAT identification number, the identifiers at Stripe, the time at which you requested the immediate start, the times of cancellation and refund, and which emails about the contract were sent. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR) and our legal obligation to retain invoices and accounting records (Art. 6(1)(c) GDPR in conjunction with Section 147 of the German Fiscal Code (AO) and Section 257 of the German Commercial Code (HGB)).
Cancellations and withdrawals also reach us as an email to service@bequ.io; we keep these as proof as well.
Retention period: we keep invoices and accounting records for ten years, contract documents and business letters for six years, in each case from the end of the calendar year. If you delete your account, we separate the contract data from your account; your email address is then no longer stored with the contract data, only in the invoices at Stripe and in our accounting.
Stripe also processes data under its own responsibility, for example to prevent fraud and to meet its legal obligations as a payment service provider. In doing so, data may be transferred to Stripe, Inc. in the USA; Stripe is certified under the EU-US Data Privacy Framework and additionally uses the standard contractual clauses of the European Commission. Depending on the payment method you choose (for example PayPal, Klarna, Amazon Pay, Apple Pay or Google Pay), the respective provider also receives payment data, under its own privacy notice. More: https://stripe.com/en-de/privacy
8. Checking targets for dangerous sites
So that no code leads to malware or fraudulent sites (phishing) and the address qr.bequ.io with all printed codes stays usable, we check target addresses with the “Web Risk” service of Google Cloud EMEA Limited (70 Sir John Rogerson’s Quay, Dublin 2, Ireland). Google processes the address on our behalf under a data processing agreement (Art. 28 GDPR); Google may also process data in the USA and is certified under the EU-US Data Privacy Framework. We check every new or changed target of a code in an account, every web address in the content of a static code without an account before it is created (the target, links in a text, the website of a contact), and once a day the targets of all active codes. For this our server only sends Google the address, no account or device data and no other content; only the address is assessed, not you as a person. The legal basis is our legitimate interest in protecting everyone who scans a code, and our service, from dangerous sites (Art. 6(1)(f) GDPR).
Our server keeps the result in memory under a checksum of the address, for a match until the time Google states for it, otherwise for at most 24 hours; on a restart it is deleted. We do not accept a target that is on the list. If it is only found in the daily check, the code stops forwarding until you enter a new target or Google no longer lists the address; we note the block with reason and time on the code and receive an email to service@bequ.io with the short code, reason and target. If Google cannot be reached, you can still continue, and we check a saved target in the next daily check.
9. Scans of your codes
When someone scans a dynamic code, the short link passes through our server. For the code’s statistics we store the time, the shortened IP address (for IPv4 without the last number, for IPv6 only the first three blocks), the country, the device type, browser with version and operating system, and of the previously visited page only the address of the website (such as https://www.instagram.com, without subpages or search terms) if the browser sends it.
We determine the country on our own server with the database “IP to Country Lite” by DB-IP (db-ip.com, licence CC BY 4.0); no address is sent to DB-IP. The legal basis is the legitimate interest of the code owners and our own in statistics on the scans (Art. 6(1)(f) GDPR). We only evaluate the scans in aggregated form and do not try to attribute them to individual persons; code owners only see the statistics, no IP addresses. We keep individual scans for 14 months; after that we only keep the number of scans per code and day. These are deleted together with the code’s content.
10. Clicks to our other sites
Links from qr-code-world.com to bequ.store and bequ.codes pass through a redirect on our server (addresses starting with /weiter/). If you have consented to “statistics” (section 11), we store every click as a single event: time, page and position of the link, target, language of the page, country, device type (phone, tablet or computer), operating system and browser, both only as a name without version. We determine the country from your IP address with the database “IP to Country Lite” by DB-IP (db-ip.com, licence CC BY 4.0) on our own server; we do not store the IP address itself for this.
Without this consent the link only forwards you: we store nothing and add no details about the position to the address. For the counting we set no further cookies; we only read what you chose in the cookie notice. We derive device type, operating system and browser from the browser identifier your browser sends with every request; we do not store the identifier itself, and we assign no number or other feature that could link one person’s clicks. We do not count search engines and link previews. With your consent we add the position to links to the shop (bequ_herkunft and utm details) so that bequ.store sees which link you came through. The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). We keep the events for 14 months; after that a daily run deletes them.
Conversely, we count when you come to us through a link from our shop bequ.store (the address then carries utm_source=bequ.store and the position of the link), but only with your consent to “statistics” (section 11): your browser reports the position of the link and the page you opened to our server, and the server adds the time, language, country (derived from your IP address as above, without storing it), device type, operating system and browser. We then remove these details from the address in your browser. The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG); we keep the events for 14 months.
11. Google Analytics and Google Ads with your consent
Only if you agree in the cookie notice does the site load Google Tag Manager and through it Google Analytics 4 (statistics) and Google Ads (marketing), services of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Without your consent it loads nothing from Google. The legal basis is your consent (Art. 6(1)(a) GDPR, for cookies and similar storage in your browser Section 25(1) TDDDG). You can change or withdraw it at any time with effect for the future via “Cookie settings” in the footer of every page; we then delete Google’s cookies on this site and the entry “_gcl_ls” in your browser’s local storage and reload the page.
With consent to statistics, Google Analytics measures which pages you visit and for how long, where you come from (previous page and campaign details), what you click and which events happen: sign-up, sign-in, new QR code, contact request and click to the shop. It also records device, operating system, browser, language and the approximate location that Google derives from the IP address; according to Google, Google Analytics does not store the IP address itself. We analyse bequ.store, qr-code-world.com, bequ.codes, bequ.gmbh and bequ.io together to see paths between these sites. With Google Signals, Google links the data to the accounts of signed-in Google users who have allowed personalised advertising; we only see aggregated figures, for example across devices. Google Analytics deletes the data 14 months after your last visit.
With consent to marketing, Google Ads measures whether you create an account after clicking one of our ads (conversion tracking) and may later show you our ads on other sites (remarketing). For enhanced conversions, the Google tag detects the email address, phone number and address you enter in forms, for example when signing up or in the contact form; if you create an account, we also pass your email address to Google Ads. Your browser first turns this data into a checksum (SHA-256). Google matches it with signed-in Google accounts to attribute the sign-up to an ad; we only receive figures.
For Google Analytics, Google processes the data on our behalf (Art. 28 GDPR). For Google Ads and Google Signals, Google also uses the data for its own purposes and is responsible for that itself. Google may also process data in the USA; Google is certified under the EU-US Data Privacy Framework. More in Google’s privacy policy (policies.google.com/privacy). The cookies with consent:
| Cookie | Purpose | Duration |
|---|---|---|
| _ga | Google Analytics (statistics): recognises your browser on later visits. | 2 years |
| _ga_WG1LVBECXG | Google Analytics (statistics): keeps track of the current session. | 2 years |
| _gcl_au | Google Ads (marketing): attributes sign-ups to ads. | 90 days |
| _gcl_aw | Google Ads (marketing): remembers the click on an ad. | 90 days |
| _gcl_ls | Google Ads (marketing), in your browser’s local storage: remembers ad clicks to attribute sign-ups. | 90 days |
| IDE | Google Ads (marketing) on the domain doubleclick.net: ads on other sites (remarketing). | 13 months |
| bequ_ereignis | Statistics or marketing: passes an event after a redirect to the measurement once (sign-up, sign-in, new code, contact request), without details about you. | 5 minutes, deleted after reading |
| __Host-bequ_ereignis_email | Marketing: after your sign-up, your email address once for the enhanced conversion. | 5 minutes |
12. Emails and contact form
We send emails about your account (confirmation, new password, notices) through the email service of Google Workspace (Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland). Google processes your email address and the content of the email on our behalf under a data processing agreement (Art. 28 GDPR); Google may also process data in the USA and is certified under the EU-US Data Privacy Framework. This also applies to emails from the contact form and to our mailbox service@bequ.io. The legal basis is Art. 6(1)(b) GDPR.
If you write to service@bequ.io, we only use your details to answer your request (Art. 6(1)(b) or (f) GDPR).
With the contact form you send us your email address, your message and, if you like, your name. The server forwards them straight away as an email to our mailbox service@bequ.io, delivered through Google Workspace (Google Cloud EMEA Limited), and does not store them; the server log does not contain the content either. We only use the details to answer your request (Art. 6(1)(b) GDPR where it concerns a contract or your account, otherwise point (f)) and delete the email once the request is settled and we are not required to keep it. To prevent misuse, the server keeps a checksum of your shortened IP address in memory for up to one hour (Art. 6(1)(f) GDPR).
13. Newsletter
If you agree, we send our newsletter with news and tips about QR Code World as well as offers from our shop bequ.store to your email address. We ask when you create your account, with a checkbox that is never pre-ticked, and once in your account if you have not been asked yet; under “Account” (your account settings) you can order the newsletter at any time. It is voluntary, and your account works without it. The legal basis is your consent (Art. 6(1)(a) GDPR).
After you agree, we send you an email with a confirmation link that is valid for 48 hours (double opt-in). Only when you click it do we add your address to the mailing list; without the click you receive no newsletter. If you ticked the box when creating your account, this email arrives as soon as you have confirmed your email address. We send the confirmation email, like all emails about your account, through Google Workspace (Google Cloud EMEA Limited).
So that we can prove your consent, we record each step with the time, your email address, the way (when creating the account, with the question in your account or under “Account”) and the version of the wording you agreed to: when we asked, when you agreed or declined, when we sent the confirmation email, when you confirmed and when you unsubscribed. We do not store your IP address for this. The legal basis is our legitimate interest in being able to prove consent (Art. 6(1)(f) in conjunction with Art. 7(1) GDPR).
We do not measure whether you open the newsletter or click links in it; we use no tracking pixels and no tracked links.
You can unsubscribe at any time: via the link in every newsletter email, in your account under “Account” and, where your email program offers it, with its unsubscribe function. This withdraws your consent with effect for the future; processing up to that point remains lawful (Art. 7(3) GDPR).
Your address stays on the mailing list until you unsubscribe or delete your account. We keep the record as long as your account exists and delete it together with the account. If you had confirmed the newsletter, we keep it for three more years from the last entry after you delete your account, to be able to prove your consent (Art. 6(1)(f) GDPR), and use it only for that purpose.
14. Sign in with Google
If you click “Sign in with Google” or “Sign up with Google”, we forward you to Google (Google Ireland Limited). With the click you consent to Google sending us your email address and the permanent identifier of your Google account (Art. 6(1)(a) GDPR). We receive no other data from your Google account.
What Google processes during sign-in is governed by Google’s privacy policy (policies.google.com/privacy). Google may also process data in the USA; Google is certified under the EU-US Data Privacy Framework. You can withdraw your consent at any time by signing in with email and password or by deleting your account.
15. Your rights
You have the right to:
- access your data (Art. 15 GDPR)
- rectification (Art. 16 GDPR)
- erasure (Art. 17 GDPR); you delete single codes yourself under “My codes” and your account under “Account”
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- object to processing based on legitimate interest (Art. 21 GDPR)
- withdraw consent with effect for the future (Art. 7(3) GDPR), for Google Analytics and Google Ads via “Cookie settings” in the footer of every page
16. Complaints
You can lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Hamburg Commissioner for Data Protection and Freedom of Information (Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit), Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany.
17. Security
The site can only be reached encrypted (TLS). We store passwords only as an argon2id hash, sessions and links only as a checksum. We make no automated decisions about you. With your consent to marketing, Google may analyse data for personalised advertising (section 11).
18. Notes for Switzerland
For users in Switzerland, the Swiss Federal Act on Data Protection (FADP) also applies. We disclose personal data to these countries: Germany (our server in Frankfurt am Main), Cyprus (Hostinger International Ltd.), Ireland (Google Cloud EMEA Limited and Google Ireland Limited) and the USA (Google LLC). Under Annex 1 of the Swiss Data Protection Ordinance, the EU countries provide adequate protection, and so does the USA for companies certified under the Swiss-U.S. Data Privacy Framework, which Google LLC is. Where Hostinger uses service providers in other countries, standard data protection clauses safeguard the disclosure (Art. 16(2)(d) FADP).