Written for the person whose job is to review vendors. Everything here is verifiable from our privacy policy and observable behavior; if anything is unclear, ask and we will answer specifically.
Consent banners are required when you track. We set exactly one cookie, a session cookie after a customer signs in, which is strictly necessary and exempt under the ePrivacy rules. Visitors who scan a code or browse the site get no cookies at all.
For scan analytics we act as processor for our customers. Because no visitor identifiers are stored, scan records are not personal data in most analyses, which simplifies DPIAs considerably. Data subject requests are honored for account data (access, export, deletion). EU or UK customers can request our data processing terms by email.
That is the complete list. No analytics vendors, no advertising networks, no data brokers.
Team access uses role-based permissions (admin, editor, viewer) with optional per-folder scoping, enforced server side on every request. Every team action is recorded in an activity log visible to the account owner. API keys are named, individually revocable, and shown once at creation. Sign-in uses single-use emailed links; there are no passwords to breach.
The service runs on Cloudflare's edge in 300+ cities with no single server to fail. Destinations of paid codes are health-checked continuously and owners are alerted when they break. Existing codes are a commitment: if the service were ever to wind down, we would provide notice and a migration path, as stated in our terms.
Found a vulnerability? Email us and we will respond quickly and gratefully. We do not operate a bounty yet but we do credit reporters.
Questions? Contact WOCxO, LLC via the email on your receipt, or reply to any EverQR email.