EverQR

Security and data practices

Written for the person whose job is to review vendors. Everything here is verifiable from our privacy policy and observable behavior; if anything is unclear, ask and we will answer specifically.

What we store, by design

  • Scan events: timestamp, coarse location resolved in transit (country, region, city), a truncated user agent, and a daily-rotating hash used only to count unique visitors. The hash key changes every day, so it cannot be joined across days to build a profile.
  • Never stored: scanner IP addresses, device identifiers, advertising IDs, cross-site cookies, or any persistent visitor identifier. This is architectural: the columns do not exist.
  • Creator data: account email, subscription status, and the codes you create. IPs used for free-tier rate limiting are deleted within 7 days.

Why there is no cookie banner

Consent banners are required when you track. We set exactly one cookie, a session cookie after a customer signs in, which is strictly necessary and exempt under the ePrivacy rules. Visitors who scan a code or browse the site get no cookies at all.

GDPR posture

For scan analytics we act as processor for our customers. Because no visitor identifiers are stored, scan records are not personal data in most analyses, which simplifies DPIAs considerably. Data subject requests are honored for account data (access, export, deletion). EU or UK customers can request our data processing terms by email.

Subprocessors

  • Cloudflare: hosting, storage, and delivery on their global edge network.
  • Stripe: payments. We never see or store card numbers.
  • Resend: transactional email (sign-in links, alerts, reports).

That is the complete list. No analytics vendors, no advertising networks, no data brokers.

Access control

Team access uses role-based permissions (admin, editor, viewer) with optional per-folder scoping, enforced server side on every request. Every team action is recorded in an activity log visible to the account owner. API keys are named, individually revocable, and shown once at creation. Sign-in uses single-use emailed links; there are no passwords to breach.

Reliability

The service runs on Cloudflare's edge in 300+ cities with no single server to fail. Destinations of paid codes are health-checked continuously and owners are alerted when they break. Existing codes are a commitment: if the service were ever to wind down, we would provide notice and a migration path, as stated in our terms.

Disclosure

Found a vulnerability? Email us and we will respond quickly and gratefully. We do not operate a bounty yet but we do credit reporters.

Questions? Contact WOCxO, LLC via the email on your receipt, or reply to any EverQR email.

© 2026 WOCxO, LLC · EverQR · Privacy · Terms · Security