Scanlink.noGo to homepage

Privacy

Privacy notice

This page explains how Scanlink may process personal information and usage data when providing dynamic QR codes. Scanlink is currently operated from Norway and is built with privacy and security as important principles.

About the service

Scanlink is provided through scanlink.no and lets customers create, manage, and update dynamic QR codes while keeping the same printed code.

Information that may be stored

Information needed to provide the service may include:

  • name, email address, contact name, and company name
  • QR code names, destination URLs, and Scanlink URLs
  • uploaded PDF and logo file metadata such as filename, file size, MIME type, storage reference, owner account, associated QR code or schedule, timestamps, and status, plus image dimensions for logos where stored
  • subscription status and payment references from Stripe
  • support requests
  • basic scan activity

PDF and logo files and storage

Customer-uploaded PDF files and logo or image files may be kept in private cloud storage provided by Supabase Storage, or an equivalent provider if Scanlink's technical setup changes. Scanlink does not use uploaded file content for marketing without the customer's permission.

Customers should avoid uploading personal or sensitive information unless they have a lawful basis, the necessary rights, and a legitimate reason to share it through the QR code.

Saved logo files may be used to generate QR code previews and downloads for the authenticated customer.

Public access to PDF destinations

When a visitor opens a PDF destination through a public Scanlink QR code, the document may be made available through a time-limited signed link to the storage provider. This is a temporary technical access link and should not be treated as a permanent public URL.

The normal scan activity described below also applies when a visitor opens a QR code with a PDF destination.

Destination checks and abuse prevention

When an external Link destination is created or changed, Scanlink may normalize the address and compare its hostname against a limited internal list of clearly prohibited domains and hostname keywords. This is used to prevent misuse and enforce the terms.

This check is a basic safety measure, not comprehensive automated content moderation. It does not inspect the contents of private PDF files. Suspected misuse may also be reviewed and handled manually by a founder/admin.

Scan activity

Scan activity may include the time of a scan, browser or device information where available, a referring page where available, and approximate country or city data supplied by hosting or network services.

Payments, sign-in, and service providers

Stripe handles payments, and Scanlink does not store full card numbers. Supabase provides authentication and database services, and Supabase Storage may be used for private storage of uploaded PDF and logo files. Google may be used when a customer chooses Google sign-in.

Cookies

Scanlink uses necessary cookies and similar technology to keep sessions secure, maintain sign-in, and remember relevant choices during registration or authentication.

Stripe, Supabase, and Google may set their own cookies when providing secure payment or sign-in services. Scanlink does not currently use advertising pixels or marketing cookies. This notice will be updated if that changes.

How information is used

Information is used to provide and secure Scanlink, manage subscriptions, present scan activity, respond to support requests, prevent misuse, and protect customers and visitors.

Access, correction, and deletion

Contact Scanlink to ask about access, correction, or deletion of personal information at contact.scanlink@gmail.com.

This notice may be updated as the service and its operational setup develop.

PrivacyTermsContactNorsk