Qrious.
PRIVACY & GDPR

Privacy Policy

Qrious provides QR-code generation, file sharing, analytics and subscription services. This policy explains how the service processes personal data under the GDPR and applicable Romanian law. For a dedicated rights overview, see the GDPR page.

Service operator

Qrious is operated by Radulescu D Stefan-Radu PFA, CUI 55429019.

Data we process

Why we process it

We process data to provide and secure the service, authenticate users, deliver QR content, enforce plan limits, process subscriptions, provide scan analytics, answer support requests, measure advertising performance and prevent abuse.

Processors

Qrious uses Supabase for authentication, database and private storage, Stripe for payments and subscription management, Google Ads for advertising measurement, and hosting infrastructure for delivering the application. These providers process data under their own security and data-processing terms.

Advertising choice

Advertising cookies are denied by default. If you allow advertising measurement, Google Ads may use cookies and conversion data to attribute actions to ads. If you reject it, the tag may send cookieless signals. You can change your choice at any time through Cookie settings.

Scan privacy

Every visit to a dynamic Qrious short link counts as a scan. A daily HMAC hash derived from network and browser signals estimates unique visitors without retaining the raw IP address. Location is approximate and may be unavailable.

When an account owner enables QR conversion tracking, the QR destination link includes a random click identifier. The optional script on the owner's destination site stores that identifier in first-party local storage only after the site signals analytics consent. It is valid for attribution for seven days and is cleared on a later script load after expiry. Visiting the configured confirmation page can then be counted as a conversion for that QR. Refusing or withdrawing consent prevents or clears this local attribution; it does not erase an event already sent. Site owners are responsible for their own notices and consent integration.

Retention

Account, QR and uploaded-file data is retained while the account or service relationship remains active. Scan events and billing records may be retained as needed for analytics, security, legal and accounting obligations. Contact messages are retained only as long as reasonably necessary to resolve the request.

Your GDPR rights

You may request access, correction, deletion, restriction, portability or objection where applicable. You may also complain to the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP).

Contact

Submit privacy and deletion requests by email at stefan@qrious.now or through the Qrious Contact page. Verification may be required before account data is disclosed or deleted.