Privacy Policy
Last updated: August 4, 2026
Who we are
sqr.art is operated by CAMINA (SASU), 11 Avenue Maurice Chevalier, 06150 Cannes, France. This policy describes how we process personal data in accordance with the EU General Data Protection Regulation (GDPR).
Data we collect
- Account data — name, email address and password (hashed) when you create an account.
- Content — images you upload, destination URLs, and the generated QR codes.
- WiFi codes — for a WiFi QR code, the network name, security type and password you provide are encoded into the image itself and stored with the code so we can display and regenerate it. Anyone able to scan the printed code can read these details — that is its purpose.
- Payment codes — for a SEPA transfer QR code (EPC), the beneficiary name, IBAN, optional amount and payment reference are encoded into the image during generation. The full IBAN is then deleted from our systems: we retain only a masked version (first and last characters), the beneficiary name, the amount and the reference. We never receive or store card details, and no payment passes through our servers — transfers happen directly between banks.
- Scan data — when a QR code is scanned we record the timestamp and the browser's user-agent string (categorized as mobile, tablet, desktop or bot). We do not store the scanner's IP address with scan records and we do not track scanners across sites. This applies to link QR codes only: WiFi and payment codes are read entirely offline by the scanning device, so we receive no data at all when they are scanned.
- Billing data — subscriptions are processed by Stripe. We never see or store your card details; we keep only the Stripe customer and subscription identifiers.
- Audience measurement — to understand how the site converts, we record anonymous events (preview generated, checkout started, account created, payment completed) tied to a pseudonymous first-party identifier, together with the referrer of your first visit. This is aggregate measurement of our own site; it is not sold, not linked to advertising and not used to track you across other websites.
- Technical logs — IP addresses appear in server logs and rate-limiting counters for security purposes.
Why we process it
We process this data to provide the service (contract performance, Art. 6(1)(b) GDPR), to secure and rate-limit the platform (legitimate interest, Art. 6(1)(f)), and to comply with legal obligations such as invoicing (Art. 6(1)(c)).
Cookies and analytics
sqr.art uses only first-party cookies and no advertising trackers. Two are strictly necessary — the session cookie and the CSRF token the application needs to function. In addition, a short-lived first-party identifier (kept for up to seven days) lets us measure our acquisition funnel — how many visitors generate a preview, start checkout and complete a purchase — in aggregate. It is never shared and never used to follow you across other sites.
For traffic statistics we use Matomo, an analytics tool we host ourselves on our own infrastructure, configured to run without cookies and with anonymised data — your browsing data is not sent to any third party. Because this processing is limited to anonymous audience measurement, we rely on the CNIL exemption from consent, so no cookie banner is required.
Sharing
Data is shared only with the processors required to run the service: our hosting provider (OVHcloud, France), Stripe (payments), Brevo (transactional email, France) and Sentry (error monitoring; technical data only). Database and file backups are encrypted (AES-256) and replicated to an object-storage provider located in the European Union. We never sell personal data. Data may be disclosed to authorities when legally required.
Retention
Account data and QR codes are kept while your account is active and deleted upon account deletion. Failed or abandoned anonymous generations are purged automatically. The full IBAN of a payment QR code is deleted as soon as the code is generated (see above). Technical logs and anonymous audience-measurement events are kept no longer than 13 months.
Your rights
You may access, correct, export or delete your data, and object to or restrict its processing. Write to privacy@sqr.art. You may also lodge a complaint with the CNIL (cnil.fr).