Privacy Policy
Last updated: July 5, 2026
Overview
MosaicQR is operated by MosaicQR LLC, a Delaware limited liability company (“we,” “us,” or “our”). When you use the Service, you are contracting with MosaicQR LLC. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information. We are based in the United States and process data on U.S. servers, and we collect only what is necessary to provide the Service.
Information We Collect
- Account information: if you sign in with Google via Firebase Authentication, we receive your email address and basic profile information to identify your account.
- Authentication state cookie: a first-party cookie used only for signed-in navigation and account-page redirects, not for analytics or advertising.
- Uploaded images: images uploaded for static QR generation are stored temporarily and automatically deleted within 24 hours. Images used in a dynamic QR code are stored with your account for as long as the code exists, so we can serve and re-render it.
- Destination URLs: the URL you provide is encoded into your QR code and logged by our generation service for internal usage analytics. For dynamic codes, the destination URL is stored with your account so you can edit it and so we can redirect scans.
- Purchase records: your plan, unlocked URLs, and purchase or subscription history, associated with your account. Payment card details are handled entirely by Stripe and never reach our servers.
Scan Data (When Someone Scans a Dynamic Code)
When a dynamic QR code is scanned, our redirect service briefly processes the scanner's IP address and browser user agent to derive an approximate location (country and city) and device type (platform and browser). We store this only as aggregate counts per code, together with scan totals, and show those aggregates to the code's owner as analytics. Raw IP addresses are not stored: a short-lived hash is kept for a few seconds solely to avoid double-counting repeat scans. Scan data is never sold or used for advertising.
What We Do Not Collect
- We do not use advertising cookies or tracking cookies of any kind.
- We do not sell, rent, or share your personal information with third parties for marketing purposes.
How We Use Your Information
- Account information: to authenticate you, display your account, and associate your Stripe purchases and subscriptions with your Firebase user ID.
- Uploaded images and URLs: solely to generate, serve, and redirect your QR codes.
- Scan data: to provide analytics to the code's owner and to enforce plan scan limits.
Third-Party Services
We use the following third-party services to operate MosaicQR:
- Stripe: processes one-time purchases and subscription payments. Your payment information is handled entirely by Stripe; we never see or store your card details. Stripe's privacy policy is available at stripe.com/privacy.
- Firebase: provides authentication and stores your account, unlocked-URL records, dynamic QR configurations and images, and aggregate scan analytics. Firebase's privacy policy is available at firebase.google.com/support/privacy.
- Vercel: hosts the application, provides temporary blob storage for static images (24-hour TTL), and derives the approximate location used in scan analytics. Vercel's privacy policy is available at vercel.com/legal/privacy-policy.
- PostHog: product analytics to understand how visitors use MosaicQR (e.g. page views, feature interactions). PostHog is configured in cookieless mode: no tracking cookies are set, and analytics data is anonymized, so we see approximate geographic region and interaction events but nothing that personally identifies you. PostHog's privacy policy is available at posthog.com/privacy.
Data Retention
Images uploaded for static generation are removed automatically within 24 hours. Dynamic QR configurations, their images, and aggregate scan analytics are retained while the code or your account exists and are deleted when you delete them. Account and payment records remain in Firebase and Stripe until you delete your account or as required for tax and bookkeeping purposes.
Data Security
We use industry-standard security measures to protect your information during transmission and storage. All data is transmitted over HTTPS. Payment processing is handled entirely by Stripe, a PCI-compliant payment processor.
Your Rights
You may request access to, correction of, a copy of, or deletion of the personal information we hold about you at any time by contacting us at the address below. We will respond within the time required by applicable law. Depending on where you live (for example, the EEA, the UK, or California), you may have additional rights under local law, and we will honor valid requests accordingly.
Children's Privacy
MosaicQR is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us and we will promptly delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated “Last updated” date, and we will give reasonable advance notice of material changes (for example, by email or a notice on the Service). Your continued use of MosaicQR after changes take effect constitutes acceptance of the updated policy.
Contact
If you have any questions about this Privacy Policy, please contact us at contact@mosaicqr.com.