1.Who we are and what this policy covers
This Privacy Policy explains how Cuanto Labs LLC, a Florida limited liability company ("Cuanto Labs LLC", "we", "us" or "our") collects, uses, shares and protects personal information when you visit https://qraffic.com, use qraffic (the "Service") or otherwise interact with us. It also explains the rights and choices you have.
For personal information we collect to run our own business, such as account, billing and website data, we are the "controller" (or "business") responsible for it. When a business customer uses the Service to process information about its own users, customers or contacts, that customer is the controller and we process the information on its behalf, as explained in the section on customer data below.
This policy does not cover third-party websites or services that you reach through links in the Service. Their own privacy policies apply.
2.Information we collect
We collect personal information in three ways: you give it to us, it is collected automatically when you use the Service, and we receive it from third parties. The table below lists the categories we collect, where they come from and why we use them.
| Category | Examples | Source | Why we use it |
|---|---|---|---|
| Account information | Name, email address, password (hashed), organization name, role | You, or your organization's administrator | Creating and securing your account, providing the Service, contacting you about it |
| Customer content | QR codes and their destinations, multilink and landing pages, forms, A/B test and targeting settings, uploaded logos and images | You and your team | Providing the Service as you direct |
| Scan and visit data (processed for our customers) | Approximate location (country, region, city), device type, operating system, browser, language, referrer, campaign (UTM) tags, time of scan, A/B variant served, one-way hashes derived from the IP address | Collected automatically when someone scans a code or opens a customer's page | Redirecting the scan and giving the customer who owns the code its analytics; security and abuse prevention |
| Form submissions (processed for our customers) | Whatever fields the customer's form asks for, such as name, email, phone number or a message | People who fill in a form published by a customer | Delivering the submission to the customer that published the form |
| Billing information | Billing name and address, last four card digits, transaction history, tax ID | You, through our payment processor | Processing payments, invoicing, tax compliance, fraud prevention |
| Usage and device data | IP address, browser and device type, pages and features used, timestamps, error logs | Collected automatically | Security, troubleshooting, understanding and improving the Service |
| Communications | Support requests, abuse reports, feedback, email preferences | You | Supporting you, handling reports, improving the Service, sending messages you opted into |
| AI inputs and outputs | Prompts and instructions you submit to AI features, and the generated text and images | You | Generating results for you, preventing abuse |
| Mail recipient data (processed for our customers) | Recipient names and postal addresses a customer uploads for a mail campaign | The customer sending the mail | Printing and mailing the pieces the customer orders |
You do not have to give us personal information, but some of it is needed to create an account and provide the Service. If you choose not to provide it, some features may not be available to you.
3.How we use information, and our legal bases
We use personal information to:
- create and manage your account, and provide the features you ask for;
- process payments, send receipts and manage subscriptions;
- send service messages, such as security alerts, account notices and changes to our terms, which you cannot opt out of while you have an account;
- respond to your requests and provide customer support;
- keep the Service secure, including detecting, investigating and preventing fraud, abuse, spam and security incidents;
- understand how the Service is used, fix problems and improve and develop features;
- send product updates and marketing, where the law allows and subject to your choices; and
- comply with legal obligations, enforce our terms and protect our rights and the rights of others.
Legal bases (EEA and UK)
If you are in the European Economic Area or the United Kingdom, we rely on these legal bases under the GDPR and UK GDPR:
- Contract: to provide the Service you signed up for and manage your account.
- Legitimate interests: to secure, support, understand and improve the Service, and to send business-to-business marketing. We balance these interests against your rights, and you can object at any time.
- Consent: for non-essential cookies, marketing emails where consent is required. You can withdraw consent at any time without affecting processing that already took place.
- Legal obligation: to keep tax and accounting records and respond to lawful requests.
| Category | Legal basis |
|---|---|
| Account information | Contract |
| Customer content | Contract |
| Scan and visit data (processed for our customers) | The customer's lawful basis (we act as its processor); legitimate interests for security |
| Form submissions (processed for our customers) | The customer's lawful basis (we act as its processor) |
| Billing information | Contract; legal obligation |
| Usage and device data | Legitimate interests |
| Communications | Contract; legitimate interests; consent for marketing |
| AI inputs and outputs | Contract |
| Mail recipient data (processed for our customers) | The customer's lawful basis (we act as its processor) |
We do not make decisions based solely on automated processing that produce legal or similarly significant effects for you.
4.Customer data we process for businesses
Our business customers use the Service to store and process information about their own employees, customers and contacts ("Customer Data"). For Customer Data, the business customer is the controller and we are its processor or service provider. We process Customer Data only on the customer's instructions, as set out in our agreement with them and our Data Processing Addendum, and not for our own purposes.
The customer's own privacy policy governs how it uses Customer Data. If your information has been added to the Service by one of our customers and you want to exercise your privacy rights, please contact that customer directly. If you contact us, we will forward your request to the customer and help them respond.
5.People who scan codes or use our customers' pages and forms
Businesses use qraffic to create QR codes, short links, multilink pages, landing pages and forms. If you scanned one of those codes or used one of those pages or forms, the business that created it decides what is collected and why. We process that information on its behalf, as its processor or service provider, and its own privacy notice governs how it uses the information.
What we record when a code is scanned or a page is opened
- approximate location (country, region, city and approximate coordinates), derived from your IP address by our hosting provider at the network edge, never from your device's GPS;
- device type, operating system, browser and language;
- the referring site and any campaign (UTM) tags in the link, the time of the scan, and which version of the destination you were shown if the business is running an A/B test or targeting rule; and
- one-way hashes derived from your IP address, used to count unique scans and to detect abuse. We do not store your raw IP address with scan records, although it appears briefly in our hosting and security logs.
We do not set cookies on your device to track scans, we do not build profiles of people across different businesses' codes, and we do not use this information to market to you or sell it. We use it ourselves only to keep the Service secure, prevent abuse and count scans for billing.
Forms
Answers you submit in a form are delivered to the business that published it, which decides how to use them. Do not enter sensitive information in a form unless you trust that business.
Your choices
To access, correct or delete information about a scan or a form submission, contact the business that created the code, page or form. If you cannot identify it, or it does not respond, write to privacy@qraffic.com with the link or a photo of the code, and we will forward your request and help the business respond. To report a code you think is malicious, see the Acceptable Use Policy.
6.AI features
When you use AI features, the content you submit (such as prompts, files and the context needed to answer them) is sent to our AI model providers, Anthropic and OpenRouter, to generate output. The providers act as our sub-processors and process the content only to provide the feature to us.
We do not use your inputs or outputs to train or fine-tune AI models, and our agreements with our providers prohibit them from doing so.
Our providers may retain content for up to 30 days solely to detect and prevent abuse, and then delete it. Our AI Terms have more detail.
8.Analytics on our own website
To understand how people use qraffic's own website and app, we use OnyxMetric, an analytics tool we operate ourselves. It does not use cookies and records page views, referring sites, device and browser type and approximate location in aggregate. We do not use third-party advertising, retargeting or social media tracking pixels, and we do not share analytics data with advertisers.
10.International data transfers
We are based in the United States, and we and our service providers process personal information there and in other countries whose data protection laws may differ from yours. When we transfer personal information out of the European Economic Area, the United Kingdom or Switzerland, we rely on an adequacy decision (including the EU-U.S. Data Privacy Framework where the recipient is certified) or on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with additional safeguards where appropriate. You can ask for a copy of the relevant safeguards by contacting privacy@qraffic.com.
11.How long we keep information
We keep personal information for as long as we need it for the purposes described in this policy, then delete or anonymize it. How long that is depends on the type of information and why we have it:
| Information | How long we keep it |
|---|---|
| Account information and customer content | While your account is active, then deleted within 30 days of closure |
| Scan and visit records | Until the customer deletes the code or closes its account; how far back a customer can view depends on its plan |
| Form submissions | Until the customer deletes them, the form or its account |
| Billing and tax records | 7 years, as required by tax law |
| Security and access logs | Up to 12 months |
| Abuse reports and enforcement records | Up to 3 years after the report is closed |
| Support communications | Up to 3 years after the request is resolved |
| Encrypted backups | Up to 35 days on a rolling basis |
| AI inputs held by model providers | Up to 30 days, for abuse monitoring only |
Deleted information may remain in encrypted backups for a short time until those backups are overwritten. We may keep information longer when the law requires it or to resolve a dispute, and only for as long as needed.
12.How we protect information
We protect personal information with administrative, technical and physical safeguards appropriate to its sensitivity, including encryption in transit (TLS) and at rest, least-privilege access controls, multi-factor authentication for staff, logging and monitoring, and vendor security reviews. No system is perfectly secure, and we cannot guarantee absolute security.
If a data breach affects your personal information, we will notify you and the relevant authorities as the law requires. To report a vulnerability, contact security@qraffic.com.
13.Your privacy rights and choices
Wherever you live, you can:
- access and update most account information in your account settings;
- ask for a copy of your personal information in a portable format;
- ask us to correct inaccurate information;
- ask us to delete your personal information, subject to legal exceptions; and
- unsubscribe from marketing emails using the link in any of them. We will still send service messages.
To make a request, email privacy@qraffic.com from the address on your account, or use the tools in your account settings. We will verify your identity before acting, usually by confirming control of your account email, and may ask for more information if needed. We respond within 30 days and will tell you if we need more time, as the law allows. Requests are free unless they are manifestly unfounded or excessive. We will not discriminate against you for exercising your rights.
14.Additional rights in the EEA, UK and Switzerland
If the GDPR, UK GDPR or Swiss data protection law applies to you, you also have the right to object to processing based on our legitimate interests (and an absolute right to object to direct marketing), to ask us to restrict processing, to data portability, and to withdraw consent at any time.
You can lodge a complaint with your local data protection authority. In the UK, that is the Information Commissioner's Office. We would appreciate the chance to address your concern first, so please contact us at privacy@qraffic.com.
15.U.S. state privacy rights
Privacy laws in California (CCPA, as amended by the CPRA), Florida (the Florida Digital Bill of Rights), Colorado, Connecticut, Virginia, Texas, Oregon and other states give their residents specific rights. We extend these rights to all of our users in the United States, whether or not their state's law applies to us.
Notice at collection
In the past 12 months we have collected these categories of personal information: Account information, Customer content, Scan and visit data (processed for our customers), Form submissions (processed for our customers), Billing information, Usage and device data, Communications, AI inputs and outputs and Mail recipient data (processed for our customers). We collect them from the sources and for the business purposes described in the "Information we collect" section, keep them for the periods in the "How long we keep information" section, and disclose them for business purposes to the service providers described in "How we share information".
We do not sell or share personal information, including that of consumers under 16. We use sensitive personal information (such as account login credentials) only for purposes permitted by law, such as providing the Service you asked for, and not to infer characteristics about you.
Your rights
- Know and access: the categories and specific pieces of personal information we hold about you, the sources, our purposes, and the categories of third parties we disclose it to.
- Delete and correct your personal information.
- Portability: receive your information in a portable, readily usable format.
- Opt out of the sale of personal information, of sharing for targeted advertising, and of profiling in furtherance of decisions with legal or similarly significant effects. Use Global Privacy Control or email privacy@qraffic.com.
- Limit the use of sensitive personal information to permitted purposes.
- Non-discrimination: we will not deny you service, charge you a different price or give you a lower quality of service for exercising your rights.
How to make a request
Email privacy@qraffic.com with the subject line "Privacy request". You can also have an authorized agent make a request for you; we will ask the agent for proof of your signed permission and may ask you to verify your identity directly. We respond within 30 days, as required by law.
Appeals
If we decline your request, you can appeal by replying to our decision or emailing privacy@qraffic.com with the subject line "Privacy appeal". We will respond in writing within 60 days, explaining our decision. If you are not satisfied, you may contact your state attorney general.
California "Shine the Light"
California residents may ask once a year whether we disclosed personal information to third parties for their direct marketing purposes. We do not do so.
16.Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. You must be at least 16 to use the Service. If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete it promptly. If you believe a child has given us personal information, contact privacy@qraffic.com.
17.Marketing communications
We may send you emails about new features, events and offers. Each marketing email identifies us, includes our postal address and contains an unsubscribe link. We process unsubscribe requests within 10 business days, and you will still receive service messages about your account. Where the law requires your consent to send marketing, such as in the EEA and UK, we ask for it first.
18.Changes to this policy
We may update this policy from time to time. If we make a material change, we will notify you by email or in the Service before it takes effect and update the "Last updated" date above. If a change means we will use personal information we already hold in a materially different way, we will ask for your consent where the law requires it. Previous versions are listed on our legal center.
19.Contact us
For questions about this policy or to exercise your rights, email privacy@qraffic.com or write to Cuanto Labs LLC, Attn: Privacy, 1314 E Las Olas Blvd, Unit #2570, Fort Lauderdale, FL 33301, USA.