Skip to content

Privacy policy

This page explains in plain language what data we collect when you use linqr, why we process it, who we share it with and what your rights are. It covers both language versions of the service, the app and the onsonara.com/q/… short links.

In short

  • We only collect what we need: your email, an optional name, your QR codes and their links.
  • Scan statistics are anonymous — we don't store IP addresses or full browser details of people who scan your codes.
  • We don't sell data. We don't use analytics or advertising cookies.
  • Payments are handled by Polar — we never see your card number.
  • You can download, correct or delete your data at any time.
Contents
  1. 1.Who is responsible for your data
  2. 2.What data we collect
  3. 3.Why we process data and on what legal basis
  4. 4.Who we share data with
  5. 5.Cookies and browser storage
  6. 6.How long we keep data
  7. 7.Your rights
  8. 8.How we protect data
  9. 9.Children
  10. 10.Changes to this policy
  11. 11.Contact

1.Who is responsible for your data

The controller of your personal data is Halo spółka z ograniczoną odpowiedzialnością (a Polish limited liability company), ul. Warszawska 40 / 2A, 40-008 Katowice, Poland, registered in the National Court Register under KRS 0001145505, VAT ID PL9542880835, REGON 540462426 (“Halo”, “we”, “us”).

For anything related to personal data, write to hello@onsonara.com. We haven't appointed a data protection officer, so we handle this inbox directly.

2.What data we collect

Your account

  • your email address — to sign you in and send messages about your account;
  • your name, if you give it;
  • your password — we only store a salted one-way hash of it; we never know the password itself;
  • if you sign in with Google: your Google account ID and the email address Google has verified. We get no access to your mailbox, contacts or files;
  • your language, when you created the account and when you last signed in.

Your QR codes

  • the short code, the code's name, its destination link and the history of link changes;
  • the design (colours, shapes, frame) and any logo you upload;
  • a draft code created before you sign up — if it's never saved to an account, we delete it automatically.

Scan statistics

When someone scans your code, we record the scan so we can show you statistics. We don't store the IP address or the full browser identifier (User-Agent) of the person scanning. We keep only:

  • the date and time of the scan;
  • an approximate location — country, region and city — which Cloudflare derives from the IP address and passes to us in request headers; the address itself is not stored;
  • the device type (phone, tablet, computer) and the operating system and browser family, such as “iOS” or “Chrome”;
  • the browser's preferred language and the referring site's domain, if the browser sends it;
  • a pseudonymous daily identifier used to count unique scans — a cryptographic hash made with a key that changes every day. It can't tell us who scanned, and scans from different days can't be linked.

This data doesn't let us identify people who scan codes. Only the code's owner can see its statistics.

Payments

If you buy Pro, the payment is handled by Polar Software Inc. as the seller (Merchant of Record). Polar processes your card and billing details. From Polar we receive only what we need to run your subscription: its ID, plan, status and billing period dates. We have no access to your card number.

Technical data

Our server keeps short-lived technical logs (such as the requested page, response code and time) for security and debugging. Logs don't contain passwords, tokens or email addresses. To prevent abuse, such as limiting sign-in attempts, IP addresses are processed on the fly in server memory and never stored in the database.

3.Why we process data and on what legal basis

  • Your account, signing in (including with Google), creating and storing codes, redirects, statistics for the code owner

    Legal basis (GDPR)
    Art. 6(1)(b) — performance of a contract, i.e. our Terms
  • Pro: subscription and payments through Polar

    Legal basis (GDPR)
    Art. 6(1)(b) — performance of a contract
  • Account emails: address confirmation, password reset, subscription notices and important changes

    Legal basis (GDPR)
    Art. 6(1)(b) — performance of a contract
  • Recording scans as described above (concerns people who scan)

    Legal basis (GDPR)
    Art. 6(1)(f) — legitimate interest: showing code owners how their codes are used, with minimal data
  • Security: protection against phishing, spam and attacks, blocking codes that break our rules, technical logs

    Legal basis (GDPR)
    Art. 6(1)(f) — legitimate interest: keeping the service and its users safe
  • Establishing, exercising or defending legal claims

    Legal basis (GDPR)
    Art. 6(1)(f) — legitimate interest
  • Legal obligations, e.g. responding to requests from competent authorities

    Legal basis (GDPR)
    Art. 6(1)(c) — legal obligation

Giving us your email is voluntary, but you can't create an account without it. We'll only send marketing emails if you explicitly agree (Art. 6(1)(a)), and you can withdraw that consent at any time. We don't make decisions about you based solely on automated processing, including profiling.

4.Who we share data with

We work with trusted providers. Some process data on our behalf under a data processing agreement (Art. 28 GDPR); others act as independent controllers. We don't sell data to anyone.

  • OVHcloud (OVH SAS)

    Role
    server and database hosting
    Data
    all service data
    Where
    European Union
  • Cloudflare, Inc.

    Role
    network and attack protection, detecting the country and city of a scan
    Data
    network traffic, including the IP address at request time
    Where
    global — transfers outside the EEA under Standard Contractual Clauses and the EU-U.S. Data Privacy Framework
  • Resend

    Role
    sending emails (confirmations, password resets)
    Data
    email address, message content
    Where
    EU region
  • Polar Software Inc.

    Role
    selling Pro as Merchant of Record — independent controller
    Data
    payment and billing details, email
    Where
    USA — transfers under Standard Contractual Clauses
  • Google Ireland Limited

    Role
    optional Google sign-in — independent controller
    Data
    account ID and email
    Where
    EU and USA — EU-U.S. Data Privacy Framework

We may also disclose data to public authorities where the law requires it, for example at the request of a court or prosecutor.

5.Cookies and browser storage

We only use cookies that are strictly necessary for the service to work. We don't use analytics, advertising or tracking cookies, which is why there's no consent banner.

  • __Host-linqr

    Purpose
    keeps you signed in
    Lifetime
    up to 30 days after your last activity, or until you close the browser if you don't choose to stay signed in
  • XSRF-TOKEN, __Host-linqr-csrf

    Purpose
    protect forms against CSRF attacks
    Lifetime
    until the session ends
  • __cf_bm (Cloudflare)

    Purpose
    tells people apart from bots
    Lifetime
    up to 30 minutes

We also keep the draft of the code you're creating in your browser's storage (localStorage), so it survives a page refresh or signing in, together with a note that you signed in recently. If you choose to sign in with Google, Google may use its own cookies under its privacy policy.

6.How long we keep data

  • Account and codes — until you delete your account. On deletion we immediately anonymise your personal data and your codes stop working.
  • Scan statistics — up to 25 months after the scan, then deleted.
  • Draft codes never saved to an account — deleted automatically.
  • Backups and technical logs — up to 30 days, then overwritten.
  • Messages you send us — as long as needed to deal with your request, then until any related claims become time-barred.

Payment records and invoices are kept by Polar for as long as tax and accounting laws require.

7.Your rights

You have the right to:

  • access your data and get a copy of it (Art. 15 GDPR);
  • have your data corrected (Art. 16) — you can change your name yourself in Settings;
  • have your data erased (Art. 17) — you can delete your account in Settings at any time;
  • restrict processing (Art. 18);
  • data portability (Art. 20) — we'll send your data in a common format such as JSON or CSV;
  • object to processing based on legitimate interests (Art. 21);
  • withdraw consent at any time where we rely on it, without affecting the lawfulness of earlier processing.

To use any of these rights, write to hello@onsonara.com from the email address on your account. We'll reply without undue delay and within one month at the latest.

You can also complain to a supervisory authority. In Poland that's the President of the Personal Data Protection Office (UODO, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl); you can also contact the authority in the EU country where you live or work.

Scanning someone else's code? We don't keep data that could identify you, so we usually can't point to your scans (Art. 11 GDPR). If a code leads to a suspicious site, report it to hello@onsonara.com.

8.How we protect data

  • encrypted connections (HTTPS) on every page and every redirect;
  • passwords stored as salted PBKDF2 hashes; sign-in is locked after 10 failed attempts;
  • signing you out on all devices after a password change;
  • protection against CSRF attacks and rate limiting;
  • servers in the European Union, with access only for authorised people and only as far as needed;
  • regular backups and security updates.

No system is completely immune to attacks. If a breach could put your rights at risk, we'll inform you and the supervisory authority as the GDPR requires.

9.Children

linqr isn't meant for anyone under 16, and we don't knowingly collect their data. If you believe a child has created an account, write to us and we'll delete it.

10.Changes to this policy

We may update this policy, for example when we change a provider or add a feature. The date of the last change is at the top of this page. We'll tell you about significant changes in advance by email or in the app.

11.Contact

Halo Sp. z o.o., ul. Warszawska 40 / 2A, 40-008 Katowice, Poland, email: hello@onsonara.com.

See also: Terms of service