QRsetter

Privacy policy

We process this data when you ask for a sign-in link and use the QRsetter account.

Last updated September 11, 2026.

Who processes the data

Sergei Sorokin, Belgrade, Serbia. For anything about personal data write to [email protected].

What data we need and why

  • We need your email to send the sign-in link and to sign you in.
  • We keep the account number, the sign-up date, the last sign-in and the plan so that the account works.
  • We keep request logs: the IP address, the browser, the time and result of each request, a session cookie and session data. They protect the sign-in and help us look into errors.

The QR code generator itself works without an account. The lists you paste are not stored. The files you download are stored on the server for 24 hours and then deleted. There are no advertising trackers on the site.

Legal basis, hosting and protection

We process account data because you gave consent. We keep request logs because we need them to keep the sign-in secure. The site is hosted by Timeweb Cloud in Frankfurt, Germany. Two companies see the sign-in email on the way: our email provider and the one that runs your mailbox.

We serve the site over HTTPS, and sign-in links work once. Access to the data is limited to the operator and the hosting provider. We do not publish account data and do not send marketing emails. We disclose data to authorities only where the law requires it.

How long we keep the data

We keep account data while you have the account. When you delete the account or withdraw the consent, we delete the data within 30 days, unless the law requires keeping it longer.

We delete the text of a sign-in email once it is sent. An email that is never sent goes away together with its record. We delete records of emails and links 24 hours after the link expires. We delete sign-in attempt counters 2 days after the last attempt.

Your rights

Write to [email protected] from the account email. You can ask what we hold about you, correct it, restrict or delete it, or withdraw the consent. Before acting on the request, we check that the account is yours.

You can also complain to your data protection authority. In Serbia it is the Commissioner for Information of Public Importance and Personal Data Protection, in the EU it is the authority of your country.