Privacy policy
Last updated: 10 September 2026
This English translation is provided for convenience; the Romanian version prevails.
Această traducere în limba engleză este oferită pentru comoditate; versiunea în limba română prevalează.
Who we are
QR Stream (qrstream.pro) is operated by TWOSECONDS SRL, with its registered office at [adresa sediului], registered with the Trade Register under number [nr. înregistrare], tax identification number [CUI]. In this policy, “we” means TWOSECONDS SRL, and “you” are the person who creates an account or uses the QR codes generated with QR Stream.
For any question about your data, you can write to us through the contact form or at [email de contact].
What QR Stream is
QR Stream is a generator of static and dynamic QR codes. Static codes carry the destination inside them and no longer pass through our servers once you have downloaded them. Dynamic codes go through an intermediate link and give you scan statistics, hosted pages (a PDF, a coupon or a storage bin with photos, for example) and, on the Business plan, a domain of your own for the short links.
What data we collect
We collect different data depending on how you use the product:
- Account data: your name, your email address and your password, stored as a hash and not as plain text. If you choose to be invoiced as a company, we also optionally store the tax identification number and the billing address.
- The content of your codes: the destinations you set and the files you upload — logos, PDFs, photos for the storage bins — stored on Vercel Blob.
- Scan events, for dynamic codes only: the time of the scan, an approximate location derived from the IP address (country and, sometimes, city), the type of device and operating system and the page the visitor came from (referrer). The IP address itself is never stored — we keep only a one-way hash, derived from the IP address, the user agent and the scanned code, which cannot be turned back into the IP address.
- The messages you send through the contact form.
- The status of your subscription, synchronised from Polar, our payment processor.
Why we process this data
We use the account data to administer your account and your subscription. We use the content of your codes and the files you upload so that the product works — without them, a dynamic code has nowhere to send the visitor. We use the scan events to show you the statistics in your account; we do not use them for any other purpose and we do not sell them. We use contact messages in order to answer you. All of this rests on the performance of the contract between us (the terms you accepted when you created the account) or on our legitimate interest in operating and improving the service.
Who we send the data to
We do not sell your data. We send it only to the technical partners who help us operate QR Stream, each with its own role:
- Vercel — hosts the application and the uploaded files.
- Neon — hosts the PostgreSQL database that holds your account, your codes and your statistics.
- Resend — sends the transactional emails (account confirmation, notifications, password reset).
- Polar — processes the payments and issues the invoices. Polar is the merchant of record for your subscription, so your card details never reach the QR Stream servers.
- Google — only if you choose to sign in with your Google account, in which case we receive your name, your email address and your profile picture from Google.
We may also disclose data where the law obliges us to, for example following a lawful request from an authority.
Cookies
We use only the cookies strictly necessary for your account to work: the session cookie, the CSRF protection and the cookie that remembers you entered the right password for a protected code. We do not use advertising or cross-site tracking cookies, so we do not ask for your consent for them.
QR Stream uses Vercel Web Analytics and Speed Insights on the qrstream.pro domains, including on the public pages of the codes: no cookies, no persistent identifiers, with the page address anonymised. They do not run on customers' own domains.
If you are on the Pro or Business plan, you can connect your own Google Analytics account to a dynamic code — the tag then loads only on the page of that code. In that case you are the data controller for the statistics collected through your tag, and it is your responsibility to inform the people who scan the code.
How long we keep the data
- Account data — for as long as your account is active, plus 30 days after you delete it.
- Scan statistics — 12 months on the Pro plan and 36 months on the Business plan; the Start plan has no dynamic codes, so it generates no statistics.
- Invoices issued through Polar — 10 years, as Romanian tax law on the retention of accounting documents requires.
- Messages from the contact form — for as long as it takes us to resolve the request.
Your rights
Under the General Data Protection Regulation (GDPR), you have the right to:
- find out what data we hold about you (access);
- ask for incorrect data to be corrected (rectification);
- ask for your data to be deleted (erasure);
- ask for processing to be limited, in certain situations (restriction);
- receive your data in a structured format, so you can move it elsewhere (portability);
- object to processing based on our legitimate interest (objection).
You can exercise any of these rights through the contact form or at [email de contact]. If you remain dissatisfied with our answer, you can lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), www.dataprotection.ro.
Security
Passwords are stored as a hash, never as plain text. Communication with QR Stream goes over encrypted connections (HTTPS). Access to the database and to the infrastructure is limited to the team that operates the product.
Changes to this policy
We may update this policy from time to time, for example when we add a new processor or change a data flow. If the change is significant, we will let you know by email. The date at the top of the page shows the last update.