Skip to content
KeepQR
  • Generator
  • Pricing
  • How it works
  • Our promise
My codes
  1. Home
  2. Privacy notice

Privacy notice

Last updated: 5 October 2026

The short version

  • Free static codes are made in your browser. We never see what you put in them.
  • If you buy editable codes, we keep your email address so you can sign in. We don't use passwords.
  • Stripe handles card payments. We never see or store your card number.
  • We count how many times each editable code is scanned per day. We don't record who scanned it, their location, their device or their IP address.
  • This website uses no tracking cookies and no advertising trackers. Our visitor statistics are cookieless.
  • We don't sell your data, and we don't send marketing emails.

Who we are

KeepQR is a product of TPS505 Ltd, a company registered in England and Wales (company number 16788028). Our registered office is 244 Desborough Road, Eastleigh, England, SO50 5NH. Our VAT number is GB525904585. You can contact us at contact@tps505.com.

TPS505 Ltd is the data controller for the personal data described here. That means we decide how and why it's used, and we're responsible for looking after it under UK data protection law (the UK GDPR and the Data Protection Act 2018).

What we collect, and why

When you visit keepqr.co.uk

We use Cloudflare Web Analytics to count page views. It doesn't use cookies, doesn't store anything on your device and doesn't track you across sites. We see totals such as page views, which pages were visited, the referring site, browser type and country. We can't see individual visitors.

Like any website, our hosting provider Cloudflare processes your IP address to deliver pages to you and to protect the site from attacks.

Lawful basis: our legitimate interest in running a secure website and understanding which pages are useful.

When you make a free static code

Static codes are generated entirely in your browser. The link, text, Wi-Fi details or contact card you enter is not sent to us, and we don't store it.

When you create an account

You sign in with a link or 6-digit code sent to your email address. We store:

  • your email address
  • when your account was created and when you last signed in
  • sign-in links and codes, stored in scrambled (hashed) form, which expire after 15 minutes and can be used only once

Lawful basis: performing our contract with you (we need your email to give you access to the codes you bought).

Your editable codes

For each editable code we store its short link, destination, label, style settings and status (active or paused). We keep a history of changes to destinations and status, so we can help you if something goes wrong and investigate abuse.

When you create or change a destination, we send the web address to Google's Web Risk service to check it isn't a known phishing or malware site. Only the web address is sent, not your email or any other details about you.

Lawful basis: performing our contract with you, and our legitimate interest in keeping the service safe from abuse.

Payments

Payments are handled by Stripe. You enter your card details on Stripe's checkout page, not ours, and we never see or store your full card number. Stripe may ask for your billing country or postcode so the correct VAT is applied.

We receive and keep a record of each payment: what you bought, the amount, the date, Stripe's reference for the payment, and whether it was refunded.

Lawful basis: performing our contract with you, and our legal obligation to keep accounting and tax records. Stripe's own use of your data is covered by the Stripe privacy policy.

When someone scans an editable code

We add one to a daily count for that code. That's all. We don't record the scanner's IP address, location, device, browser or any identifier, and the redirect sets no cookies. Cloudflare processes the scanner's IP address for an instant to deliver the redirect, as any web server must.

Code owners see the daily totals. Nobody, including us, can see who scanned a code.

When you report a code

If you use our report form, we store the code you reported, the reason you give, and your email address if you choose to provide it. We use your email only to reply about that report.

The form uses Cloudflare Turnstile to check that you're a person and not a bot. Turnstile processes information such as your IP address and browser details for that purpose only. The Turnstile privacy addendum explains what it collects.

Lawful basis: our legitimate interest in preventing abuse of the service.

When you email us

We keep your message and our reply so we can help you and refer back to it if needed.

Lawful basis: our legitimate interest in answering your questions.

Emails we send

We only send emails you need: sign-in links, messages about your purchases or refunds, a notice if one of your codes is disabled following an abuse report, and important notices about the service, such as changes to these terms or a notice that we're closing. We don't send newsletters or marketing.

Cookies

keepqr.co.uk and our redirect address go.keepqr.co.uk set no cookies. The dashboard at app.keepqr.co.uk sets one cookie after you sign in. It keeps you signed in for up to 30 days, can't be read by scripts on the page, and is used for nothing else. Because it's strictly necessary for the service you've asked for, we don't need to ask for consent, and there's no cookie banner.

Who we share data with

We use a small number of service providers who process data on our behalf, under contracts that require them to protect it:

  • Cloudflare hosts the website, the dashboard, the redirects and our database, sends our emails, provides cookieless analytics and runs the Turnstile check.
  • Stripe processes payments and calculates VAT. For some purposes, such as fraud prevention and its own legal obligations, Stripe acts as a separate controller.
  • Google checks code destinations against its list of unsafe sites (web addresses only).

We may also share data with our accountants and professional advisers, or with HMRC, the police or a court if the law requires it. We never sell personal data or share it for advertising.

International transfers

Cloudflare, Stripe and Google are international companies, so your data may be processed outside the UK, including in the United States. Where that happens, the transfer is protected by safeguards recognised under UK law, such as the UK International Data Transfer Addendum, standard contractual clauses or the UK–US data bridge.

How long we keep data

  • Account and codes: for as long as you have an account. Codes keep working after you delete your account unless you choose to delete them too.
  • Sign-in links and codes: they expire after 15 minutes. We delete them shortly afterwards.
  • Payment records: six years from the end of the financial year in which you paid, because UK tax law requires it. If you delete your account, we remove your email address and the link between these records and you.
  • Daily scan counts: for as long as the code exists. They contain no personal data.
  • Abuse reports: up to two years after the report is resolved, so we can spot repeated abuse.
  • Emails with us: up to two years after our last contact.

Deleting your account

You can delete your account from the dashboard at any time. We delete your email address and remove the link between you and your payments. Your editable codes keep working, pointing where you last left them, unless you choose to delete them as well. Once your account is deleted, you can no longer edit those codes.

Your rights

Under UK data protection law you have the right to:

  • ask for a copy of the personal data we hold about you
  • ask us to correct data that's wrong
  • ask us to delete your data
  • ask us to limit how we use your data, or object to how we use it
  • ask for your data in a portable format (you can also export your codes as CSV from the dashboard at any time)

To use any of these rights, email contact@tps505.com. We'll reply within one month. There's no charge.

Complaints

If you're unhappy with how we've handled your data, please tell us first at contact@tps505.com and we'll try to put it right. You also have the right to complain to the Information Commissioner's Office (ICO), the UK regulator for data protection: make a complaint on the ICO website or call 0303 123 1113.

Children

KeepQR accounts are not intended for children under 13, and we don't knowingly collect their data.

Changes to this notice

If we change this notice, we'll update the date at the top. If a change affects how we use your data in a significant way, we'll email account holders before it takes effect.

Print it once. It works forever. Pay once if you want to edit it.

  • QR code stopped working?
  • Static vs dynamic
  • QR codes for…
  • Alternatives
  • Guides
  • Report abuse
  • Privacy
  • Terms

KeepQR is a product of TPS505 Ltd.