GDPR-Compliant Link in Bio
Link Hubs are on every plan: one hub on Free (€0), unlimited from Pro at €9 per month.
No ad trackers on the hosted page
The public hub page serves exactly one script: a first-party click beacon with zero user data in it. No Google or Meta pixels, no advertising cookies, no cross-site tracking — a data-protection officer can read the page source and be done.
IPs are hashed before they are stored
Every visitor IP goes through an HMAC-SHA-256 hash keyed by a deployment secret before anything touches the database. The raw address is never persisted, so there is no raw-IP store to secure, leak or answer subject-access requests about.
First-party analytics only
Clicks and scans land in your dashboard and nowhere else. The data is never sold, never shared with an ad network, and never enriched by a third-party tracker — visitor counts come from hashed identifiers, not advertising profiles.
Consent is a stored field, not an assumption
Form and newsletter blocks on a hub require an explicit consent checkbox before an email is accepted, the consent state is saved with the lead, and it travels with the CSV export. Stored emails are additionally encrypted at rest.
Retention that actually ends
Analytics retention is plan-driven — 30 days on Free, 12 months on Pro, 24 on Business, 36 on Agency — and a background worker deletes events past the window automatically. Data minimisation happens on a schedule, not on a promise.
The same rules behind the QR code
A bio link usually lives behind a QR code on packaging, posters or a business card. Scans through the code follow identical rules to hub visits: hashed IPs, bot filtering, first-party storage, plan-driven purge.
Know the limits
A hosting choice cannot make your page compliant by itself: the destinations you link to, the content behind them, your privacy notice and your lawful basis remain your responsibility. And we do not advertise EU-only data residency — what we commit to, verifiably, is that raw IPs are never stored and no ad tech runs on the page.
Frequently asked questions
How does QRCode Suite handle IP addresses?
QRCode Suite never stores raw IP addresses. Before any scan event is recorded, the IP is put through an HMAC-SHA-256 hash keyed by a deployment secret, and only that hash is written. The original IP cannot be recovered from it.
Does QRCode Suite filter bot traffic?
Yes. Scans are matched against 26 known bot, crawler, scraper and link-preview user-agent patterns. Matching scans are flagged as bot traffic, excluded from your reported counts, and never forwarded to integrations or webhooks.
Is QRCode Suite compliant with GDPR?
QRCode Suite is built with GDPR in mind: raw IP addresses are never stored, only a keyed hash; bot traffic is filtered out; scan events are purged automatically once your plan retention window elapses; and nothing is forwarded to a third-party platform unless you connect it. Consult your legal team for your specific compliance obligations.
How long is scan data kept?
Retention is enforced automatically per plan — 30 days on Free, 12 months on Pro, 24 months on Business, 36 months on Agency. A background job purges events past that window, so old scan data does not accumulate.
Does QRCode Suite use tracking cookies?
No advertising or cross-site tracking cookies are set. Scan analytics are recorded server-side from the redirect itself, using a hashed IP and a hashed session value rather than a persistent identifier.
A bio link your privacy policy can vouch for
No ad trackers on the page, no raw IPs in the database.