QRCode SuiteQR platform
Privacy

GDPR-Compliant Link in Bio

Whether a link-in-bio page is GDPR-compliant comes down to what happens to visitor data the moment someone taps it — and QRCode Suite's hosted Link Hubs are built so that answer stays short. The hub page itself loads no third-party advertising or cross-site tracking scripts; the only script it serves is a first-party click beacon that carries no user data. Visitor IP addresses are never written raw: every IP passes through an HMAC-SHA-256 hash keyed by a deployment secret before anything is stored, so the original address cannot be recovered from what we keep. Analytics stay first-party in your dashboard, never sold or shared with an ad network. Form and newsletter blocks demand an explicit consent checkbox before an email is stored, and the consent state is saved with the record. Retention is not open-ended either — a background worker purges events automatically once your plan's window elapses. This page owns the privacy angle; what a Link Hub can do is covered on the link-in-bio pages.

Link Hubs are on every plan: one hub on Free (€0), unlimited from Pro at €9 per month.

Start free See pricing

No ad trackers on the hosted page

The public hub page serves exactly one script: a first-party click beacon with zero user data in it. No Google or Meta pixels, no advertising cookies, no cross-site tracking — a data-protection officer can read the page source and be done.

IPs are hashed before they are stored

Every visitor IP goes through an HMAC-SHA-256 hash keyed by a deployment secret before anything touches the database. The raw address is never persisted, so there is no raw-IP store to secure, leak or answer subject-access requests about.

First-party analytics only

Clicks and scans land in your dashboard and nowhere else. The data is never sold, never shared with an ad network, and never enriched by a third-party tracker — visitor counts come from hashed identifiers, not advertising profiles.

Consent is a stored field, not an assumption

Form and newsletter blocks on a hub require an explicit consent checkbox before an email is accepted, the consent state is saved with the lead, and it travels with the CSV export. Stored emails are additionally encrypted at rest.

Retention that actually ends

Analytics retention is plan-driven — 30 days on Free, 12 months on Pro, 24 on Business, 36 on Agency — and a background worker deletes events past the window automatically. Data minimisation happens on a schedule, not on a promise.

The same rules behind the QR code

A bio link usually lives behind a QR code on packaging, posters or a business card. Scans through the code follow identical rules to hub visits: hashed IPs, bot filtering, first-party storage, plan-driven purge.

Know the limits

A hosting choice cannot make your page compliant by itself: the destinations you link to, the content behind them, your privacy notice and your lawful basis remain your responsibility. And we do not advertise EU-only data residency — what we commit to, verifiably, is that raw IPs are never stored and no ad tech runs on the page.

Frequently asked questions

How does QRCode Suite handle IP addresses?

QRCode Suite never stores raw IP addresses. Before any scan event is recorded, the IP is put through an HMAC-SHA-256 hash keyed by a deployment secret, and only that hash is written. The original IP cannot be recovered from it.

Does QRCode Suite filter bot traffic?

Yes. Scans are matched against 26 known bot, crawler, scraper and link-preview user-agent patterns. Matching scans are flagged as bot traffic, excluded from your reported counts, and never forwarded to integrations or webhooks.

Is QRCode Suite compliant with GDPR?

QRCode Suite is built with GDPR in mind: raw IP addresses are never stored, only a keyed hash; bot traffic is filtered out; scan events are purged automatically once your plan retention window elapses; and nothing is forwarded to a third-party platform unless you connect it. Consult your legal team for your specific compliance obligations.

How long is scan data kept?

Retention is enforced automatically per plan — 30 days on Free, 12 months on Pro, 24 months on Business, 36 months on Agency. A background job purges events past that window, so old scan data does not accumulate.

Does QRCode Suite use tracking cookies?

No advertising or cross-site tracking cookies are set. Scan analytics are recorded server-side from the redirect itself, using a hashed IP and a hashed session value rather than a persistent identifier.

A bio link your privacy policy can vouch for

No ad trackers on the page, no raw IPs in the database.

Start freeSee pricing