Skip to content
QR WILD
How it works Plans Open studio
QR Wild home

Privacy Policy

Effective September 13, 2026 · Last updated September 13, 2026

On this page

  1. Information we handle
  2. How we use it
  3. Scan reports & device data
  4. Cookies & browser storage
  5. AI & business lookup
  6. Who receives information
  7. Published pages
  8. How long we keep it
  9. Your choices & rights
  10. Security & international use
  11. Children
  12. Changes & contact

Your page becomes public when you publish it. Account information, unpublished work and uploaded source images are handled separately from those public pages. QR-link reports show aggregate visits and approximate locations, rather than a list of individual visitors.

QR Wild LLC, a New York software company operated by Dustin Runnells, provides QR Wild at qrwild.com. This policy covers our website, account and page-building tools, QR-link routing and hosting. It explains how we handle information about account holders, people who contact us, and visitors to QR links and hosted pages.

Businesses and other customers choose the content of their QR pages and the outside services those pages use. Their own privacy practices, and those of other QR Wild LLC products linked from our website, are not described by this policy. Our Terms of Service govern use of QR Wild.

1. Information we handle

  • Account and sign-in information. Your email address, name, profile image when provided, account identifiers, connected sign-in methods, verification status, and settings such as your display name and time zone. Google, Apple and Firebase provide the identity information needed to sign you in. Apple may provide a private relay email address. Passwords, if you choose to use one, are handled by Firebase Authentication; QR Wild’s application does not store your password.
  • Your content. Business names, contact details, links, instructions, messages, website information, images, logos, QR artwork, page content and revisions that you submit, import, generate, save or publish. This can include personal information you choose to place in that content.
  • Billing information. Your selected plan, subscription status, payment and invoice identifiers, amounts, currency and payment dates. Stripe collects and processes payment details through its checkout and billing portal. QR Wild does not store full payment-card numbers or card security codes.
  • Support communications. Your contact details and the messages or attachments you send us, along with information needed to investigate or respond.

Google sign-in gives us basic identity information, such as your name, email address, profile image and account identifier. We use this to create and identify your QR Wild account, authenticate you, display your profile and support account access. Google sign-in does not give QR Wild access to your Gmail messages, contacts or Google Drive files. Linking another sign-in method associates that provider’s identity with the same QR Wild account.

2. How we use information

We use information to provide and protect QR Wild: create and secure accounts, prepare and edit pages, store and publish your content, route QR links, provide reports, process subscriptions, administer usage limits, send sign-in and service messages, respond to support requests, investigate abuse and meet legal obligations. We also use account activity and aggregate service statistics to understand usage and improve the service.

Account details and unpublished content are accessible to service providers and authorized personnel as needed for these purposes, including support, moderation and security review. We do not make your sign-in email or profile public merely because you create an account; information you include in a published page is public.

3. Scan reports and device data

When a browser requests a QR Wild link or page, our servers and hosting providers receive technical information such as its IP address, browser or device information, requested address and request time. Operational logs may contain this information for delivery, troubleshooting and security. Abuse controls also use account or guest identifiers and IP-derived identifiers to limit requests.

For QR-link reports, we use the requesting IP address to look up an approximate city, region and country using a local location database. The reports store daily totals by QR code and location; service reports also group visits by broad operating-system category. These analytics records do not store visitors’ IP addresses, raw browser descriptions, precise GPS locations or unique visitor identifiers. Code owners and authorized administrators can view the aggregate reports.

Reports count eligible visits through QR Wild links, including repeat visits. They do not identify individual people or measure completed reviews, bookings or button clicks. Direct visits to a hosted page are not included in QR-link reports, although hosting servers still receive those requests.

For signed-in use of the studio and settings, we also record daily account activity and a broad operating-system category. QR-link analytics and this account-activity collection skip requests carrying an enabled Do Not Track or Global Privacy Control signal. Those signals do not disable essential account, billing, delivery or security processing, or control services embedded by a page owner.

The QR Wild homepage and account tools do not use advertising pixels or cross-site advertising analytics. Outside services on customer-created pages may have different practices, as described below.

4. Cookies and browser storage

QR Wild uses session cookies to keep account and guest work connected to the right browser and to protect requests. Firebase uses browser storage to maintain your sign-in state. Email-link sign-in also temporarily remembers your email address, a sign-in flow identifier, timestamps and, when needed, an account identifier in your browser. That flow information is no longer accepted after 24 hours and is removed on completion or during later cleanup when you use the sign-in tools.

Ordinary unpublished editor work and undo history are held in the open browser page and can be lost when it closes or reloads. A separate, temporary account-verification recovery copy may be saved on our server. Uploaded or saved images and previously saved page revisions have their own storage lifecycle.

The local Wi-Fi QR tool builds the Wi-Fi code in your browser without sending the network name or password to QR Wild’s server or AI service. The code and any file you export contain the connection information, so share them accordingly.

You can clear cookies and browser storage through your browser settings. This may sign you out, interrupt an email sign-in or remove access to guest work. QR Wild’s scan reporting does not set visitor tracking cookies. Sign-in, payment and security providers may use their own cookies or similar technologies when you use those features.

5. AI assistance and business lookup

When you use AI or content-moderation features, relevant instructions, page content, selected images, business details, website extracts and recent editing context may be sent to OpenAI to process the request. This also applies to moderation of uploaded or edited content. Optional web search and website import can involve external search services and the public websites you ask us to use.

Business lookup sends your search to Google Places and retrieves public business information, such as a name, address, website and review link. Searching for a business does not provide access to its private Google account. We may retrieve public website text or images to help prepare your page. The full fetched website and structured extraction are processed for the request; selected details, images and resulting page content may be retained with your work.

AI processing can involve provider retention and security review under the provider’s service terms. Avoid submitting passwords, payment-card details or other confidential or sensitive personal information in page instructions, images or AI requests. See OpenAI’s business data privacy information for its handling of API data.

6. Who receives information

We do not sell personal information or share it for targeted advertising.

We use service providers for the features you use. They receive information needed for their role and may also process technical information directly from your browser:

  • Google and Firebase: account authentication, sign-in emails and public business lookup. See Firebase’s privacy information and Google’s Privacy Policy.
  • Apple: Apple sign-in and private email relay when selected. See Apple’s Privacy Policy.
  • OpenAI: AI generation, moderation and related search, using content relevant to your request. See OpenAI’s business data privacy information.
  • DigitalOcean: hosting, storage and delivery of application data, saved content, images and published pages. See DigitalOcean’s Privacy Policy.
  • Stripe: checkout, recurring payments and billing management. We provide your account email and a customer/account reference, and receive subscription and payment records. See Stripe’s Privacy Policy.
  • Mailgun: delivery of service messages, including reminders, with recipient addresses and message content. See Mailgun’s Privacy Policy.
  • Cloudflare Turnstile, when enabled: browser security checks to help prevent automated abuse. See Cloudflare’s Privacy Policy.

We may also disclose relevant information to professional advisers, to comply with lawful requests, to protect people and the service, or to investigate and enforce our terms. If the business is involved in a merger, acquisition or asset transfer, relevant information may be disclosed as part of that process, subject to applicable privacy obligations. We may share information when you direct us to do so, including when you publish a page.

7. Published pages and outside services

Publishing makes the selected page and its included content available to anyone with its address. Pages and images may be copied, indexed or redistributed by visitors and search engines. Source uploads are private by default, but images included in a published page can become public as part of that page.

Customer pages can contain links, images, scripts or embedded services from other providers. Those providers may receive visitors’ IP addresses and browser information, use cookies or collect information entered on their sites. Their practices are controlled by the page owner and those providers, rather than by this policy. Contact the business shown on the page about information you provide to its booking, review, ordering or other services.

Removing or expiring a QR page starts removal of its public hosting copies. Removal may require retries, and a direct content address may remain accessible until that removal succeeds. We cannot remove copies already saved by other people or control search-engine caches.

8. How long we keep information

Retention depends on the information and the purpose:

  • Account records: kept while the account exists and as needed for support, security, billing and legal obligations. Ending a subscription or deleting a code does not automatically delete your account or its billing records.
  • Saved content: retained while the code remains eligible for hosting or recovery. Deleting a code or passing its recovery deadline starts cleanup of stored revisions and images. Removing an image from the available photo list does not necessarily erase copies used by older page revisions; code cleanup removes the tracked stored copies.
  • Signup recovery: a saved verification recovery copy expires after 24 hours or earlier if its code is released. Successful publication or code deletion clears it sooner; expired copies are removed by maintenance.
  • Reports and request limits: detailed aggregate location reports use a configured retention period of 7 to 365 days. Coarse daily account and code activity and subscription-count reports are kept for up to 730 days. Request-limit records, including IP-derived identifiers, are removed by maintenance after two days.
  • Other records: payment records, support correspondence, administrative audit records and operational or security logs may be retained longer for their operational, accounting, dispute or legal purposes. Some records do not have an automatic deletion schedule.

Cleanup may be delayed by an outage or a failed storage operation. Service providers may retain separate records under their own retention rules and our agreements, including records necessary for security or legal obligations. We may preserve information when required by law or needed to resolve a dispute.

9. Your choices and privacy rights

You can edit your display name and time zone in Settings, manage connected sign-in methods, and edit or delete your QR codes in the studio. Disconnecting a sign-in method does not delete your QR Wild account or the account held by Google or Apple.

To request access to, a copy of, correction of or deletion of your personal information, email support@qrwild.com. Account deletion and broader data requests are handled through support rather than a self-service account-deletion button. Tell us which account or QR page your request concerns; do not send your password or sign-in link. We may ask for information needed to verify your identity or authority before acting.

Depending on your location and the law that applies, you may also have rights to restrict or object to processing, receive a portable copy, withdraw consent for processing based on consent, appeal a decision about your request, or complain to a privacy regulator. We will consider requests and respond as required by applicable law, including explaining any legal reason we cannot fulfill a request. Exercising a privacy right will not result in unlawful discrimination.

If your request concerns information collected by a business through its own QR page or linked service, contact that business. You can also contact us about a privacy concern involving content hosted by QR Wild.

10. Security and international use

We use measures such as HTTPS, authenticated access to account data, restricted access to stored source content and separation of published pages from account tools. No internet service or storage system can guarantee complete security. Keep your sign-in methods secure and tell us promptly if you suspect unauthorized access.

QR Wild is operated from the United States. We and our providers may process information in the United States and other countries, where privacy laws may differ from those where you live. Where applicable law requires a legal basis for processing, we rely on providing the service you request, legitimate interests such as security and service improvement, legal obligations, or consent for processing that requires it. Where legally required, international transfers must use an appropriate lawful transfer mechanism; contact us for information relevant to your data.

11. Children

QR Wild’s account and page-building tools are intended for business owners and other people legally able to use the service, and are not directed to children under 13. We do not knowingly collect personal information from children under 13 through those tools. Public QR pages may have different audiences, including educational uses, and their owners are responsible for the content and services they choose. If you believe a child has provided personal information to QR Wild, contact us so we can review and address it.

12. Changes and contact

We may update this policy as the service or our practices change. We will post the revised policy here with a new update date and provide additional notice or seek consent when required by law. Review this page to stay informed about our current practices.

For privacy questions, requests or concerns, contact QR Wild LLC, New York, United States, at support@qrwild.com.

Back to top

QR WILD

A QR Wild LLC service

QR Wild LLC is a New York software company operated by Dustin Runnells. For support, company inquiries, or legal notices, email support@qrwild.com.

Privacy PolicyTerms of Service

Also from QR Wild LLC

ReciScanBingo EscapeSurvey.isPartyKit.site

© 2026 QR Wild LLC