Skip to content

Privacy Policy

Effective date: October 7, 2026

The short version

Who we are

Orange Arc LLC, a California limited liability company ("Guaranteed QR", "we"), operates guaranteedqr.com, the short-link domain gtdqr.com, and the domains our customers connect to it. This policy explains what we collect, why, how long we keep it, who else receives it, and what you can ask of us. Contact: support@guaranteedqr.com, or 2108 N St, Ste N, Sacramento, CA 95816.

What we collect, and from whom

Visitors to guaranteedqr.com

The free generator encodes your link, Wi-Fi details, contact card or text into a QR code inside your browser. Nothing you type is sent to us; our servers only deliver the page.

Our host, Cloudflare, processes the technical data of every request (IP address, browser type, page requested) to deliver and protect the site, as any host does. We keep short-lived operational logs of errors and scheduled jobs; they do not contain the content of your codes.

The sign-in and report forms carry Cloudflare Turnstile, a check that tells a person from a script. Cloudflare receives signals such as your IP address and browser details and uses them only to tell people from bots and to improve that detection, not to profile or target anyone.

We count page views with Cloudflare Web Analytics. Visitors in the European Union, the European Economic Area, the United Kingdom and Switzerland (as our host places the connection) are asked first, in a banner, and their browsers get the script only after they accept it. Anyone, anywhere, can turn it off on the Cookie settings page. When a public page of guaranteedqr.com loads with the script, it reports the page address without its query string, the referring site and how fast the page loaded, and Cloudflare adds the browser, the device type and the country from that request. It sets no cookie and uses no other storage in your browser, and Cloudflare says it does not fingerprint visitors, so it cannot recognize you on a later visit or on other sites. It does not run on the sign-in link page, your account screens or the admin screens.

Account holders

People who scan a dynamic code

When someone scans a code and we forward them to its destination, we record one row: the time, the date, a two-letter country code (from our hosting provider's geolocation of the connection), the device type (iPhone or iPad, Android, computer, other) and the operating system family, both read from the browser's user-agent string. That is all. We do not store the IP address, the full user-agent string, the referring page, a cookie or any identifier.

To avoid counting one phone twice, a keyed hash of the connection address sits in our host's cache for 10 seconds, then disappears; the key changes every day. Beyond those 10 seconds we cannot tell whether two scans came from the same person. Scans by bots and link previews are not counted. We forward you with no referrer, so the destination site does not learn which code you scanned.

Codes on a customer's own domain work the same way. The customer sees only totals by day, country and device type.

People who report a code

The report form asks for the address you saw, a reason, optional details and an optional email address for a reply. Your network address is hashed to limit reports per hour and is not stored with the report. Your email address is deleted when the report is closed.

Payments

Checkout happens on Polar's pages. We send Polar your account email, an internal account identifier, the pack you chose, the page on our site where you chose it, the version of our terms you accepted with the time you accepted them, and your IP address, from which Polar works out your country for sales tax. Polar collects your payment details and billing address and whatever else it needs to charge you and collect tax, and tells us when an order is paid or refunded, with the order identifier and amount.

Why we use this information

We do not use your information for advertising, we do not build profiles, and we do not sell personal information or share it for cross-context behavioral advertising.

We collect only what is needed to provide the Service you asked for, to protect it, and to meet legal obligations such as tax records. For readers in the EU, the UK or places with similar laws: account and payment data are processed to perform our contract with you; scan statistics and security data on the basis of our legitimate interest in running a safe service with as little data as possible; and purchase records are kept under our legitimate interest in meeting US tax and accounting rules. You may object to processing based on legitimate interests, ask us to restrict it, and complain to your data protection authority.

Who receives your information

We share personal information only with the providers we need to run the Service, each for its own narrow job:

ProviderWhat it does for usWhat it receives
Cloudflare, Inc.Hosts our servers and database, caches recent answers, issues certificates for connected domains, runs the Turnstile check, counts page views (Web Analytics; in the EU, the EEA, the UK and Switzerland only with consent), resolves DNS for the domain setup screenAll request traffic, as our host; our database; connected hostnames; request data for Turnstile; page views without identifiers
Polar Software, Inc.Merchant of record: checkout, payment, sales tax, receipts, refundsYour email address, account identifier, chosen pack and the page where you chose it, the terms version you accepted with its time, and your IP address (for the sales tax country); the payment details you give Polar directly
Plus Five Five, Inc. (Resend)Sends our emailYour email address and the content of each message, including the exit kit attachment
Google LLC (Web Risk)Checks destination URLs against lists of phishing and malware sitesThe destination URL of a code, with no account information
Google LLC (Public DNS)Backup resolver when we check a connected domain's DNS recordThe hostname you are connecting

We also disclose information when the law requires it (for example a subpoena or court order), to investigate abuse of the Service or a threat to anyone's safety, and to a successor if the Service changes hands, in which case this policy continues to apply. When we learn of apparent child sexual abuse material, child sex trafficking or online enticement of a minor, we report it to the National Center for Missing & Exploited Children (NCMEC), as federal law provides for.

Cookies

We set three cookies, all first-party: two the site needs to work, and one that remembers your choice about page counting.

CookiePurposeLifetime
gqr_sessionKeeps you signed in30 days, or until you sign out
gqr_flashCarries a one-time message (such as "Saved") to the next page60 seconds
gqr_consentRemembers whether you accepted or rejected page counting6 months

All three are HttpOnly and HTTPS-only. The redirect service at gtdqr.com and on connected domains sets no cookies. We use no advertising or social-media cookies. The only third-party scripts are Cloudflare's: Turnstile on the sign-in and report forms, and Cloudflare Web Analytics on public pages, which sets no cookie and, in the EU, the EEA, the UK and Switzerland, loads only after you accept it in the banner. Cloudflare may set its own security cookies when it challenges suspicious traffic.

Do Not Track. We do not collect personal information about your activities over time and across other websites, and no advertising or analytics company does so through our site, so our site does not respond differently to Do Not Track, Global Privacy Control or similar signals.

How long we keep information

InformationKept for
Account email, settings and the terms version you acceptedWhile the account exists
Sign-in tokens15 minutes, then deleted within a day
Sessions30 days, or until you sign out; expired sessions are deleted daily
Codes, designs, domainsUntil you delete them or the account
Scan records90 days; the all-time total stays with the code; records are deleted with the code
Destination history of codes1 year, including after the code or the account is deleted; longer for a blocked code, as evidence
Purchase recordsWhile the account exists, then seven years after the end of the year of purchase
Abuse reportsClosed reports 1 year, without the reporter's email; open reports at most 1 year
Record of support actions on your account or codes (what was done, when, by which of our staff)3 years
Payments that matched no account (the order identifier, the amount and the account reference the payment carried)1 year after we have handled them
Rate-limit counters (hashed)2 days
Payment webhook identifiers90 days
Cached last answer for a code, at our host's data centers7 days from the last scan
Operational logsUp to 7 days
Database backups (point-in-time restore at our host)30 days

Your choices and your rights

We answer requests and complaints within 30 days, verify requests by replying to the account's email address, accept requests from an authorized agent once we can confirm your permission, and never treat anyone differently for exercising a privacy right.

State privacy laws. Laws such as the California Consumer Privacy Act apply to businesses above certain size thresholds (for California in 2025 and 2026: more than $26,625,000 in revenue in the preceding year, or buying, selling or sharing the personal information of 100,000 or more consumers or households). We are below those thresholds today, so those laws may not apply to us yet; we honor the requests above for everyone regardless. Nevada residents: support@guaranteedqr.com is our designated request address for requests not to sell; we do not sell covered information.

Outside the United States. The Service is operated from the United States; your information is processed in the United States and wherever our host's network delivers it. Wherever you are, you may send us the requests above and we will honor them. Polar, as merchant of record, is responsible for the data it collects to process your payment and tax.

Children

The Service is for adults and businesses, and you must be 18 or older to create an account. It is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, email us and we will delete it.

Security

Sign-in tokens and sessions are stored only as hashes, cookies are HttpOnly and HTTPS-only, our pages use a strict Content Security Policy and refuse framing, destinations are screened before they go live and re-screened on a schedule, and admin access is limited to named addresses. No system is perfect: to report a security problem, see guaranteedqr.com/.well-known/security.txt or email security@guaranteedqr.com. If a breach affects your information, we will tell you as the law requires.

Changes

We may update this policy. We will post the new version here with a new effective date and, for material changes, email account holders before they take effect.

Contact

Orange Arc LLC
2108 N St, Ste N, Sacramento, CA 95816
support@guaranteedqr.com