Privacy Policy for QR Security

Last Updated: January 2026

Introduction

This Privacy Policy describes how QR Security (“we”, “our”, or “the App”) collects, uses, and shares your personal information when you use our mobile application.

Information We Collect

Information You Provide

  • Account Information: Email address, full name, phone number
  • Profile Information: Building name, unit number, role within your residence
  • Visitor Information: When creating QR codes, you may provide visitor details including name, email, phone number, identification number, and vehicle information
  • QR Code Data: Information embedded in QR codes for entry management

Information Collected Automatically

  • Usage Data: How you interact with the App, features you use, time spent
  • Device Information: Device type, operating system version, unique device identifiers
  • Log Data: IP address, access times, app errors and crashes
  • Camera Data: When scanning QR codes, camera access is temporary and images are not stored

How We Use Your Information

We use the collected information for:

  • Service Provision: To provide and maintain our entry management services
  • Authentication: To verify your identity and secure your account
  • QR Code Generation: To create and manage visitor access QR codes
  • Entry Validation: To scan and validate QR codes for security purposes
  • Communication: To send you service-related notifications and updates
  • Improvement: To improve app functionality and user experience
  • Security: To detect and prevent fraud, abuse, and security incidents
  • Legal Compliance: To comply with applicable laws and regulations

Data Storage and Security

Cloud Storage

We use Firebase, a Google Cloud Platform service, to store and process your data:

  • Firestore Database: Stores user profiles, QR codes, and entry logs
  • Firebase Authentication: Manages user authentication securely
  • Data Encryption: All data is encrypted in transit (TLS/SSL) and at rest

Data Location

Your data is stored on Firebase servers, which may be located in various regions. Firebase complies with GDPR and other international privacy standards.

Security Measures

  • End-to-end encryption for data transmission
  • Secure authentication with industry-standard protocols
  • Regular security audits and updates
  • Role-based access control to protect sensitive information
  • Automatic session expiration after inactivity

Third-Party Services

We integrate with the following third-party services:

Firebase (Google)

  • Purpose: Authentication, database, analytics
  • Data Shared: Email, name, usage data
  • Privacy Policy: https://policies.google.com/privacy

Google Sign-In

  • Purpose: Alternative authentication method
  • Data Shared: Email, name, profile picture (if chosen)
  • Privacy Policy: https://policies.google.com/privacy

Apple Sign-In

  • Purpose: Alternative authentication method
  • Data Shared: Email (or Apple relay email), name
  • Privacy Policy: https://www.apple.com/legal/privacy/

Data Sharing and Disclosure

We do NOT sell your personal information. We may share your information in the following circumstances:

Within Your Residence

  • Information is shared with other users in your residence based on their role and permissions
  • Admins can view user lists for their residence
  • Security personnel can view visitor information when scanning QR codes

Service Providers

  • Firebase/Google for cloud infrastructure and services
  • Only for purposes of providing and improving our services

We may disclose your information if required by law or in response to valid requests by public authorities (e.g., court orders, government requests).

Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity.

Your Rights and Choices

Access and Update

  • You can access and update your profile information in the app settings
  • Request a copy of your personal data by contacting us

Data Deletion

  • You can request deletion of your account and associated data
  • Some information may be retained for legal or legitimate business purposes
  • Contact us at [email protected] to request deletion

Opt-Out Options

  • Email Communications: Unsubscribe from promotional emails (service emails are required)
  • Analytics: Disable analytics in app settings (if implemented)
  • Location Services: Deny location permissions in device settings (if feature is used)

Our app does not use cookies. However, Firebase services may use local storage for authentication tokens and app functionality.

Data Retention

  • Active Accounts: We retain your data while your account is active
  • Deleted Accounts: Data is deleted within 30 days of account deletion request
  • Legal Requirements: Some data may be retained longer if required by law
  • QR Codes: Historical QR codes and entry logs may be retained for audit purposes

Children’s Privacy

QR Security is not intended for children under 13 years of age. We do not knowingly collect personal information from children. If we discover that a child under 13 has provided us with personal information, we will delete it immediately.

International Data Transfers

Your information may be transferred to and maintained on servers located outside of your country, where data protection laws may differ. By using our App, you consent to this transfer.

GDPR Compliance (for EU Users)

If you are in the European Economic Area (EEA), you have additional rights under GDPR:

  • Right to Access: Request copies of your personal data
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure: Request deletion of your data (“right to be forgotten”)
  • Right to Restrict Processing: Request limitation of data processing
  • Right to Data Portability: Receive your data in a structured format
  • Right to Object: Object to processing of your data
  • Right to Withdraw Consent: Withdraw consent at any time

Legal Basis for Processing: We process your data based on:

  • Consent when you create an account
  • Contract performance when providing services
  • Legitimate interests in operating and improving our service
  • Legal obligations for compliance

To exercise these rights, contact us at [email protected]

California Privacy Rights (CCPA)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: What personal information we collect and how we use it
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: Opt-out of sale of personal information (we do not sell data)
  • Right to Non-Discrimination: Equal service regardless of exercising privacy rights

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the new Privacy Policy in the app
  • Updating the “Last Updated” date
  • Sending an email notification (for significant changes)

Your continued use of the App after changes constitutes acceptance of the updated policy.

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data:

Email: [email protected] Address: Caracas, Venezuela

By using QR Security, you consent to this Privacy Policy and agree to its terms.


Summary of Key Points

  • We collect information you provide and usage data
  • We use Firebase (Google Cloud) for secure data storage
  • We do not sell your personal information
  • You can request access, correction, or deletion of your data
  • We comply with GDPR, CCPA, and other privacy regulations
  • Data is encrypted and secured with industry-standard practices
  • You can contact us to exercise your privacy rights

Version: 1.0 Effective Date: January 2026 App Version: 1.0.0