Privacy Policy
Last updated: 9 June 2026
1. Who we are
LinQR Digital Link Solutions provides QR code management, review collection, and payment link services for UK businesses. We are the data controller for personal data collected through this website.
Contact us at: linqrsupport@gmail.com
2. What data we collect
We collect the following categories of personal data:
- Enquiry data: When you submit a free business enquiry, we collect your name, business name, email address, phone number (if provided), and details about your requirements.
- Review data: When customers use a LinQR review page, we collect only the review text they choose to submit. No account creation is required. When visitors rate LinQR directly at linqr.dev/reviews, we collect the review text, star rating, name (if provided), and service type selected.
- Usage data: We collect anonymised data about how our platform is used, including page views and QR code scan counts (linked only to a scan timestamp and, where relevant, the staff member whose code was scanned). We do not log or store IP addresses, device identifiers, or precise/derived location data anywhere in this pipeline, and a guest scanning a code at one venue is never linked to the same guest scanning a code at a different venue.
- Business configuration: Business clients store staff names and review platform URLs in our system. This data is used solely to provide the LinQR service.
- Payment data: Where clients purchase a design service, payments are processed securely by Stripe. LinQR does not store card details — only the outcome of the transaction (paid or unpaid) and a Stripe-issued reference.
3. How we use your data
We use your personal data for the following purposes:
- To respond to your business enquiry and provide our services
- To send service-related communications (e.g. your enquiry confirmation)
- To improve our platform and user experience
- To comply with legal obligations
We will not use your data for unsolicited marketing without your explicit consent.
4. Legal basis for processing
We process your personal data under the following lawful bases (UK GDPR Art. 6):
- Contract: To fulfil our obligations as a service provider to business clients.
- Legitimate interests: To respond to enquiries and improve our services.
- Consent: For any marketing communications (you may withdraw consent at any time).
5. Data sharing
We share personal data only with the following third parties, solely to operate our services:
- Resend (resend.com): Our transactional email provider, used to send enquiry notifications. Resend processes email data on our behalf.
- Neon (neon.tech): Our database provider, used to store enquiry and business data securely. Neon is SOC 2 Type 2 certified.
- Stripe (stripe.com): Our payment processor, used when clients purchase a design or update service. Stripe processes payment card data directly and is PCI DSS Level 1 certified. LinQR does not receive or store card details.
- Vercel: Our hosting provider. Data is processed in accordance with their privacy terms.
We do not sell, rent, or trade personal data with third parties.
6. Data retention
We retain personal data only for as long as necessary:
- Enquiry data: Retained for 2 years from submission, or until you request deletion.
- Business client data: Retained for the duration of the service agreement plus 1 year.
- Anonymised analytics: Scan and review-event records contain no personal data and are retained indefinitely in aggregate. Individual scan-timestamp records are periodically compacted into aggregated counts once older than 90 days, reducing granular data without affecting the anonymised totals shown to business clients.
7. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data ("right to be forgotten")
- Restrict our processing of your data
- Data portability — receive your data in a machine-readable format
- Object to processing based on legitimate interests
- Withdraw consent at any time where processing is consent-based
To exercise any of these rights, email us at linqrsupport@gmail.com. We will respond within 30 days.
You also have the right to lodge a complaint with the ICO (Information Commissioner's Office) at ico.org.uk.
8. Cookies & session storage
We use one strictly necessary cookie, linqr-portal, set only when a business client logs in to their LinQR management portal. It stores a signed session token so you stay logged in, expires after 7 days, and is not used for tracking or advertising. Because it is essential to providing the service you've requested, it does not require consent under PECR.
We also use browser-only session/local storage (never transmitted to our servers) for temporary UI state such as dismissed banners and admin login state. We do not use tracking or advertising cookies.
Guests scanning a QR code and viewing a public review page are not issued any cookie.
If we introduce analytics or marketing cookies in future, we will update this policy and request your consent before placing them.
9. Security
We take appropriate technical and organisational measures to protect your personal data, including:
- HTTPS encryption for all data in transit
- Encrypted database storage via Neon
- Access controls limiting who can view personal data
No method of transmission over the internet is 100% secure. We will notify you of any data breach that affects your rights and freedoms within 72 hours as required by law.
10. International transfers
Our database provider (Neon) may process data in the United States. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) where required under UK GDPR.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify business clients of material changes by email. The "Last updated" date at the top of this page reflects the most recent revision.
12. Contact us
If you have any questions about this Privacy Policy or how we handle your data: