Privacy policy

Last updated: September 22, 2026

This policy covers the QR Code Alligator tracking service: the dashboard at track.qrcode-alligator.com and the short links at qrgo.page. The QR generator at qrcode-alligator.com has its own privacy policy. The service is operated by QR Code Alligator, the data controller for everything described here. Questions and requests: [email protected].

When someone scans a tracked code

Each scan of a qrgo.page link records the short code, the time, the country, region and city (derived by Cloudflare from the network address), the device type, operating system and browser (derived from the browser’s user agent), and the host name of the referring page if the browser sends one.

The IP address is never stored. To count unique visitors without a cookie, the IP address and user agent are turned into a one-way hash with a key that changes every day (UTC). Once the day is over, nobody — including us — can work out which address produced a hash.

qrgo.page sets no cookies and loads no scripts or third-party resources. A scan is answered with a redirect, or with a warning page if the link has been flagged.

The legal basis is legitimate interest: ours, and the link owner’s, in knowing how a printed code is used. City is the finest location we record.

When you use the dashboard

Signing in needs only an email address. We send a single-use sign-in link through Resend, our email provider, and store your email address and when it was confirmed. You can instead continue with Google: Google then tells us your account’s email address and a fixed account identifier, which we store to recognise you next time. We receive nothing else from your Google account — no name, photo or contacts.

After you sign in we set one cookie, qrt_session, which keeps you signed in for up to 30 days. It is strictly necessary and is used for nothing else. Continuing with Google also sets __Host-qrt_oauth for 10 minutes; it protects the trip to Google and back and is deleted when you return.

The dashboard also uses Google Analytics to see which parts of it are used. It sets its own cookies on qrcode-alligator.com, shared with the QR generator there, so a visit that starts on the generator and continues here is understood as one visit. Visitors in the EU, the EEA and the UK are shown a notice about it. Scans of qrgo.page links are never included — they are counted without cookies, as described above.

We store the links you create with their destination history, your API keys (as a hash only — a key is shown to you once), and daily scan totals for your links.

Creating a link without an account is protected by Cloudflare Turnstile, which checks that the request comes from a person.

Abuse prevention

Every destination address is checked against Google Safe Browsing when a link is created or changed, and periodically afterwards. This sends the destination address to Google.

To enforce usage limits and investigate abuse, we keep the same daily-rotating IP hash with rate counters, with each link created, and with each change to a link — a new destination, or pausing and resuming it. When the change is made with an API key, we record which key it was.

If you report a link, we store the report, and your email address only if you choose to give it.

How long we keep data

Individual scan records: up to 3 months. Daily totals per link: for as long as the link exists.

Rate counters: 2 days. Unused sign-in links: 1 day. A daily sweep does the deleting, so a row can outlive those by up to a day.

A link created without an account expires after 7 days unless it is claimed; 30 days later its destination, IP hashes and statistics are deleted.

When you delete a link, its destination, statistics and IP hashes are deleted at once. The record of which destinations the code once pointed to is kept without any connection to you, so the code is never reused and abuse can still be investigated. Scan records already written expire with the 3-month window; they contain the short code, not your identity.

Your rights

You can view, change and delete your links in the dashboard at any time.

To delete your account and email address, or to use any other right under the GDPR or similar laws (access, correction, objection), email [email protected]. We reply within 30 days.

Service providers

Cloudflare (hosting, storage, scan analytics, Turnstile), Resend (sign-in emails) and Google (Safe Browsing checks of destination addresses, Google Analytics in the dashboard, and sign-in with Google if you choose it) process data on our behalf. We do not sell data and do not use it for advertising.

Changes

When this policy changes, the date at the top changes with it.