Legal

Privacy

Last updated 6 October 2026

QR Island makes QR codes in your browser. Free codes never leave your device. This page explains the few cases where information does reach our server, what we do with it, how long we keep it and your rights.

  • No cookies for visitors, no ad trackers, no analytics companies.
  • When you buy, we keep your email address and an order record. Your code’s content, logo, island picture and island video are encrypted and deleted when the downloads end.
  • We count a few anonymous actions as daily totals, never who did them.

Who is responsible

QR Island is run by AVERKO AI, Bridgetown, Barbados. We are the data controller for the personal information described here under the Barbados Data Protection Act, 2019 and, where they apply, the EU and UK GDPR. For privacy questions, email support@qrisland.com or use the contact details at the bottom of this page.

Free codes and saved islands

Text, links, Wi‑Fi details, contacts and anything else you type into a free code are processed only in your browser. They are not sent to our server, to analytics or to advertisers (we use none of those). The free styled PNG, the free print sheet and the free screen-size island picture are also made in your browser and stay on your device.

Appearance preferences are remembered in this browser. The code you are making (a Wi‑Fi password too) and the choices and email you type in Your code are kept in this tab only, so a reload doesn’t lose them; closing the tab clears them. Choosing Save under Saved stores the island name, QR content, look and camera angle in this browser’s local storage. It is not encrypted and does not sync between devices. A saved Wi‑Fi code includes its password, so avoid saving secrets on shared devices. Purchases are remembered there too (the order reference and its private key), so you can download again. Clearing this site’s browser data removes everything saved.

Island packs

To make an Island pack, your browser sends our server the code’s content, style choices and the logo you upload, plus the email address you give for your order. We use them only to check that the code scans, take payment, produce your files and contact you about your order.

Your island pictures are rendered in your browser from the island view and backdrop you chose: one uploaded at checkout, from which we make the Large print and the Wide poster, and an upright one for the Poster, uploaded right after payment (or when you finish it from your purchase link). They are stored encrypted with your order and deleted when the downloads expire, like the rest of your files.

Your island video is made in your browser just after payment, after the Poster’s picture and any other sign styles, from the same island, and uploaded to your order with your private download key. It is stored encrypted and deleted with the rest of your files.

  • The content, logo, island picture and island video are encrypted at rest and automatically deleted when the downloads end: normally 90 days after payment, and for an Editable code when its year and grace period are over, if that is later. Unpaid or cancelled checkouts, and refunded orders, are deleted about a week after they close.
  • Our staff tools show order records, not your code’s content, logo, island picture or video (only whether a picture or video is stored).
  • Your purchase link works like a password: anyone with it can download the files until they expire. Its key travels in the part of the link that browsers don’t send to servers, so it never appears in our logs.

Editable codes

  • An Editable code’s forwarding address is stored as entered so our short link can redirect to it. It is visible to anyone who scans the code, and staff can see it to stop abuse.
  • We keep a history of forwarding-address changes (old address, new address and time) to look into abuse. After a code ends, we keep its short link, last forwarding address and history, so the same short link is never given to anyone else.
  • When someone scans an Editable code, we add one to that day’s total. We do not store their IP address, device, location or browser, and short-link visits are not written to our request logs. To avoid counting the same scan twice, the server briefly holds a scrambled form of the network address in memory only, under a key that is replaced every day.
  • Daily totals are kept for about 400 days.
  • We email the address from your receipt before each yearly renewal, when its forwarding address changes, and when we send you a new manage link.

Island sign packs

If you buy a sign pack, your browser sends pictures of your island drawn for the sign pieces and your sign’s wording, style and colour. Right after payment, after your Poster’s picture (or when you finish them from your purchase link), it also sends the pictures your pack’s other styles are drawn from. They are encrypted at rest with the rest of your order and deleted with it.

While you choose a sign pack, before you pay, your browser also sends the island with your code on it, the code’s content and the sign’s wording, so our server can test-print the island and show you where it scans. The pictures and the code’s content are read for that test and never stored. We keep only the result, with scrambled fingerprints of the pictures and the code, in memory for up to two hours, so your order can use the same result.

Usage counts

To see which features and worlds people use, the site counts a few anonymous actions, such as a visit (phone, tablet or desktop), choosing a world, choosing a code type, opening checkout or starting a checkout. We store daily totals only: no cookies, no identifiers, no IP address, no browser details and no link between one action and another. To stop anyone inflating the counts, the server keeps a scrambled form of the network address in memory for a short time; it is never stored or logged. We also count which kind of link brought a visit (for example “instagram”, from the link on our Instagram profile) as an anonymous daily total, and if you buy in that browser tab we note that one word on your order, with no cookies or tracking. If your browser sends Global Privacy Control or Do Not Track, nothing is counted at all and no such word is noted.

Payments

Our orders are sold through Paddle.com, our online reseller and merchant of record. Paddle takes the payment, works out and collects tax, issues receipts, runs Editable-code subscriptions and handles payment questions and refunds. For the payment details you give in its checkout (such as your card, name, country and postcode), Paddle is an independent data controller, and Paddle’s privacy policy applies.

  • We send Paddle your email address, the order reference, what you are buying and its price. Paddle tells us whether the payment went through, with its transaction and subscription numbers, the amount, and your country for tax. We never see or store your card number.
  • Paddle’s checkout script (Paddle.js) loads only when you start a checkout, never when you just visit or make free codes. Paddle’s checkout runs its own scripts and cookies under Paddle’s policies.
  • An Editable code’s subscription is managed from its manage link: turning auto-renew off or on asks Paddle to change the subscription, and a new card is entered in Paddle’s checkout, never on our pages. Paddle emails your receipts.

Email

We email download links for purchases, and renewal reminders, change notices and new manage links for Editable codes. Paddle emails your receipts and any problem with a payment. Our emails are sent through an email delivery provider that sends our emails on our behalf. We do not send marketing email, and we never sell or share your address for marketing.

Support messages

If you write to us with the form on our contact page, we receive the topic, your message, your email address and, if you give it, your order number, and use them only to answer you and fix the problem. Technical details are optional: if you leave them ticked, the message also carries your browser’s name and version, your device type, your window size, the page it is about and, if you have used the studio on this device, its quality setting and graphics card. The form shows exactly what is included before you send. To stop spam, we also store a scrambled form of your network address that changes every day, never the address itself. Support messages are kept for 12 months and then deleted.

Server logs and cookies

Our server keeps short technical logs (time, page requested and response status) to keep the service running. They don’t include QR content, email addresses, IP addresses or payment details. Server logs rotate automatically by size and are normally kept for no more than a few weeks. We set no cookies for visitors. The staff admin area uses one essential sign-in cookie. The site loads no scripts, fonts or trackers from other companies, except Paddle’s checkout once you choose to pay (see Payments).

The site is delivered through Cloudflare’s network, which passes your requests on to our server and keeps copies of our public files (pictures, scripts and styles) near you so pages load faster. To do that, Cloudflare handles your network address and the address of each page you ask for, and protects the site from attacks. We have turned off the Cloudflare features that add scripts or cookies to our pages.

Why we use your information

  • To provide what you buy (make and deliver files, run an Editable code, send receipts, reminders and notices): this is needed to perform our contract with you.
  • To keep accounting and tax records: this is a legal obligation.
  • To keep the service safe (checking destinations, change notices, investigating abuse and fraud, backups): this is in our legitimate interests and those of the people who scan codes.

Anonymous daily counts don’t identify anyone. We don’t sell personal information, use it for advertising or profiling, or make automated decisions about you.

Who we share it with

We use a few service providers, who may only use your information to provide their service to us:

  • Google Cloud hosts our server, database, file storage and backups in us-east1 (South Carolina, United States).
  • Paddle.com sells our products as merchant of record and processes payments, as an independent controller for payment data (see Payments).
  • An email delivery provider sends our emails on our behalf.
  • Off-site backup copies are kept in Google Cloud, in the United States.

We may also share information when the law requires it, or to protect people from fraud or abuse (for example, reporting a phishing link). If the business is ever sold, the new owner would have to keep these promises.

Where your information is stored

Our server and backups are in the United States, and our providers may process data in other countries. That means personal information leaves Barbados (and, for visitors from the EU or UK, leaves those places). We rely on our providers’ contractual safeguards, such as Google Cloud’s data processing terms and standard contractual clauses, to protect it.

How long we keep it

  • Free codes and saved islands: only in your browser, until you clear it.
  • Island pack content, logos, island pictures, island videos and sign pictures: until the downloads end (see above). Encrypted backup copies roll off within 14 days after that.
  • Order records (reference, what you bought, amount, status, dates, email): for 7 years, for tax and accounting.
  • Editable codes: the short link, last forwarding address and change history are kept after the code ends, as explained above. Daily scan totals are kept for about 400 days.
  • Anonymous usage counts: about 400 days.
  • Support messages from our contact form: 12 months, then deleted automatically.
  • Emails you send us: as long as we need them to help you, and up to 2 years.

Security

The whole site uses HTTPS. Code content, logos, island and sign pictures, island videos and download keys are encrypted at rest. Staff sign-in needs two-factor authentication, and the database is backed up every night. No system is perfect. If a breach puts your information at risk, we will tell the Data Protection Commissioner and, where required, you, as the law requires.

Your rights

Under the Barbados Data Protection Act (and the GDPR, if you are in the EU or UK) you can ask us to:

  • tell you what personal information we hold about you and give you a copy;
  • correct it;
  • delete it (we can delete Island pack files early, but we keep the order records the law requires);
  • restrict or object to how we use it;
  • give it to you in a portable format.

Write to us from the email address you used to buy, so we can check it’s you. We will reply within 30 days. If you are unhappy with our answer, you can complain to the Data Protection Commissioner of Barbados, or to the data protection authority where you live.

Children

QR Island isn’t aimed at children, and we don’t knowingly collect personal information from anyone under 16. The free generator needs no personal information at all. If you think a child has given us their email address, contact us and we will delete it.

What a code reveals

Anyone who scans, photographs or receives a QR code can read its content. Use Get QR code or a download for the most reliable scanning.

Changes to this policy

We will update the date at the top when this policy changes, and email owners of Editable codes about important changes.

Contact

QR Island is run by AVERKO AI, Barbados registered business name No. 92961, Bridgetown, Barbados.

Email: support@qrisland.com

We reply within 2 business days. You can also use our contact page.

QR Island is built with Three.js and qrcode. Regional worlds are artistic interpretations.