Skip to content
OneKiteSign inStart free

Privacy Policy

Last updated 14 August 2026

OneKite is a QR marketing platform. This policy explains what we collect, why we collect it, and what you can do about it. We have tried to write it in plain language rather than in the language of a form.

Who we are

OneKite is the data controller for the information described here. You can reach us about anything in this policy at [email protected].

What we collect from you

  • Account details — your email address, your name if you give one, and a hashed password. We never store your password itself; it is hashed with Argon2id and cannot be reversed.
  • Content you create — your QR codes, their destinations and design, and your Studio pages.
  • Billing records — your plan, and the amount and status of payments. Card details are handled by our payment provider and never reach our servers.
  • Sign-in with Google — if you use it, we receive your email address and name from Google. We do not receive or store your Google password.

What we collect when someone scans a code

Scanning a OneKite QR code, or visiting a Page, records an analytics event. This is how the person who made the code sees how it is performing. It is deliberately built to avoid identifying the person scanning.

  • No cookies are set on scanners. — Scanning a code places nothing on your device.
  • No IP address is stored. — The IP address is used to derive a one-way hash and is then discarded. The hash is salted with a secret that rotates every day, so the same device produces a different value tomorrow and the values cannot be linked over time or reversed back to an address.
  • Approximate location — country, and where available region and city, as reported by our network provider. Never a precise location.
  • Device type and browser — for example “iPhone, Safari”, derived from the user-agent your browser sends.
  • Referrer — the page a visit came from, when the browser provides one.

The owner of a QR code sees aggregate statistics — totals, trends, countries, device types. They cannot see who you are, and neither can we.

Cookies

OneKite sets three cookies, and all three are strictly necessary for the service to function: one holds your sign-in session, one holds a short-lived value that protects the Google sign-in flow, and one holds an administrator session for our own staff. All are HTTP-only, meaning scripts cannot read them.

We use no advertising cookies, no tracking pixels, and no third-party analytics. Because we set nothing that is not strictly necessary, there is no consent banner to click — and nothing you would need to opt out of.

Why we are allowed to hold it

  • To provide the service you asked for — your account, your codes, your pages. Without this we have no product to give you.
  • Our legitimate interest — scan analytics, which is the point of the product, and security measures such as rate limiting and abuse prevention.
  • Legal obligation — keeping records of payments for the period tax law requires.

Who else sees it

We do not sell your data, and we do not share it for advertising. We use a small number of providers to run the service: hosting and databases, a network and security provider that sits in front of our servers, an email provider for verification and password-reset messages, and a payment provider. Each receives only what it needs to do its job.

One of these is worth naming, because it sees something you typed rather than something about your account. When you save or change a QR code’s destination, we send that address to Google Safe Browsing to check whether it is a known phishing or malware site. We do this because every OneKite code resolves through one shared domain: a handful of codes pointing at harmful pages would get that domain flagged in browsers, and every printed code — including yours — would stop working. The check happens when you save, never when somebody scans, so the destination is sent once rather than on every scan.

How long we keep it

  • Your account and content — until you delete them. Deletion is immediate and permanent.
  • Individual scan records — one year, after which they are removed.
  • Daily scan totals — kept for as long as the QR code exists, so your historical charts do not disappear. These contain no visitor identifiers at all.
  • Payment records — for as long as tax law requires us to keep them.

Your rights

If you are in the UK, EU, or another region with comparable law, you have the right to access your data, correct it, delete it, take it elsewhere, and object to how we use it. Two of these are built into the product and need no request:

  • Export — download everything we hold about your account as a single file from your settings page.
  • Deletion — erase your account and all its content from the same page. This deletes your QR codes, so anything already printed will stop working.
  • One exception to deletion: — records of payments you have made are kept, because tax law requires us to keep them. They are detached from your account first — what remains is an amount, a date and a payment reference, with nothing identifying you.

For anything else, email [email protected]. If you are not satisfied with our response you can complain to your local data protection authority.

Which language version applies

This policy is published in English and Hindi. The two are intended to say the same thing. If they ever differ, the English version is the one that applies — a translation should not quietly change what we have committed to.

Changes

If we change this policy in a way that materially affects you, we will tell you by email before it takes effect. The date at the top always reflects the current version.