KuikCode (“we”, “us”) operates kuikcode.com (this site and the KuikCode app), kuikco.de (the short links our QR codes encode), and kuik.page (hosted sites). This policy explains what we collect, why, and the choices you have. The short version: we collect only what the product needs to work, we never store raw IP addresses from scans, and we don't sell personal data — full stop.
This policy covers two different groups of people, and we describe each separately: account holders (you sign up and create QR codes) and scan visitors (you scanned a QR code someone made with KuikCode).
1. What we collect from account holders
- Account details — your email, name, and, if you sign in with Google, GitHub, or Facebook, the basic profile those providers share (name, email, avatar). We never see your passwords for those services.
- Waitlist email — if you join the waitlist, just your email address and which page you signed up from.
- Content you upload — logos, images, PDFs, and ZIP files for hosted sites, plus the QR designs and destination settings you create.
- Product usage — how you use the app (pages visited, features used), collected through our own analytics to improve the product. This is internal telemetry, not advertising tracking.
KuikCode is free during early access, so we collect no payment information today. When paid plans launch, payment details will go directly to a payment processor and we will update this policy first.
2. What we collect when someone scans a QR code
When a KuikCode QR code is scanned, our redirect service records a scan event so the code's owner can see how their campaign performs. A scan event contains:
- The time of the scan and which code was scanned.
- Approximate location derived from the network address — city, region, and country. This is the default for every scan.
- Precise location, only if you allow it— some codes have precise scan locations enabled by their owner. Scanning one shows a consent screen first: your exact coordinates are captured only if you tap “Share location” andaccept your browser's permission prompt. Declining never blocks the link. Precise coordinates are shown to the code's owner in their scan analytics and are used for nothing else.
- Device basics — device type (mobile/desktop), operating system, browser, language, and timezone.
- Which destination the code sent the visitor to.
We never store raw IP addresses. The IP is used transiently to derive the approximate location and a one-way hashed identifier for counting unique visitors, then discarded. Scan events carry no name, contact detail, or network address — neither we nor the code's owner can identify who scanned.
Scanning a KuikCode never sets a cookie. We don't build profiles of scan visitors, don't track them across sites, and don't use scan data for advertising.
Note that the destination a code points to (a website, a hosted site, a PDF) is chosen by the code's owner. What that destination collects is governed by the owner's own privacy practices, not this policy.
3. How we use this information
- To provide the service — routing scans, serving hosted sites, showing analytics to code owners.
- To send transactional email — waitlist confirmation, account and product notices. Marketing email is opt-in and every message has an unsubscribe link.
- To keep the service safe — rate limiting, abuse and fraud prevention. Network addresses are used transiently for this and not retained.
- To improve the product, using our own internal usage analytics.
Where GDPR applies, our legal bases are performance of a contract (running the service for you), legitimate interests (security, product improvement, analytics for code owners), and consent (marketing email).
4. Cookies
The KuikCode app uses essential cookies to keep you signed in. This marketing site and the app use our own product analytics. We use no advertising or cross-site tracking cookies anywhere, and — worth repeating — the scan redirect sets no cookies at all.
5. Who processes data for us
We share personal data only with the infrastructure providers that run KuikCode — cloud hosting, database, content delivery and storage, scan-analytics processing, rate limiting, transactional email, background jobs, and internal product analytics — under agreements that limit them to processing it for us. If you sign in with Google, GitHub, or Facebook, those providers are involved in sign-in only. A full list of subprocessors is available on request at hello@kuikcode.com.
Beyond these providers, we disclose personal data only if required by law or to protect the rights and safety of KuikCode and its users. We do not sell or rent personal data, and we do not share it with ad networks or data brokers.
6. How long we keep it
- Account data — for as long as your account exists; deleted when you delete your account or ask us to.
- Content you upload — until you delete it or your account.
- Scan analytics — for as long as the owning account is active, so owners keep their campaign history.
- Waitlist emails — until you get access or ask to be removed.
7. Your rights
Wherever you live, and specifically under GDPR and CCPA where they apply, you can ask us to access, correct, export, or delete the personal data we hold about you, object to or restrict processing, and withdraw consent. We will never treat you differently for exercising these rights.
During early access, requests are handled personally: email hello@kuikcode.com and we'll respond within 30 days. Self-serve export and deletion are coming to the app before public launch.
8. Security
All traffic is encrypted in transit, credentials are hashed, secrets are stored outside the codebase, and access to production data is limited to what operating the service requires. No system is perfectly secure, but the scan-data design above — hashing at ingestion, no raw IPs at rest — means the most sensitive thing we could leak simply isn't stored.
9. International transfers
Our infrastructure is primarily in the United States, with content delivery distributed globally through Cloudflare. Where data moves across borders from the EU/UK, our providers rely on recognized transfer mechanisms such as Standard Contractual Clauses.
10. Children
KuikCode is not directed to children under 16 and we don't knowingly collect their personal data. If you believe a child has provided us data, contact us and we'll delete it.
11. Changes to this policy
We'll update this page as the product evolves — especially at public launch, when paid plans and self-serve data tools arrive. Material changes will be announced by email to account holders. The date at the top always reflects the latest revision.