Legal
Acceptable Use Policy
A QR code hides its destination until someone has already committed to opening it. That makes this policy more important here than on most services, and we enforce it.
Last updated Aug 9, 2026 · Hostelastic Technologies LLP
Why this policy is strict
Nobody can read a QR code with their eyes. A person scanning one has no way to judge where it goes before they arrive, which makes QR codes an unusually effective delivery mechanism for fraud. We take that seriously: abuse reports are acted on quickly, and we would rather lose a paying customer than host a code that empties someone’s bank account.
You must not
- Point a code at malware, ransomware, spyware, or any file intended to compromise a device.
- Run phishing of any kind — pages impersonating a bank, a payment provider, a government service, a courier, an employer, or us.
- Impersonate another business or person, or use a brand, logo or name you have no right to use.
- Place codes over other organisations’ codes — on parking meters, restaurant tables, payment terminals, invoices or posters — to intercept payments or credentials. This is the most common form of QR fraud and it is a permanent ban.
- Encode content that is illegal where it will be scanned, including child sexual abuse material, content inciting violence or hatred, or material infringing someone else’s intellectual property.
- Operate cryptocurrency giveaways, advance-fee schemes, fake investment offers, or other financial scams.
- Send unsolicited bulk messaging, or point codes at pages that harvest contact details for it.
- Deliberately overload, probe or reverse-engineer our systems or our provider’s, or attempt to reach another customer’s workspace.
- Resell raw access to the underlying QR API as though it were your own, without adding a service of your own on top.
Adult and regulated content
Legal adult content, gambling, alcohol, and similar regulated categories are permitted where they are lawful in the places the code is distributed and where you hold the licences required. Tell us at sign-up if this is your use case so we can confirm it is workable rather than discovering it during an abuse review.
What we do about breaches
Where a code is being used for fraud or to distribute malware, we disable it immediately and without notice, and we may suspend the account. For everything else we contact you first, explain the problem and give you a reasonable opportunity to fix it.
Because dynamic codes can be repointed after printing, disabling a destination does not require anyone to recall physical material — the code simply stops resolving to the offending page.
Accounts closed for fraud or malware are not refunded, and we report criminal activity to the relevant authorities.
Reporting abuse
If you have found a PixelQode code being used for fraud, email support@pixelqode.com with the short link or a photograph of the code. You do not need an account to report one, and we investigate reports from the public the same way we investigate our own detections.
Questions about this page? Email support@pixelqode.com.