Legal
Privacy Policy
What Hostelastic Technologies LLP collects when you use PixelQode, why we hold it, who else sees it, and how to get it removed.
Last updated Aug 9, 2026 · Hostelastic Technologies LLP
Who is responsible
Hostelastic Technologies LLP, 78 Vidya Sagar Road, Kolkata, West Bengal 700077 (LLPIN ACL-6671), is the controller of the personal data described here. For privacy questions or requests, email privacy@pixelqode.com.
What we collect
- Account data — your name, email address, and company name if given. Your password is held by our managed authentication provider, hashed; it never reaches our own code and we cannot recover it. If you sign in with Google there is no password at all.
- Workspace content — the QR codes you create: their names, destinations, folder structure, design settings, and the encoded content of static codes. This is your data and may itself contain personal data if you choose to encode it, for example in a vCard code.
- Your QR provider API key — held so the service can act on your behalf against your provider account. It is stored on the server only, in a file readable by the service account alone, and is never sent to a browser.
- Scan counts — for dynamic codes we record, once a day, the total number of scans each code has received. These are aggregate numbers per code. We do not receive or store the IP address, location, device or identity of anyone who scans your codes.
- Billing data — your plan, billing cycle and subscription identifiers. Card details are handled entirely by our payment provider and never reach our servers.
- Support messages — anything you send us through the support form or by email.
What we do not collect
We do not run advertising or third-party analytics on this site, we do not sell or share personal data with data brokers, and we do not build profiles of the people who scan your codes. There is no tracking pixel on these pages.
Why we hold it
- To provide the service you have asked for — creating codes, resolving them, and reporting on them. This is performance of our contract with you.
- To take payment and meet tax and accounting obligations. This is a legal obligation.
- To keep the service secure and investigate abuse. This is our legitimate interest in running a service that is not used for fraud.
- To answer your support requests, which is again performance of our contract.
Who else processes it
We use a small number of processors, each with access only to what their function requires:
- ME-QR — our QR service provider. Dynamic codes are created on and resolve through their infrastructure, so the destination, the code’s name and its design are shared with them. Static codes are generated by us and are never sent to them.
- Our payment processor — merchant of record for subscriptions. They receive your billing details directly; we receive only your plan, cycle and subscription identifiers back. They are named on the checkout page and on your receipt, and we will name them here once the merchant account is live.
- Cloudflare, Inc. — hosting and network. The application runs on Cloudflare Workers, so every request to this site passes through their network, which also provides TLS and DDoS protection. Cloudflare holds SOC 2 Type II and ISO 27001 certification.
- Neon Inc. (on Amazon Web Services) — the managed Postgres database where your account, workspace, folders and scan history are stored, and the managed authentication service that holds your password. Data is encrypted at rest and in transit. Both Neon and AWS hold SOC 2 Type II and ISO 27001 certification.
We will also disclose data where we are legally required to, and we will tell you when we are permitted to do so.
How long we keep it
- Account and workspace data: for as long as your account is open, and for 30 days after closure so it can be restored if you change your mind.
- Daily scan-count snapshots: rolling 120 days, then discarded.
- Billing records: as long as tax law requires us to keep them, typically several years.
- Support correspondence: two years.
Your rights
You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, or to receive it in a portable format. Email privacy@pixelqode.com and we will respond within 30 days. We will ask you to verify your identity first, so that we do not hand your data to someone else.
One thing we cannot undo: a dynamic QR code that has already been printed and distributed will keep being scanned by the public. Closing your account stops us processing your data, but it does not recall codes already in the world.
Where your data is held
Data is processed in India and by the providers listed above, some of whom operate outside it. Where data is transferred internationally we rely on the safeguards our providers have in place, including standard contractual clauses where applicable.
Security
Passwords are held and hashed by our managed authentication provider rather than by us. Provider API keys are stored server-side, never sent to the browser, and never included in a page; QR downloads are proxied through our server so a key is never needed client-side. All traffic is served over TLS, and the database is encrypted at rest and in transit. Access to production data is limited to those who need it to operate the service.
If a breach occurs that is likely to affect your rights, we will tell you and the relevant authority without undue delay.
Changes
If we change this policy materially, we will email you before the change takes effect. The date at the top of this page always reflects the current version.
Questions about this page? Email support@pixelqode.com.