Privacy Policy
This Privacy Policy describes how Elevate Hub Agency LLC ("we", "us") collects, uses and protects information when you use QR by Elevate Links (the "Service"). We are committed to processing only what we need to operate the Service.
1. Information we collect
Account information you provide: name, email, profile photo (optional). Content you create: QR codes, destinations, custom landing pages, comments. Scan metadata: timestamp, approximate location (city/country), device type, OS, browser. Hashed IP address (SHA-256 with daily salt) for unique-visitor counting only.
2. How we use information
To provide and improve the Service, authenticate you, deliver redirects from your QR codes, generate analytics, process payments via Stripe, send transactional emails (account confirmation, billing receipts), respond to support requests, and measure the effectiveness of our advertising. We never sell your personal data. We share a limited set of data with Meta (Facebook) and Google for analytics and advertising measurement — see sections 4 and 12.
3. Third-party services
We use: Supabase (database + auth) hosted in EU; Vercel (hosting + CDN); Stripe (payments — they store card details, we never see them); Google Cloud (Sign-in with Google flow only); Google Analytics (traffic analytics on marketing pages); Meta Platforms / Facebook (advertising measurement via the Meta Pixel and Conversions API); Cloudflare Turnstile (bot protection); SendGrid or similar (transactional email). Each provider is contractually bound to GDPR-equivalent protections.
4. Cookies and storage
We use strictly necessary cookies for authentication (session token from Supabase) and a small set of preferences (theme, language) stored in localStorage. On our marketing pages only, and only after you accept the cookie banner, we use analytics and advertising cookies from Google Analytics and the Meta (Facebook) Pixel to measure traffic and ad performance. You can decline them and the Service still works fully, and you can clear cookies anytime from your browser settings. See our Cookie Policy for the full list.
5. Your rights
Under GDPR (EU) and similar regulations, you have the right to access, correct, export and delete your personal data. You can do most of this directly from /dashboard/account. For data export or deletion requests beyond what the UI offers, email us at elevatehuboficial@gmail.com — we respond within 30 days.
6. Data retention
Active accounts: we keep your data for as long as your account is open. Deleted accounts: data is removed within 30 days, except backups (additional 30 days) and information required by law (tax records: 7 years). Scan events are retained according to your plan retention (Free: 0d, Pro: 180d, Team: 365d).
7. Security
All data in transit is encrypted with TLS 1.3. Passwords are hashed with bcrypt. Service tokens are stored only as HTTP-only cookies. We run security audits and dependency scans on every deploy. If a breach affects you, we notify you within 72 hours as required by GDPR.
8. Children
The Service is not directed to children under 16. We do not knowingly collect data from children. If you become aware that a minor has provided us with personal data, please contact us and we will delete it.
9. Changes to this policy
We will notify you of material changes via email at least 30 days before they take effect. Minor clarifications may be published without notification — the "Last updated" date at the top of this page is the source of truth.
10. Contact
Privacy questions or requests: elevatehuboficial@gmail.com. Data Protection Officer: elevatehuboficial@gmail.com.
11. Visitors who scan QR codes (anonymous tracking)
When someone scans a QR code created with our Service, we register the scan event on behalf of the QR owner so they can see aggregated analytics (count, country, device). This processing is anonymous: we DO NOT set any cookies or local storage on the visitor's browser, we do not assign persistent identifiers, and we do not perform device fingerprinting. The IP address is hashed with a rotating daily salt (SHA-256) and is never stored in plain text. The legal basis is the legitimate interest of the QR owner to measure the performance of their codes (GDPR Art. 6.1.f). For this reason, visitors who scan a QR do not need to accept any cookie banner before being redirected to the destination.
12. Advertising measurement (Meta Pixel & Conversions API)
On our marketing pages we use the Meta (Facebook) Pixel and, server-side, the Meta Conversions API to measure how our ads perform and to improve them. The Pixel records page views and conversion events (such as sign-up, start trial and purchase). When a purchase happens, our server also sends Meta a hashed (SHA-256) version of your email plus the purchase value so Meta can match the conversion — Meta never receives your email in plain text. We use Google Analytics 4 for traffic statistics. These run only after you accept the cookie banner; you can decline and still use the Service fully. This processing relies on your consent (GDPR Art. 6.1.a), which you can withdraw at any time by clearing cookies. We do not sell your data; this is advertising measurement, not data brokering. QR scans by visitors are never sent to Meta or Google.
Operated by Elevate Hub Agency LLC. This document is informational and does not constitute legal advice.