Legal

Privacy Policy

Effective September 3, 2026

The short version

QR Gate exists to open doors, not to profile people. We collect the minimum needed to run phone-verified access, we hash what we can, we sell nothing to anyone, and visitors never need an account.

What we collect from visitors (people at the door)

When you scan a QR code and request entry, we process your phone number to send a one-time verification code. After verification:

  • We do not store your phone number. Access logs keep a one-way cryptographic hash plus the last 4 digits so the organization can recognize entries in its own audit trail. The full number cannot be recovered from what we store.
  • Each access attempt records the location, time, result (granted or denied, and why), and technical basics of the request.
  • If an organization uses trust features, a record of "this hashed phone has visited before" is kept — scoped to that organization's community context, never shared across contexts, and dormant after 12 months of inactivity.

Verification codes are delivered by Twilio, our SMS provider, which processes your number for delivery under its own privacy policy.

What we collect from organization admins

  • Account: your email, an optional name, and a bcrypt hash of your password (we never store the password itself). Sessions are signed cookies on your own device.
  • Organization data:your org's name, locations, member phone lists you add, lock codes (encrypted at rest), and settings. Member lists belong to your organization — we process them only to run the access checks you configure.
  • Billing:handled by Stripe. We never see or store card numbers — only your plan, subscription status, and Stripe's references.

What we deliberately never do

  • No sale or rental of any data, ever.
  • No advertising, no ad trackers, no cross-site profiling.
  • No storing of raw visitor phone numbers in access logs.
  • No cross-context trust sharing: recognition earned at one kind of community never grants access or visibility at another — by design, with no override.
  • No disclosure of blocklist status to the blocked person, and no sharing of block reasons between organizations (other organizations' admins may see only an anonymous count in narrow, safety-relevant moments).

Who processes data on our behalf

We run our own servers and database. A small set of processors help:

  • Twilio — SMS delivery of verification codes and door codes.
  • Stripe — subscription billing.
  • Resend — transactional email (alerts, password resets).
  • Cloudflare — network protection and the CAPTCHA on the visitor form.

Each receives only what its job requires.

Retention and deletion

  • Access logs are kept for the organization's audit purposes and deleted with the organization.
  • Trust records go dormant after 12 months without activity in a community context.
  • Organization admins can delete members, locations, or their whole organization from the dashboard; deletion is permanent.
  • To exercise any data request — access, correction, deletion — email privacy@qrgate.app. Visitors may need to tell us the phone number in question so we can locate its hash.

Changes

If this policy changes materially, we'll note it here with a new effective date, and email organization admins for significant changes.