Privacy-First Architecture

Privacy Policy

Last updated: August 28, 2026

1. Our Commitment to Privacy

At Snapcode, privacy is built directly into our technical architecture. We provide dynamic QR code redirection and analytics without compromising scanner privacy.

2. Cryptographic IP Hashing (No Raw IP Storage)

When a visitor scans a dynamic QR code generated via Snapcode, we immediately hash their IP address using **SHA-256 with a unique server-side salt**.

Raw IP addresses are never saved to disk or database.
Hashed IPs prevent tracking scanners across third-party websites.

3. Information Collected

We collect minimal information necessary to deliver scan analytics and account management:

  • Account Owners: Name, email address, and authentication details (Google OAuth or hashed passwords).
  • Scan Analytics: Aggregated device type (mobile/desktop), browser type, and operating system.

4. Redirection & Indexing Headers

All dynamic redirect endpoints (`/q/[shortCode]`) append `X-Robots-Tag: noindex, nofollow` headers to instruct search engine crawlers not to index or cache redirection routes.

5. Contact Us

If you have any questions about this Privacy Policy, please reach out to us at privacy@snapcode.app.