隐私政策
最近更新: 25 juillet 2026 / July 25, 2026
本文件提供法文和英文版本;如有差异,以法文版本为准。
This policy explains what personal data GetQRcard collects, why, for how long, and what rights you can exercise. It applies to getqrcard.com and macarteqr.fr.
1. Who is responsible for your data
The data controller is:
- Le Chemin Numérique — non-profit association (ASBL) under Belgian law
- Registered office: Quai du Roi-Albert 114, box 3, 4020 Liège, Belgium
- Company/enterprise number (BCE): 1039.717.066
- Contact for any question about your data: admin@lcn.ac
2. The data we collect
Account: name, e-mail address, password (hashed — never stored in plain text), preferred language, current plan.
Your QRcards’ content: the short code and label you choose, and the linked destination — a URL, a vCard contact card (name, phone, e-mail, company, job title, website) if you use that format, or an uploaded document (e.g. PDF) with its file name. This content may include third parties’ personal data if you place it there yourself (e.g. a business contact’s details): you are responsible for that (see Terms of Sale, Article 8).
Scan statistics: for each scan of a QRcard — date/time, country, device type, user-agent, referrer, and an IP address hashed and salted daily (never stored in plain text, not reversible). This data is tied to the QRcard that was scanned, not to a visitor identity.
Site visit statistics: the same approach (hashed IP, device, referrer, language) for the marketing pages, for purely internal, statistical purposes — no third-party analytics tool (such as Google Analytics) is used.
Anti-abuse security: a hashed IP address is used to limit mass account creation.
Payment: GetQRcard does not collect or store any card or PayPal account data. Only a PayPal subscription identifier is kept, to link your account to your subscription.
Cookies: see section 7.
3. Why we use it, and on what legal basis
- Performance of a contract (GDPR Art. 6.1.b): creating and managing your account, running your QRcards, handling your subscription.
- Legitimate interest (Art. 6.1.f): pseudonymised scan and visit statistics, security and anti-abuse measures (mass account creation, fraud).
- Legal obligation (Art. 6.1.c): where applicable, accounting obligations tied to payments received.
We do not currently send marketing e-mails or a newsletter; only transactional e-mails (account verification, password reset) are sent.
4. How long we keep it
- Account data: for as long as the account is active, then deleted or anonymised on request (section 8).
- Scan history: 30 days on the Free card, unlimited on the Confirmed card.
- Name of the payment account holder: communicated by the payment provider when a subscription is paid. Stored only if you choose to display it on your card, together with the date of the check. No payment data (card, IBAN, token) is ever received or stored by GetQRcard.
- E-mail verification / password reset tokens: limited validity, then automatically expired.
- Hashed IP addresses (anti-abuse): kept briefly, with a salt that changes daily, preventing any matching over time.
5. Who we share it with
Your data is never sold or rented. It may be shared with the following providers, strictly to the extent needed to run the Service:
- OVH — hosting of the Site and database (France/EU).
- PayPal — payment and subscription processing; PayPal acts as an independent controller for payment data, under its own privacy policy.
- Google Wallet — only if you choose to add a QRcard to Google Wallet (optional feature): that QRcard’s information is then sent to Google to create the pass.
6. Transfers outside the European Union
Our host (OVH) operates within the EU. PayPal and Google may transfer some data outside the EU as part of their own processing; such transfers are governed by those companies through appropriate safeguards (such as the European Commission’s standard contractual clauses). Please refer to PayPal’s and Google’s respective privacy policies for details.
7. Cookies
The Site uses two technical cookies, strictly necessary for it to work — so no consent banner is required:
qrcard_session— session cookie (deleted when you close your browser), needed to stay logged in and for form security (CSRF).locale— remembers your chosen language, for 1 year.
No advertising cookies, no third-party trackers, no external analytics tool.
8. Your rights
Under the GDPR, you have the right to access, rectify, erase, restrict, port and object to the processing of your data. Most account information can be changed directly from your account (“My account”). For any other request, e-mail admin@lcn.ac: we reply within one month.
9. Complaints to the supervisory authority
If you believe your rights are not being respected, you can lodge a complaint with the Belgian Data Protection Authority: Rue de la Presse 35, 1000 Brussels — autoriteprotectiondonnees.be.
10. Security
Passwords are hashed (never stored or readable in plain text). IP addresses tied to scans and visits are hashed and salted, never stored in plain text. Traffic to the Site is encrypted (HTTPS) and technical cookies are protected (HttpOnly, Secure, SameSite).
11. Minors
The Service is not intended for people under 16 without a legal guardian’s consent (see Terms of Sale, Article 3).
12. Changes to this policy
This policy may evolve, in particular to reflect changes to the Service or to applicable law. The last-updated date appears at the top of this page.
13. Contact
admin@lcn.ac — Le Chemin Numérique, Quai du Roi-Albert 114, box 3, 4020 Liège, Belgium.