1. Overview
Go2QR ("we," "us," or "our") operates as a Shopify application that allows merchants to create, customize, and track QR codes for their online stores. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you install and use our application through the Shopify platform.
Our app is distributed through the Shopify App Store and operates within the Shopify ecosystem. When you install our app, you are authorizing us to access certain data from your Shopify store as required for the app to function correctly.
2. Data We Collect
When you install and use Go2QR, we may collect the following categories of information:
Store & Account Information
- Shop name, URL, and primary domain
- Shop owner name, email address, and contact email
- Shopify plan and account type
- Installed app session tokens (OAuth access tokens stored securely)
QR Code Data
- QR code configurations, designs, and destination URLs you create
- Associated product, collection, or page identifiers
- Custom branding settings (colors, logos, error correction levels)
Analytics & Scan Data
- Number of scans per QR code, along with timestamps
- Device type, operating system, and browser (derived from User-Agent)
- Approximate country and region (derived from IP address; IP is not stored)
Information We Do NOT Collect
- Your customers' personally identifiable information (names, emails, payment details)
- Raw IP addresses of QR code scanners
- Any data beyond what Shopify grants us access to via the approved OAuth scopes
3. How We Use Your Data
We use the information we collect for the following purposes:
- Service Delivery: To create, store, and serve your QR codes; generate short-link redirects on your Shopify store; and display analytics dashboards.
- Authentication: To verify your identity and maintain your session securely with Shopify.
- App Functionality: To read products, collections, and pages from your store when you choose a QR code destination, and to write URL redirects that route QR scans correctly.
- Analytics: To record and display scan counts, device breakdown, and regional data so you can measure QR code performance.
- Support: To respond to support requests submitted through the in-app support form.
- Improvement: To analyze aggregate usage patterns and improve the application's features and performance.
- Security: To detect and prevent fraudulent or unauthorized activity.
4. Sharing & Disclosure
We do not sell or rent your personal information. We may share data only in the following limited circumstances:
Shopify
Our app runs on the Shopify platform. All store data is retrieved and written through the official Shopify Admin GraphQL API under the OAuth scopes you grant during installation. Shopify's own privacy practices apply: https://www.shopify.com/legal/privacy.
Infrastructure & Hosting Providers
Our backend services are hosted on secure cloud infrastructure. These providers process data solely on our behalf and under strict data processing agreements.
Legal Requirements
We may disclose your information if required by applicable law, court order, or government regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, who will be bound by this Privacy Policy.
write_products Β· write_online_store_navigation Β· write_online_store_pages Β· write_files Β· read_reportsThese are the minimum scopes needed to provide full functionality.5. Cookies & Tracking
Our Shopify app operates within an embedded iframe inside the Shopify Admin. We use session cookies and browser storage solely to maintain your authenticated session and store UI preferences.
- Session Cookies: Used to authenticate your admin session. These are essential for the app to function and expire when you log out.
- Preference Storage: We may store lightweight UI preferences (e.g., selected filters) in browser local storage for a better user experience.
- No Third-Party Tracking Cookies: We do not embed third-party advertising or social tracking pixels inside the app admin interface.
When your customers scan a QR code, they are redirected via a short URL on your Shopify store. At that redirect step, we record the scan event (timestamp, device type, approximate region). No cookies are set on your customers' devices by Go2QR.
6. Behavioral Advertising
Go2QR does not use your store data or your customers' data for behavioral advertising, retargeting, or any form of cross-site tracking.
You may independently use tools like Google Analytics or Meta Pixel on your Shopify storefront. Those services are governed by their own privacy policies, not this one.
7. Your Rights (GDPR β EEA & UK)
If you are located in the European Economic Area or the United Kingdom, you have the following rights regarding your personal data under the General Data Protection Regulation (GDPR):
To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days.
When you uninstall our app, Shopify sends us a mandatory app/uninstalled webhook. Upon receiving this, we delete your store session and all associated QR code data from our database within 48 hours.
8. Your Rights (CCPA β California)
If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you the following rights:
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the sources from which it was collected, our business or commercial purposes for collecting it, and the categories of third parties with whom we share it.
- Right to Delete: You may request that we delete personal information we have collected from you, subject to certain exceptions.
- Right to Opt-Out of Sale/Sharing: We do not sell or share personal information. This right is already guaranteed.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.
To submit a request, contact us at [email protected] with the subject line "CCPA Request."
9. Data Retention
We retain your data for as long as your store has our app installed and for a reasonable period thereafter:
- Session Data: Retained while the app is installed. Deleted within 48 hours after uninstallation.
- QR Code Data: Stored for the duration of your subscription. You may delete individual QR codes at any time from within the app.
- Scan Analytics: Retained for up to 24 months to provide historical reporting, then automatically purged.
- Support Correspondence: Retained for up to 3 years for service continuity purposes.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last Updated" date at the top of this page.
We encourage you to review this policy periodically. Continued use of the app after any changes constitutes your acceptance of the updated policy.
11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
We aim to respond to all privacy-related inquiries within 5 business days.