Legal
Privacy Policy
Last updated July 1, 2026
What this covers
This policy explains what Relay collects when you use our QR code platform — the marketing site, the app at app.relaycodes.com, and our redirect and API infrastructure. It applies to workspace owners, their team members, and the people who scan a Relay-generated QR code.
Data we collect
Account data
When you create a workspace, we store your email address, a hashed password (if you sign up with email), your workspace name, and your plan. If you sign in with Google, we receive your name, email, and profile image from Google's OAuth flow.
QR code and destination data
We store the QR codes you create — their slug, destination URL, title, folder, and visual style — for as long as your workspace exists. If a QR code is on a downgraded plan, we freeze its redirect rather than delete it; the underlying record is retained.
Scan data
Each time someone scans one of your QR codes, we log a scan event: timestamp, approximate country and city (derived from IP address, which is not stored), device type, operating system, and browser. We do not log the full IP address, and we do not attempt to identify the individual who scanned the code.
Payment data
Billing is handled by Stripe. Relay does not store your card number. We retain your Stripe customer ID and subscription ID to keep your plan in sync.
How we use it
- To operate the redirect, analytics, and API infrastructure you're paying for.
- To enforce plan limits (QR code count, API request volume).
- To send transactional email — password resets, billing receipts, plan-limit notices.
- To respond to support requests.
We do not sell your data, and we do not use scan data to build advertising profiles.
Who we share it with
Relay uses a small number of infrastructure providers to operate the product:
- Our hosting and database provider — stores your workspace data, handles authentication, and runs our redirect infrastructure. All data is hosted in the EU (Ireland).
- Stripe — payment processing.
- Google — OAuth sign-in, if you choose that method.
Each of these providers processes data only to the extent necessary to provide their service to Relay. We do not share your data with data brokers or advertising networks.
Public report links
Analytics you share via a report link (/report/:token) are viewable by anyone with the link. Only aggregate scan data is shown — never the identity of individual scanners. Treat report links like you would any other shareable URL: don't post them somewhere you wouldn't want the data seen.
Data retention
We keep your account and QR code data for as long as your workspace is active. Scan history is retained according to your plan (30 days on Free, full history on Pro and Agency). If you delete your workspace, we delete your account data and QR codes within 30 days, except where we're required to keep billing records for tax or legal reasons.
Your rights
You can access, correct, or delete your account data at any time from Settings, or by emailing privacy@relaycodes.com. If you're in the EU or UK, this includes the right to request a copy of your data and the right to object to processing under GDPR.
Changes to this policy
If we make a material change, we'll email workspace owners and update the date at the top of this page.
Contact
Questions about this policy: privacy@relaycodes.com