Privacy Policy

Last updated: 17 August 2026

This Privacy Policy explains how QR Kit Studio processes personal data when you use our website, Studio, checkout, downloads and related services.

QR Kit Studio is operated by DOMU.STUDIO — Dominic Mueller ("QR Kit Studio", "we", "us", or "our").

1. Controller

The controller responsible for the processing of personal data within the meaning of the EU General Data Protection Regulation ("GDPR") is:

DOMU.STUDIO — Dominic Mueller
Mainzer Str. 19
50678 Cologne
Germany

Email: contact@domu.studio

2. What QR Kit Studio does

QR Kit Studio is a digital design and download service that lets users create branded QR-code asset kits for links, businesses, profiles, campaigns, locations, review pages or other online destinations.

The service may include:

  • creating or configuring a QR code for a selected link or destination;
  • designing branded QR materials directly in the online Studio;
  • previewing formats before purchase;
  • generating a downloadable 108-asset QR kit, including print, web and social media assets;
  • providing files in formats such as PDF, PNG and JPG;
  • processing a one-time digital purchase;
  • delivering download links and transactional emails;
  • allowing re-downloads through a personal link for the stated availability period.

QR Kit Studio may offer different QR categories or subtypes. Some categories may relate to reviews, Google Reviews, websites, menus, social profiles, gift cards, payments, bookings, contact details or other destinations. Availability may change over time.

3. Independent service and third-party platforms

QR Kit Studio is an independent service operated by DOMU.STUDIO. We are not affiliated with, endorsed by, sponsored by, certified by or officially connected to any third-party platform unless explicitly stated.

All third-party names, logos, trademarks, brands, platform names and service names remain the property of their respective owners. Any references to third-party services are for descriptive purposes only.

When a person scans a QR code or follows a link generated with QR Kit Studio, they may be redirected to a third-party website, platform or service selected by the user who created the QR kit. That third party processes data according to its own terms and privacy policy.

We do not own, operate, control, host, moderate, edit, verify, approve, reject or remove content published on third-party platforms.

4. Review-related QR kits

Some QR Kit Studio products or subtypes may help users create QR materials that point to review pages, including Google Reviews or other review platforms.

Reviews submitted through a third-party review platform are submitted to and processed by that platform, not by QR Kit Studio.

We do not collect, store, host, moderate, edit, display, verify, approve, reject or remove reviews submitted on third-party platforms. We do not have access to the content of reviews that visitors leave on those platforms after following a QR code or link generated with QR Kit Studio.

5. Categories of data we process

Depending on how you use QR Kit Studio, we may process the following categories of data.

5.1 Studio preview and QR kit design

When you design a QR kit in the Studio, we may process the information you enter, paste, select or configure in order to generate previews and create your files.

This may include:

  • destination URL;
  • QR category or subtype;
  • business name;
  • subtitle or location text;
  • title;
  • call-to-action text;
  • selected template;
  • selected colours;
  • selected formats;
  • generated preview data;
  • technical request data, such as timestamp, browser information and hashed IP address where practical.

You can browse and design in the Studio without creating an account. Preview files may be watermarked, limited, lower resolution or otherwise restricted until purchase.

5.2 Business search and link resolution

For certain QR categories or subtypes, such as Google Review QR kits, QR Kit Studio may allow you to search for a business or resolve a third-party business link into a more specific destination URL.

When you use such features, we process the information you submit in order to find, resolve or validate the relevant business listing or destination.

This may include:

  • business search query;
  • business name;
  • third-party business URL;
  • Google Maps or Google Business Profile URL, where applicable;
  • place ID, where applicable;
  • formatted address, where applicable;
  • selected business listing;
  • generated review URL or destination URL;
  • technical request data, such as timestamp and hashed IP address where practical.

To perform the lookup, relevant search or link data may be sent to third-party services, such as Google Places, Google Maps or other business-data providers, depending on the selected QR category.

We may cache non-sensitive business or destination data, such as business name, place ID, formatted address or destination URL, to reduce repeat lookups, improve performance and prevent abuse.

5.3 QR kit purchase

When you purchase a QR kit, we process the data necessary to create, deliver and document your order.

This may include:

  • business name or project name;
  • selected destination URL;
  • selected QR category or subtype;
  • selected design options;
  • generated kit details;
  • email address;
  • order ID;
  • payment status;
  • order amount and currency;
  • invoice or receipt information;
  • download token;
  • download count;
  • token expiry date;
  • hashed IP address where practical;
  • timestamps relating to order, payment, generation and download activity.

We use this data to generate the purchased digital product, deliver the download, provide receipts, enable re-downloads during the stated availability period, prevent fraud and comply with accounting obligations.

5.4 Payments

Payments are processed by Stripe or another payment provider shown at checkout.

When you pay, payment-related data is collected and processed directly by the payment provider. This may include your name, email address, billing details, payment method details, transaction data, fraud prevention data and payment status.

We do not receive or store your full card number or complete payment credentials.

We receive only limited payment information from the payment provider, such as payment status, payment intent or checkout session ID, amount and currency, customer email address, receipt status, transaction timestamps, and information needed for order fulfilment, fraud prevention and accounting.

5.5 Email delivery through Resend

We use Resend to send transactional emails, such as order confirmations, receipt information, download links, re-download links, support replies and important service-related notices.

For email delivery and monitoring, we and Resend may process recipient email address, sender information, message content, message ID, delivery status, bounce status, suppression status, timestamps, IP addresses and limited technical metadata.

If an email cannot be delivered, or if you unsubscribe from non-essential emails, your email address may be stored in a suppression list to ensure we do not continue sending emails to that address.

Transactional emails that are necessary for your purchase or service request may still be sent where legally permitted.

5.6 Google Analytics

We use Google Analytics to understand how visitors use QR Kit Studio and to improve reliability, usability and performance.

Google Analytics may process information such as page views, session information, device and browser information, approximate location, referrer URL, interactions with the website, timestamps and pseudonymous identifiers.

According to Google, Google Analytics 4 does not log or store IP addresses from users in the EU, Switzerland or the United Kingdom. Google states that IP addresses are used at collection time to derive location information and are then discarded before data is logged.

However, Google Analytics may still process usage data, cookies and pseudonymous identifiers.

We use Google Analytics only where legally permitted. Where required, Google Analytics is loaded only after you have given consent through our cookie or consent banner.

You can withdraw your consent at any time with effect for the future through the consent settings on our website, where available, or by deleting or blocking cookies in your browser.

We do not use Google Analytics to build advertising profiles for QR Kit Studio users.

5.7 Our own first-party analytics

In addition to Google Analytics, we operate our own first-party analytics on our own infrastructure. It is used only to understand how QR Kit Studio is used and to improve reliability, usability and performance. No data from it is sold, shared with advertising networks or used for profiling.

Where you have accepted analytics cookies, each page view may be stored with: the page path and timestamp; the referring website and campaign parameters (utm_source, utm_medium, utm_campaign); the derived traffic channel (search, social, AI assistant, referral, campaign or direct); approximate location derived from your IP address (country, region, city); operating system, browser and device type; screen resolution, browser window size, language and time zone; selected QR categories, templates and other in-app events; and a random pseudonymous visit identifier stored in your browser.

Your full IP address is not stored. It is used transiently to derive approximate location and is otherwise kept only as an irreversible, salted hash for abuse and rate-limit protection. The legal basis is your consent under Art. 6(1)(a) GDPR and § 25 TDDDG, which you can withdraw at any time via "Cookie settings" in the footer. If you reject analytics cookies, no first-party analytics data is collected for your visit. This data is stored in our EU-hosted database and retained for up to 24 months, after which it is deleted or fully aggregated.

Where possible, analytics are aggregated or pseudonymised. We do not use analytics to build advertising profiles.

5.8 Abuse prevention and security

To protect QR Kit Studio from spam, fraud, bots, excessive requests and security attacks, we may process technical and security-related data.

This may include hashed IP address where practical, request frequency, rate-limit counters, user agent, timestamps, failed or suspicious requests, checkout creation attempts, download attempts, webhook verification status, fraud signals, server logs and application logs.

We use this data to detect abuse, enforce rate limits, prevent fraudulent use, secure payment and download flows, protect our infrastructure and preserve service availability.

5.9 Server logs and hosting in Frankfurt, Germany

QR Kit Studio is hosted on servers located in Frankfurt am Main, Germany.

Our hosting provider and technical infrastructure may automatically process standard server log data.

This may include IP address, date and time of request, requested URL, HTTP status code, referrer URL, user agent, browser and operating system information, and amount of data transferred.

Server logs are used for security, debugging, abuse prevention and service stability.

6. Legal bases for processing

We process personal data only where we have a legal basis under the GDPR.

6.1 Performance of a contract — Art. 6(1)(b) GDPR

We process data to provide the service you request, including generating previews, creating QR codes, creating QR kits, processing purchases, delivering downloads, enabling re-downloads, sending order-related transactional emails and providing customer support.

6.2 Legitimate interests — Art. 6(1)(f) GDPR

We process data where necessary for our legitimate interests, provided your interests and fundamental rights do not override those interests.

These interests include securing the service, preventing abuse, spam and fraud, enforcing rate limits, verifying payment-related events, maintaining technical reliability, debugging errors, measuring basic aggregated usage, improving the service, maintaining suppression lists, protecting download links, and protecting our legal and business interests.

6.3 Legal obligation — Art. 6(1)(c) GDPR

We process and retain certain data where required by law, including accounting, tax, commercial and record-keeping obligations under German and EU law.

6.4 Consent — Art. 6(1)(a) GDPR

Where we use non-essential cookies, Google Analytics, optional analytics, marketing emails or other processing that requires consent, we will ask for your consent separately.

You may withdraw your consent at any time with effect for the future.

7. Cookies and similar technologies

QR Kit Studio may use cookies or similar technologies that are technically necessary to provide the service, maintain sessions, remember essential settings, prevent abuse, generate previews, complete checkout, deliver downloads or keep the Studio working correctly.

We also use Google Analytics cookies or similar technologies if you have given consent where required by law.

You can configure your browser to block or delete cookies. However, some parts of the service may not work properly without technically necessary cookies.

More information is available in our Cookie Policy.

8. Recipients and processors

We may share personal data with carefully selected service providers where necessary to operate QR Kit Studio.

These may include:

  • hosting and infrastructure providers with servers in Frankfurt am Main, Germany;
  • Stripe or another payment provider shown at checkout;
  • Resend for transactional email delivery;
  • Google Analytics for website analytics, where consent has been given where required;
  • Google Places, Google Maps or similar services where a relevant lookup feature is used;
  • database, storage, logging, monitoring and security providers;
  • QR-code, image, PDF or asset-generation infrastructure;
  • tax, accounting or legal advisors where necessary.

Where service providers process personal data on our behalf, we use data processing agreements where required by Art. 28 GDPR.

Some providers may act as independent controllers for certain processing activities, especially payment providers or third-party platforms selected by users. Their own privacy policies apply.

9. Stripe

If you make a purchase, payment processing is handled by Stripe or another payment provider shown at checkout.

The payment provider may process personal data as necessary for payment execution, fraud prevention, regulatory compliance, authentication, accounting and dispute handling.

We receive only limited payment and transaction information necessary to fulfil your order, document the purchase and comply with legal obligations.

For more information, please refer to the payment provider’s own privacy policy.

10. Resend

We use Resend to send transactional emails related to QR Kit Studio, including order confirmations, receipt information, download links, re-download links and support-related emails.

Resend may process email-related data such as recipient address, sender address, message content, delivery metadata, bounce data, suppression data, timestamps and technical information needed to deliver and secure emails.

Resend may process data as our processor for email delivery and may use subprocessors or international transfers according to its own legal terms, data processing addendum and privacy policy.

11. Google Analytics

We use Google Analytics, a web analytics service provided by Google, to measure and improve use of QR Kit Studio.

Google Analytics helps us understand, in aggregated or pseudonymous form, how visitors use the website, which pages and features are used, how users arrive at the site, and whether the service works properly across devices and browsers.

Google Analytics may set cookies or use similar technologies. Where required by law, Google Analytics is used only after consent.

You can prevent or limit Google Analytics processing by rejecting analytics cookies in our consent banner, withdrawing consent later, blocking cookies in your browser, or using browser privacy tools.

Google may process Google Analytics data according to Google’s own terms and privacy documentation.

12. Google Places, Google Maps and similar business lookup services

For certain QR categories or subtypes, such as Google Review QR kits, we may use Google Places, Google Maps or similar services to help you find or resolve a business listing or destination URL.

When you use such a feature, we may send your submitted business search query, business link or related lookup data to the relevant service provider in order to return place data, business data or a review destination.

The relevant third-party provider may process this data according to its own terms and privacy policy.

We use such data only to provide the requested lookup, generate the selected destination and create the QR kit materials.

If you do not use a lookup feature and instead paste a URL manually, the amount of data sent to third-party lookup providers may be reduced or avoided, depending on the selected QR category and technical requirements.

13. International data transfers

Our main server infrastructure is located in Frankfurt am Main, Germany.

Some service providers, including Resend, Stripe and Google, may process personal data outside the European Economic Area, including in the United States.

Where personal data is transferred to a country without an adequacy decision, we use appropriate safeguards, such as EU Standard Contractual Clauses, where required.

Where applicable, transfers may also rely on an adequacy framework such as the EU–US Data Privacy Framework.

14. Data retention

We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, unless longer retention is required by law.

Typical retention periods are:

  • Studio preview data: retained temporarily as needed to generate previews, maintain the session, improve functionality and prevent abuse;
  • business lookup cache: retained for as long as useful to reduce repeat lookups, improve performance and prevent abuse;
  • order and payment records: retained for statutory tax, accounting and commercial retention periods, typically 6 to 10 years under German law;
  • invoices and receipts: retained as required by applicable tax and accounting law;
  • download tokens and re-download links: retained until the stated validity period expires, typically 30 days after payment, and may be limited by download count or security controls;
  • email delivery logs: retained for delivery monitoring, troubleshooting and compliance for a limited period;
  • suppression list entries: retained as long as necessary to ensure that we do not send unwanted or undeliverable emails;
  • Google Analytics data: retained according to the retention settings configured in Google Analytics and only as long as necessary for analytics and service improvement;
  • first-party analytics events: retained for up to 24 months, then deleted or kept only in aggregated form;
  • analytics events: retained only as long as necessary for aggregated usage analysis and service improvement;
  • IP hashes and rate-limit data: retained only as long as necessary for abuse prevention and security;
  • server logs: retained for a limited period for security, debugging and operational purposes, unless longer retention is necessary due to a security incident or legal obligation.

If data is no longer needed, we delete or anonymise it.

15. Security

We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.

These measures may include hosting in Germany, access controls, encryption in transit, secure payment processing through external payment providers, webhook verification, rate limits, token expiry, download limits, hashed IP addresses where practical, logging and monitoring of security-relevant events, and restricted access to production systems.

No online service can be guaranteed to be completely secure.

You are responsible for using accurate information, testing QR destinations, keeping download links confidential and protecting access to your own email account and devices.

16. Your GDPR rights

Subject to the legal requirements, you have the following rights under the GDPR:

  • right of access — Art. 15 GDPR;
  • right to rectification — Art. 16 GDPR;
  • right to erasure — Art. 17 GDPR;
  • right to restriction of processing — Art. 18 GDPR;
  • right to data portability — Art. 20 GDPR;
  • right to object — Art. 21 GDPR;
  • right to withdraw consent — Art. 7(3) GDPR.

To exercise your rights, contact us at contact@domu.studio.

We may need to verify your identity before responding to your request.

17. Right to object under Art. 21 GDPR

Where we process personal data based on legitimate interests under Art. 6(1)(f) GDPR, you have the right to object to that processing on grounds relating to your particular situation.

If you object, we will no longer process the relevant personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or unless the processing serves the establishment, exercise or defence of legal claims.

18. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority.

You may contact the supervisory authority in the EU member state of your habitual residence, place of work or place of the alleged infringement.

For businesses located in North Rhine-Westphalia, Germany, the competent supervisory authority is generally:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 Düsseldorf
Germany

Website: https://www.ldi.nrw.de/

19. Children

QR Kit Studio is intended for business, professional and organisational users and is not directed at children.

We do not knowingly collect personal data from children.

20. Automated decision-making

We do not use personal data for automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR.

We may use automated security and abuse-prevention mechanisms, such as rate limits, fraud checks, suspicious request blocking or download protection, to protect the service.

21. Links to third-party websites

QR Kit Studio may contain links to third-party websites, platforms or services, including payment providers, review platforms, map services, social media platforms or other external destinations.

We are not responsible for the privacy practices, content or security of third-party websites. Their own privacy policies apply.

22. Changes to this Privacy Policy

We may update this Privacy Policy from time to time, for example if our service, providers, legal obligations or data processing activities change.

The current version will always be available on our website and will show the latest update date.

23. Contact

For questions about this Privacy Policy or the processing of personal data, contact:

DOMU.STUDIO — Dominic Mueller
Mainzer Str. 19
50678 Cologne
Germany

Email: contact@domu.studio

QR Code is a registered trademark of DENSO WAVE INCORPORATED in the United States and other countries.