Privacy Policy
Last updated: 2026-10-07
1. Who we are
MyQRCreate is a Tegminestar product operated by Tegmine Star LLC, which is responsible for the personal data described here. You can reach us at info@tegminestar.com; we do not publish a physical mailing address. This policy describes what the service actually collects today.
2. Static codes need no account
Static QR codes are generated in your browser, without an account. The content you enter for a static code is not saved by us.
3. Account data
When you sign up and subscribe we store:
- your email address (stored lower-case) and optional name;
- a bcrypt hash of your password (we never store the password itself);
- billing state: subscription status, your PayPal subscription ID, the current period end date, and trial/grace timing;
- a log of PayPal webhook events for your subscription (event type, amount, currency and the JSON payload PayPal sent) for audit and de-duplication;
- feedback you send from the in-app feedback button (rating, optional message and the page you were on).
4. QR code content and uploads
For dynamic codes we store the content and design you enter (links, text, contact details and so on), the short code, name, status, and any expiry date, scan limit or password you set (the password is stored as a hash). Files you upload (PDF, images, video; up to 10 MB each) are stored on our server's disk and served from a public URL with a random file name. Anyone who has that URL can open the file, so do not upload anything confidential.
If your code collects responses from the people who scan it (a feedback rating and comment, or a name, email, phone and note via a contact-exchange form on a vCard code), that data is stored and shown to you as the code owner.
5. Scan analytics
When someone scans a dynamic code and it resolves, we record one event with these fields only:
- the time of the scan;
- approximate country and city, looked up from the visitor's IP address at request time using an offline database;
- device type, browser name and operating system, parsed from the User-Agent header;
- the HTTP referrer, if the browser sent one.
The IP address is used only for that lookup and is not saved in the scan record. Scans are not linked to a named person, and owners see aggregate analytics. Static codes are not tracked at all.
6. Service providers
- PayPal processes subscription payments. Card and PayPal account details are entered with PayPal and are not stored by us. We receive subscription and payment event data from PayPal (see Account data).
- Resend delivers our email: trial and grace-period reminders, payment and cancellation notices, a one-time win-back offer, and messages from our contact, abuse-report and in-app feedback forms to our team. Your email address and the message content pass through Resend for delivery.
- Hosting: the service runs on Microsoft Azure App Service and stores data in a database file and an uploads folder on its persistent storage. Any platform-level backups are controlled by the hosting provider's own settings and schedule.
We do not sell personal data.
8. Retention
Account and QR code data are kept while your account exists. Scan events, feedback responses and contact leads are deleted together with the QR code they belong to; deleting a code from your dashboard removes it and its scan history.
Payment and subscription records, including the event data PayPal sends us, are kept for as long as we need them for accounting, tax and dispute-resolution purposes. Email delivery logs are held by our email provider under its own retention policy. When you ask us to delete your account we remove your account data within 30 days, except records we are legally required or have a legitimate need to keep, such as payment records.
9. Your choices and deletion
- You can edit, pause or delete any dynamic code from your dashboard at any time.
- You can cancel your subscription from your PayPal account.
- There is currently no self-service button to delete your whole account, and no password-reset flow. To request account deletion or a copy of your data, contact us through the Help page. An administrator can delete an account, which also removes its codes, scans and related records.
Your rights. Whatever your location, you can ask us to give you a copy of your data, correct it, or delete it, by emailing info@tegminestar.com from the address on your account. We respond within 45 days. Depending on where you live (for example the EU/UK, California or Texas) you may have additional legal rights, and we will honour those that apply to us. We do not sell personal data or use it for targeted advertising.
10. Security
Passwords are stored as bcrypt hashes, sessions use signed tokens, and PayPal webhooks are verified with PayPal's signature check. The website is served over HTTPS, so traffic between your browser and the service is encrypted in transit. We also rely on our hosting provider's platform security controls. No system is perfectly secure and we cannot guarantee absolute security.
11. Changes and contact
We may update this policy; the date above shows the latest revision. Contact us through the Help page, or email info@tegminestar.com.