HomePrivacy
Privacy Policy
Last updated: 2026-09-28
This page describes how QRburst (operated by SOTO Labs / STO.ec) handles personal data when you use qrburst.com. It is written to support compliance with the EU/UK GDPR, Ecuador’s Ley Orgánica de Protección de Datos Personales (LOPDP), and Argentina’s Ley 25.326 (and related AAIP guidance). It is product documentation, not legal advice.
1. Controller
Controller: SOTO Labs (STO.ec), operating QRburst.
Contact: https://sto.ec. For access, deletion, or other data-subject requests, contact us through that site and reference “QRburst privacy”.
2. Summary
- Browser QR tools generate codes locally in your device. Payload content (Wi-Fi passwords, vCards, messages, etc.) is not intentionally stored by QRburst as part of generation.
- Optional Google Analytics loads only after you accept analytics cookies (when a measurement ID is configured for the deployment).
- The optional developer API is authenticated and stateless: requests are processed to return PNG/SVG and are not kept as a customer payload archive.
- We do not require accounts for the website generator.
3. What we process
3.1 Data that stays on your device
Design presets, UI preferences, A/B experiment assignment letters, and analytics consent choice may be stored in your browser’s localStorage. These are functional or preference data. Experiment keys store only variant letters (for example A / B), not QR payloads.
3.2 Optional analytics (consent)
If Google Analytics is enabled for a deployment and you grant consent, Google may receive standard usage signals (for example page views, approximate location derived from IP, device/browser metadata, and product events that exclude forbidden fields such as passwords, URLs, emails, or message bodies). We configure anonymize_ip where supported.
3.3 Hosting and security logs
Like most websites, our hosting/CDN provider may process technical request logs (IP address, user agent, timestamps, requested paths) for security, abuse prevention, and reliability. Retention follows the provider’s defaults and our operational needs.
3.4 Developer API (when enabled)
Authenticated API calls send the payload you choose to encode so the server can return an image. API keys are verified via hashed secrets. We do not operate a user account database for the public generator. Rate limiting may store opaque request counters.
4. Purposes and legal bases
| Activity | Purpose | Legal basis (GDPR / LOPDP-aligned) |
|---|---|---|
| Local QR generation | Provide the tool you requested | Contract / service performance; data stays local |
| Security & hosting logs | Protect the service, debug outages | Legitimate interests (security and availability) |
| Google Analytics | Understand product usage | Consent (Art. 6(1)(a) GDPR; LOPDP consent; Ley 25.326 Art. 5) |
| Developer API | Generate QR images for authenticated clients | Contract / legitimate interests of the API customer |
Under Argentina Ley 25.326, processing personal data generally requires free, express, and informed consent unless a statutory exception applies. We treat analytics as consent-based. Under Ecuador LOPDP, treatment of personal data requires a lawful basis (including consent or other authorized grounds) and respect for principles such as purpose limitation, minimization, and security.
5. Cookies and similar technologies
- Essential / functional: local preferences and consent choice stored in
localStorageso the product works and we remember your analytics decision. - Analytics (optional): Google Analytics cookies/scripts load only after you click “Accept analytics”. Rejecting (or doing nothing) keeps analytics off.
Analytics is not configured on this deployment, so no analytics cookies are loaded.
6. International transfers
If you consent to analytics, Google may process data in the United States or other countries. Google publishes its own privacy terms and transfer mechanisms (for example Standard Contractual Clauses). Hosting infrastructure may also process logs outside your country. Ecuador LOPDP and Argentine rules restrict certain cross-border transfers; where consent is the basis for analytics, that consent covers the transfer described here. Controllers who operate their own Argentine databases of personal data “destined to provide reports” may have additional AAIP registration duties — QRburst’s public generator does not create user accounts or a customer PII database.
7. Retention
- Local preferences: until you clear site data or overwrite them.
- Analytics: according to the Google Analytics property retention settings.
- Hosting logs: provider / operational defaults, typically short-lived.
- API payloads: processed for the request; not kept as a generation archive.
8. Your rights
Depending on where you live, you may have rights to:
- Access personal data we hold about you
- Rectification of inaccurate data
- Erasure / deletion (including “derecho al olvido” style requests under LOPDP / Ley 25.326 where applicable)
- Restriction or objection to certain processing
- Portability (GDPR / LOPDP where applicable)
- Withdraw consent for analytics at any time (see controls above) without affecting prior lawful processing
- Hábeas data and complaints before Argentine courts / AAIP (Ley 25.326)
- Lodge a complaint with your supervisory authority (EU/EEA DPAs; Ecuador’s data protection authority under LOPDP; Argentina’s AAIP)
Because browser generation keeps payloads on your device, many “delete my QR content” requests are fulfilled by clearing your browser storage. For analytics or log-related requests, contact us via sto.ec.
9. Children
QRburst is a general-audience productivity tool. We do not knowingly solicit personal data from children. If you believe a child provided personal data through analytics or the API, contact us and we will take appropriate steps.
10. Security
We apply technical and organizational measures appropriate to a static QR tool: HTTPS, security headers, private OpenAPI surface, hashed API keys, analytics property denylists for sensitive event fields, and local-first generation for website tools. No method of transmission or storage is perfectly secure.
11. Changes
We may update this policy as the product or law changes. The “Last updated” date at the top will change when we do. Material changes to analytics practices will remain consent-gated.
12. Disclaimer
This policy describes QRburst’s intended practices. It is not a substitute for legal counsel. Operators deploying forks or self-hosted copies with their own analytics, accounts, or databases remain responsible for their own compliance (including any Argentine database registration with the AAIP when applicable).