Skip to content

QRchive · Legal

Privacy Policy

Last updated September 4, 2026

What we collect, where it lives, who can see it, and how to get it back or removed.

  1. 01 Who we are
  2. 02 What we collect
  3. 03 How we use it
  4. 04 Archives are public by default
  5. 05 Where your data lives
  6. 06 Automated processing of files
  7. 07 Who we share it with
  8. 08 How long we keep it
  9. 09 Your rights
  10. 10 Cookies
  11. 11 Security
  12. 12 Children
  13. 13 Changes to this policy
  14. 14 Contact

01Who we are

QRchive is operated by Pacific Rim Wastewater Solutions Ltd., a British Columbia company. We are the organization accountable for the personal information described here under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia's Personal Information Protection Act. Questions and requests go to jordan@qrchive.ca.

02What we collect

Account information. Your email address, and if you give them, your name, company name, trade, phone number, province and postal code, and a shipping address for sticker rolls. We use sign-in links and codes sent by email; we never store a password for you.

Payment information. Stripe processes payments. We receive the outcome of each payment, the last four digits of the card, and the billing and shipping address Stripe collects. We never receive or store full card numbers.

Archive contents. The files you put in an archive and the details you enter about it (project name, address, description, contact details), plus files added by other people through public upload or the archive's email-in address, and the sender address of email-in messages.

Usage records. When an archive is opened, downloaded from, or added to, we record the time, the user agent, and a one-way hash of the IP address. We do not store raw IP addresses in those logs. Your dashboard shows some of this activity for your own archives.

Referral tags. If you arrive through a link with a referral code, we note which account introduced you. This is for our own reporting only; it does not affect pricing and no one is paid for it.

Support and feedback. Anything you email us or submit through the feedback form.

03How we use it

  • To run QRchive: store and serve your archives, print and ship stickers, process payments, and send receipts.
  • To email you about your account and archives: sign-in links, unlock confirmations, files added to your archives, storage warnings, monthly summaries and tips. You can turn the non-essential ones off in your dashboard.
  • To keep QRchive safe: rate limiting, abuse prevention, and acting on reports.
  • To understand how QRchive is used, in aggregate, so we can improve it.
  • To meet legal obligations, including tax records and responding to lawful requests.

We do not sell personal information, and we do not use your files to train artificial-intelligence models.

04Archives are public by default

Anyone who scans a sticker or has an archive's link can open that archive and see everything in it, including the project details and contact information the manager entered. That is the point of QRchive, and it means information in a public archive is not private. An archive's manager can make it private, in which case only people with the access password or an approved email address can open it.

If your personal information appears in someone else's public archive and you want it removed, contact the archive's manager (their company is shown on the archive) or email jordan@qrchive.ca and we will help.

05Where your data lives

Archive files are stored with Cloudflare R2 with the bucket restricted to Canadian jurisdiction. Our database, including account details and usage records, is hosted by Supabase in Canada (central region).

Requests to QRchive are handled by application servers hosted by Vercel in the United States, and emails are sent through Resend in the United States. This means your data is processed in the United States while a page is being served or an email is being sent, and while there it is subject to United States law. It is stored at rest in Canada.

06Automated processing of files

When a file is added we check its type and size, generate a smaller preview of images and a poster frame of videos so archives load quickly, and make backups. These steps are automatic and no person reviews the file.

We do not currently send customer files to any artificial-intelligence service. If we introduce a feature that does, we will update this policy first and describe exactly what is sent and why.

07Who we share it with

  • Service providers who process data for us, under their own privacy terms: Supabase, Cloudflare, Vercel, Resend, Stripe, and Sentry (error monitoring). Each sees only what it needs to do its job.
  • Anyone who opens a public archive sees its contents.
  • Authorities and courts, when the law requires it: court orders, orders of the BC Civil Resolution Tribunal, lawful requests from police, and Canada's mandatory reporting rules for child sexual abuse material.
  • A buyer of our business, if QRchive is ever sold, under the same commitments.

08How long we keep it

  • Archive contents: for as long as QRchive operates. Archives are permanent by design; see the Terms of Use for what happens when an account closes.
  • Files you delete: removed from live storage promptly and from backups within 30 days.
  • Account information: for the life of the account, then removed within 30 days of closure except for records we must keep.
  • Payment and tax records: seven years, as the Canada Revenue Agency requires.
  • Usage records: retained for security and reporting; they contain hashed IP addresses, not raw ones.

09Your rights

You can ask to see the personal information we hold about you, correct it, or have it deleted, subject to records we are legally required to keep. You can export all of your archives from your dashboard at any time, and you can withdraw consent to non-essential emails there too. Email jordan@qrchive.ca; we respond within 30 days.

If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada, or to the Office of the Information and Privacy Commissioner for British Columbia.

10Cookies

  • Sign-in cookies, so you stay signed in to your dashboard.
  • A private-archive access cookie, set only when you open a private archive with a password or approved email; it lasts 30 days.
  • A referral cookie, set only when you arrive through a link with a referral code; it lasts 90 days and is used for our own reporting.
  • Cloudflare Turnstile, which tells forms apart from bots, and Vercel performance measurement, which collects page-timing data without identifying you.

We do not use advertising cookies or third-party trackers.

11Security

Connections use TLS. Files and databases are encrypted at rest. Each archive's link carries a random token so links cannot be guessed, and access rules are enforced in the database itself. No method is perfect; if we learn of a breach that creates a real risk of significant harm, we will notify you and the Privacy Commissioner as PIPEDA requires.

12Children

QRchive is a tool for adults and businesses. We do not knowingly collect personal information from anyone under 18.

13Changes to this policy

We may update this policy. For significant changes we will email account holders before the change takes effect. The date at the top shows the most recent revision.

14Contact

Pacific Rim Wastewater Solutions Ltd., British Columbia, Canada. Email jordan@qrchive.ca.