Privacy Policy
Last updated: March 30, 2026
QR Drop ("we", "our", "the service") is operated at shareinseconds.com. This policy explains what information we collect, how we use it, and your rights.
1. Information We Collect
Files you upload. When you upload a file, it is stored in Amazon S3 (AWS, us-east-1). Files are automatically and permanently deleted after 7 days. We do not inspect, read, or analyse file contents.
Technical logs. AWS Lambda and API Gateway automatically record standard server logs (IP address, timestamp, HTTP method, response code). These logs are retained for up to 30 days for security and debugging purposes and are never sold.
Account information. If you sign in (via Google or email magic link), we store your email address and a session token. Paid users also have billing data managed by Stripe.
Analytics. We use Google Analytics (GA4) to understand how the service is used (page views, feature usage). No advertising cookies or tracking pixels are used.
Local storage. We store your language preference and session token in your browser's localStorage. This data never leaves your device except when making authenticated API requests.
2. How We Use Your Information
- To generate a presigned URL and QR code for your uploaded file.
- To allow the recipient to download the file via the QR code.
- To automatically delete the file and its link after the expiry period.
- To manage your account, billing, and usage tracking.
- To send transactional emails (sign-in links, payment receipts, file notifications).
- To maintain service security and prevent abuse.
We do not use your files or logs for advertising, profiling, or AI training.
3. Data Storage & Security
Files are stored in AWS S3 with server-side encryption (AES-256). Transfer is protected by HTTPS/TLS. Access to files requires a time-limited presigned URL generated at upload time. No file is publicly browseable or listable.
4. Data Sharing
We do not sell, rent, or share your data with third parties for commercial purposes. Third-party services involved are:
- Amazon Web Services (AWS) — file storage, email delivery (SES), compute.
- Stripe — payment processing for paid plans. Stripe handles all card data; we never see your full card number.
- Google — OAuth sign-in (if you choose Google sign-in) and Google Analytics.
These services operate under their own privacy policies: Privacy Notice.
5. Your Rights
You can sign out at any time to clear your session. If you want your account and data deleted, or if you uploaded a file containing personal data and want it removed before automatic expiry, contact us at privacy@shareinseconds.com with the file key from the QR code URL.
6. Children
QR Drop is not directed at children under 13. We do not knowingly collect data from children.
7. Changes to This Policy
We may update this policy. Material changes will be reflected by an updated date at the top of this page.
8. Contact
Questions? privacy@shareinseconds.com