Effective date: 12 July 2026 | Last updated: 12 July 2026

1. Controller and scope QReasyUse is operated by QReasyUse@gmail.com (“we”, “us”), which is the personal data controller for the processing described in this Policy. | Required information | Details | | --- | --- | | Controller name | QReasyUse@gmail.com | | Contact/service address | QReasyUse@gmail.com | | Privacy email | QReasyUse@gmail.com | | Website | qreasyuse.com |

This Policy applies to website visitors, people who contact us by email, and administrators. It does not cover third-party sites or services reached through outbound links.

2. QR-code content The QR generator is designed to process the information you enter and uploaded logo files inside your browser (client-side). We do not intentionally transmit or store QR content—such as URLs, Wi-Fi passwords, vCard details, phone numbers, text, email content, or logos—in our database. This statement applies only to the QR content itself. Loading the site and using a feature may still cause infrastructure providers to process technical request data, and the site may count usage events that do not include the QR payload. Your browser, extensions, network provider, device, and destination websites may also process information under their own policies. You are responsible for having an appropriate right or lawful basis before encoding another person’s personal data, trademarks, logos, or other third-party content.

3. Categories of information processed | Category | Examples | Source | | --- | --- | --- | | Preference data | Language setting (qre_locale) and consent choices (qre_consent) | Your browser | | Technical request data | IP address, user agent, time, requested route/URL, referrer, response status, and security data | Vercel/network systems automatically | | Usage analytics | Aggregate page, country and device metrics, and feature events that exclude QR payloads | Vercel Web Analytics and/or site counters | | Contact data | Email address, name if supplied, message contents, and attachments you send | When you email us | | Administrator data | Admin account, sessions, sign-in IP/device data, and audit logs | Administrators and Supabase Auth | | Advertising data (when enabled) | Cookie/local-storage identifiers, IP, browser/device data, consent signals, and ad interactions | Google and advertising partners | | Affiliate click data (when enabled) | Affiliate/campaign identifiers, referring page, and technical data sent by the browser to the destination | Browser and Shopee/link providers |

4. Purposes and legal bases | Purpose | Typical legal basis | | --- | --- | | Operate the site, remember language, and record consent choices | Necessary to provide requested functionality, legitimate interests, and/or legal compliance | | Security, abuse prevention, troubleshooting, and audit logging | Legitimate interests in security and legal compliance | | Respond to questions, complaints, and rights requests | Taking steps at your request, legitimate interests, and legal compliance | | Cookieless analytics and service improvement | Legitimate interests, with data minimisation and de-identification measures | | Serve, measure, or personalise advertising | Consent where required by law or provider policy, and other lawful bases for restricted-data ad modes where permitted | | Operate affiliate links and commission attribution | Legitimate interests and performance of affiliate arrangements, with clear disclosure |

Where we rely on legitimate interests, we balance those interests against your rights and freedoms and provide a right to object where required by law.

5. Recipients and service providers | Provider/recipient | Role or purpose | Information potentially involved | | --- | --- | --- | | Vercel | Hosting, network delivery, security logs, and Web Analytics | Technical request data and usage statistics | | Supabase | Article database, admin backend, authentication, and audit logs | Admin and backend data; general-user QR payloads should not be included | | Google AdSense/Google | Advertising, measurement, fraud prevention, and consent management when enabled | Identifiers, cookies/IP, device data, usage data, and consent signals according to configuration | | Shopee and affiliate-link providers | Open product pages, attribute referrals, and calculate commission after a click | Technical request data, referrer, and affiliate identifier | | Advisers and lawful authorities | Legal, accounting, security, enforcement, or compliance | Only what is necessary for the relevant matter |

A provider may act as our processor or as an independent controller for its own activities. Please review the provider’s own privacy information as applicable.

6. International transfers Our providers may process or store data outside Thailand, including a Supabase project hosted in the Singapore region and infrastructure or subprocessors used by Vercel or Google in multiple countries. Where a transfer occurs, we use legally required or appropriate contractual and service-level safeguards where available.

7. Retention | Item | Period or criterion | | --- | --- | | qre_locale and qre_consent | Up to 1 year from the latest setting or update, unless you delete them sooner | | Email correspondence | Generally up to 24 months after the last contact, unless needed for a dispute, legal obligation, or security matter | | Administrator audit logs | Generally up to 12 months, unless relevant to a security incident, investigation, or legal requirement | | Infrastructure logs and analytics | For the period necessary under account settings and provider policies, with restricted access and periodic necessity review | | Browser-processed QR payloads and logos | Not intentionally stored by us, so there is no retention period in our systems | | Advertising/affiliate data | According to consent settings and the retention practices of Google, Shopee, or the relevant provider |

8. Your rights - Withdraw consent at any time, without affecting processing that was lawful before withdrawal. - Request access to and a copy of your personal data and, where required, information about its source. - Request data portability in a machine-readable format where the legal conditions apply. - Object to processing, particularly processing based on legitimate interests or direct marketing. - Request erasure, destruction, or anonymisation. - Request restriction of use. - Request correction so data is accurate, current, complete, and not misleading. - Lodge a complaint with Thailand’s Personal Data Protection Committee/Office if you believe processing is unlawful. Rights are subject to statutory conditions and exceptions. To exercise a right, email QReasyUse@gmail.com. We may request information necessary to verify identity and will respond within the period required by law.

9. Cookies and consent choices See the Cookie and Similar Technologies Policy for details. You can change or withdraw consent through “Cookie Settings” in the footer. Withdrawal will stop optional scripts from loading on subsequent visits as configured, but third-party cookies already placed may remain until they expire or you delete them through your browser.

10. Security and personal-data breaches We use measures appropriate to risk, such as encrypted transport, role-based access, administrator authentication, event logging, software updates, backups, and provider review. No system is completely secure. If a personal-data breach occurs, we will assess the risk and notify Thailand’s Personal Data Protection Office without undue delay and, where feasible, within 72 hours after becoming aware, unless the breach is unlikely to risk individuals’ rights and freedoms. We will notify affected individuals without undue delay where the risk is high, as required by law.

11. Children The site is not designed or marketed specifically to children and has no general-user accounts. If consent is required for a minor’s data, we will follow Thai rules on age and parental or guardian authority.

12. External links and QR safety External links, ads, and affiliate links are governed by the destination’s policies. We do not control their content or data practices. A static QR code embeds information in the image. Anyone who scans it may read that information. Do not place personal passwords, access tokens, national ID numbers, or other secrets in a QR code intended for public display, and obtain permission before encoding someone else’s information.

13. Changes to this Policy We may update this Policy when the site, providers, or applicable law changes. We will display the latest update date and obtain fresh consent where a change legally requires it.

14. Contact QReasyUse@gmail.com QReasyUse@gmail.com Email: QReasyUse@gmail.com