QRdy reference
Privacy Policy
How QRdy collects, uses, stores, and protects personal information across the product.
Last updated: June 2026
1. Who we are
QRdy Limited is a New Zealand company that operates QRdy, a service that helps businesses give customers real-time status updates via QR codes. This policy explains what personal information we collect, why we collect it, and how we handle it under applicable privacy and data protection laws.
QRdy serves customers in multiple markets, including New Zealand, the United Kingdom, Ireland, the United States, Australia, and Canada. Where local privacy or electronic communications rules apply, we aim to explain clearly how QRdy uses cookies and similar browser storage and to keep those uses tied to security, login, service continuity, and core product operation rather than advertising.
2. What information we collect
From customers (people who scan a QR code):
- Your name (entered when checking in)
- Your email address (optional - only if you choose to receive email notifications)
- Your WhatsApp phone number (optional - only if you choose to receive WhatsApp notifications)
- Your browser push subscription details if you opt in to push notifications on a supported device
- Your order number if the business asks for one as part of the job or order flow
From businesses (operators who use QRdy):
- Business name
- Email address used to log in
- Business phone number, address, logo, and subscription details
- Business-account age and authorization attestation record
- Admin recovery WhatsApp details if you choose to set up account recovery
Automatically collected:
- IP address or first-party browser identifier used for abuse prevention and rate limiting
- Job status events and timestamps related to the tracker lifecycle
- Limited operational telemetry through hosting and error-monitoring providers
3. Why we collect it
- To display your job status on the status page
- To send you email or WhatsApp notifications about your job (only if you opted in)
- To send browser push notifications about your job if you opted in on a supported device
- To allow the business to identify your job in their dashboard
- To prevent abuse of the service, rate limit public actions, and prevent accidental duplicate submissions
- To secure business accounts and admin recovery flows
4. How we store and protect it
- Customer email addresses are encrypted at rest using AES-256-GCM encryption
- Customer WhatsApp numbers are encrypted at rest when stored
- All data is stored in Supabase, a US-based cloud database provider
- Data is transmitted over HTTPS at all times
- Tracker records have a validity window chosen by the business, up to 30 days
- After validity ends, a tracker can no longer be updated and is kept only for history and support during the plan retention period
5. Who we share it with
We do not sell your data. We use third-party services to operate QRdy — including hosting, authentication, payments, email, and real-time delivery. These providers process data only as needed to run the service and are bound by appropriate data processing terms. Some providers are based outside New Zealand; by using QRdy you consent to this processing.
If you opt in to WhatsApp notifications, your messages are delivered via Meta Platforms (WhatsApp Business API). See Meta's Privacy Policy.
QRdy Limited is based in New Zealand. Where personal information is transferred outside your country, we rely on our providers' contractual and operational safeguards and handle requests in line with applicable New Zealand, UK, EU, and other relevant privacy obligations.
6. Your rights
Depending on where you live, you may have the right to:
- Ask what personal information we hold about you
- Request a correction if it is wrong
- Ask us to delete your information
- Request an export of your information where applicable
- Object to or restrict certain processing where applicable law gives you that right
To exercise any of these rights, email us at support@alwaysqready.app. We currently handle access, correction, deletion, and export requests manually. We will respond within a reasonable period and in line with applicable legal requirements.
7. Data retention
- Customer job data: retained according to the business plan retention period after the tracker closes or expires
- Pro plan tracker history: retained for up to 90 days
- Business plan tracker history: retained for up to 1 year
- Anonymous/direct tracker history: retained for up to 7 days unless deleted earlier on request
- Non-subscribed business tracker history: retained for up to 30 days unless deleted earlier on request
- Business account data: retained while the account is active; deleted on request
- Email notification logs: not retained after delivery
- WhatsApp phone numbers: encrypted at rest; deleted when the associated tracker record is deleted or on request
- Push subscription records: retained only while needed for active tracker notifications and removed when a tracker is deleted or the subscription is removed
8. Notification opt-out
If you opted in to email or WhatsApp notifications, you can unsubscribe at any time by clicking the unsubscribe link included in any notification we send, or by emailing support@alwaysqready.app. Once unsubscribed, we will not send further notifications for your job.
If you opted in to browser push notifications, you can also stop those notifications from your device or browser settings.
9. Cookies and tracking
QRdy uses Vercel Analytics and Vercel Speed Insights to measure page traffic and product performance, and Sentry to monitor application errors and reliability. We do not use advertising cookies or tracking pixels. We use these tools for operational measurement, troubleshooting, and security monitoring rather than for behavioral advertising.
We may use first-party cookies and similar browser storage to maintain login state, support security and abuse prevention, remember product preferences, keep tracker actions working in the current browser session, and support browser notifications you explicitly request. These technologies are not used for advertising or cross-site tracking.
The table below summarises the main cookies and browser storage QRdy currently uses. Where possible, we rely on storage that is tied to security, login, service continuity, or the specific action you requested rather than advertising or third-party profiling.
| Name / type | Purpose | Typical duration | Notes |
|---|---|---|---|
| `qrdy_bid` cookie | Identifies a browser for public rate limiting, abuse prevention, and service protection on unauthenticated flows. | Up to 30 days | First-party, httpOnly, not used for advertising or cross-site tracking. |
| Supabase auth cookies | Keep business users signed in after magic-link authentication and support secure session handling. | Session-based or until refreshed/expired | Strictly related to login and account access. These cookies are required for authenticated dashboard use. |
| `qrdy_admin_unlock` cookie | Maintains a short-lived admin unlock session for sensitive account and billing actions after passcode verification. | About 10 minutes | First-party, security-focused, not used for advertising or analytics profiling. |
| `sessionStorage` continuity data | Helps keep track of active tracker actions in the current browser session, such as claim or cancellation continuity and same-tab duplicate-submission protection. | Current browser session unless cleared sooner | Used for service continuity rather than advertising. Some values may include tracker-specific action tokens. |
| `localStorage` preference and helper data | Stores product preferences and feature-helper values such as theme choice and push-notification unsubscribe helpers. | Until changed or cleared | Used for product functionality and user-selected preferences, not for advertising or cross-site tracking. |
| Service worker and push subscription | Stores browser notification capability and a push subscription only if you choose to turn on browser notifications for a tracker. | Until you disable notifications, clear site data, or the subscription is removed | Used solely to deliver status notifications you requested. Not used for advertising or cross-site tracking. |
| Operational analytics and monitoring | Measures product performance, page traffic, reliability, and error conditions through Vercel Analytics, Vercel Speed Insights, and Sentry. | Varies by provider and event type | Configured for operational measurement and troubleshooting rather than behavioral advertising. |
We currently operate on the basis that the cookies and browser storage we use are tied to login, security, abuse prevention, service continuity, and core product operation rather than advertising. If QRdy introduces any non-essential cookies or similar technologies in future, we will update this policy and any required notice, consent, or preference controls before doing so.
10. Children and minors
Business accounts on QRdy are intended for adults who are at least 18 years old and authorized to act for the business. QRdy is not directed to children under 13.
Businesses are responsible for using QRdy lawfully with their customers, including where a customer may be a minor and parent, guardian, or other lawful authority may be required. If we become aware that personal information was collected from a child under 13 in a way that should not have happened, we may review and delete that information.
11. Changes to this policy
We may update this policy from time to time. The date at the top of this page shows when it was last changed. Continued use of QRdy after changes means you accept the updated policy.
12. Contact
For privacy questions or requests, contact QRdy Limited at support@alwaysqready.app. If you are not satisfied with our response, you may also contact the privacy or data-protection regulator in your region.
