Acceptable Use Policy
Last Updated: August 17, 2026
Note (August 17, 2026): §6 no longer treats termination as forfeiture of your account balance. That balance is money you paid us and have not yet spent, and keeping it is a penalty we are not entitled to impose for a breach of a policy: on termination we return the unspent funded part, unless a law or a competent authority requires us to withhold it, or the balance is itself the proceeds of the abuse. Bonus credit, which you never paid for, is not returned. One-time purchases and monthly add-on fees are still not refunded. §6 also now records what was already the practice — that we tell you the reason for an enforcement decision and that you can contest it. §6.1 and §6.2 stopped promising a record that removal destroys. Deleting a hosted file deletes its database row together with the stored object, so the upload record does not outlive the upload; §6.2 says so, and §6.1 now describes repeat-infringer attribution the way it actually works — taken from the file's row while the file is still there, and kept in the report or notice we are acting on, which does survive.
Note (August 13, 2026): A gambling clause (§2.6) was added, prohibiting unlicensed paid-stake games of chance, lotteries, and deceptive prize claims. Three more prohibitions followed: adult content and services (§2.7), intellectual-property infringement (§2.8), and §2.9, which explains that those three exist because our payment processor and the card networks restrict which businesses we may serve — not because we have decided the material is unlawful. A new §3 governs content you host with us: what may be stored under our domains, the limits that apply, and the fact that a hosted file is reachable by anyone holding its link. §1 and the monitoring section were reconciled — the Policy used to say we do not review destinations at all while the monitoring section described automated checks. Both now say the same thing: we run narrow automated checks and we act on reports, and we do not pre-screen. That section also dropped a claim we could not stand behind — we do not check destination domains against malware or reputation feeds. The formal route for reporting unlawful content moved to the Notice & Takedown Policy, and §6.1 sets out when we terminate repeat infringers. Sections after §2 were renumbered accordingly.
Note (June 13, 2026): The content-enforcement wording (then §3, now §4) was revised — we previously implied we could not inspect encrypted URLs; in fact our systems can access destinations while operating the Service.
This Acceptable Use Policy ("AUP") defines the acceptable standards for using eqr.link ("Service") to create QR codes and redirect links. It applies to all users, customers, and visitors who access or use our Service.
By using the Service, you agree to comply with this AUP. If you violate this AUP, we reserve the right to immediately suspend or terminate your account and block your QR codes and redirect links without prior notice.
1. User Responsibilities
The Service provides redirect links and QR codes that route scanners to user-designated destination websites. Some features also store content you supply on our own infrastructure and serve it under our domains.
- Content Responsibility: You are solely responsible for the content and safety of the destination URLs you associate with your QR codes.
- Third-Party Destinations: We do not control the destination websites you configure. Scanners access them at their own risk.
- No Pre-Publication Review: We do not routinely conduct manual pre-publication review of destination websites or of content you host with us, and we are under no general obligation to monitor what you publish. We do operate the automated checks described in Section 4, and we investigate reports we receive. Where we find content that breaks this Policy, we block or disable it.
- Hosted Content: Where a feature stores your content on our infrastructure and serves it under our domains, Section 3 applies in addition to this Section.
2. Prohibited Content and Behaviors
You are strictly prohibited from using the Service to create QR codes or redirect links that route to websites containing or promoting any of the following, and from hosting any of it with us:
2.1. Phishing and Deception
- Credential Harvesting: Sites designed to mimic login pages (e.g., banks, email providers, social networks) to steal user credentials.
- Impersonation: Sites that impersonate brands, governments, organizations, or individuals without authorization to deceive users.
- Social Engineering: Deceptive pages designed to trick users into revealing sensitive personal or financial information.
2.2. Malware and Security Threats
- Harmful Software: Sites that distribute malware, ransomware, spyware, trojans, viruses, rootkits, or keyloggers.
- Exploits: Pages containing browser exploits or drive-by download triggers.
- Wallet-Draining: Deceptive Web3 applications, smart contract authorization requests (e.g., fraudulent
approveortransfercalls), or phishing pages designed to steal cryptocurrency or digital assets from web3 wallets.
2.3. Scams and Fraud
- Financial Scams: "Get-rich-quick" schemes, fake giveaways, fraudulent cryptocurrency investment platforms, or sweepstakes scams.
- Pyramid and Multi-Level Marketing: Pyramid selling, chain-referral schemes, and multi-level marketing programmes in which participants earn principally from recruiting other participants rather than from selling a real product or service to end customers.
- Deceptive Advertising: E-commerce sites that engage in bait-and-switch tactics, baiting, or failing to deliver purchased goods.
2.4. Abuse and Spam
- Spam Redirects: Using QR codes in unsolicited email campaigns, SMS spam, or comment spam.
- Aggressive Redirection: Creating loops, rapid successive redirects, or pages that prevent users from using the "Back" button in their browser.
2.5. Illegal and Harmful Content
- Child Exploitation: Any material containing child sexual abuse material (CSAM) or exploiting minors.
- Violence and Hate: Content that promotes violence, physical harm, hate speech, or harassment against protected groups or individuals.
- Regulated and Illegal Goods: Sites facilitating the sale or supply of narcotics, controlled substances and their precursors, prescription-only medicines dispensed without a valid prescription, tobacco and nicotine products, firearms, ammunition, explosives, weapon parts, or any other regulated good offered without the licences and age controls required where the buyer is. Counterfeit and unauthorised branded goods are covered by §2.8.
2.6. Gambling and Games of Chance
- Unlicensed Gambling: Casino games, sports betting, poker, lotteries, scratch cards, or any game of chance in which participants pay — in money or money's worth — for the chance to win, without holding the licences required in every jurisdiction where participation is possible.
- Deceptive Prize Claims: Telling a scanner they have won when there is no prize, or requiring a payment, premium-rate call, or purchase to claim a prize.
2.7. Adult Content and Services
Most of this material is lawful, and we are not saying otherwise. We prohibit it for the narrower reason set out in §2.9: our payment processor and the card networks do not permit it on an account like ours, and a single violating code puts the Service at risk for everyone using it.
- Sexual Services: Escort services, prostitution, and the arrangement, brokering, or advertising of sexual services.
- Adult Media: Pornography and other sexually explicit material intended for an adult audience, in any form — video, imagery, audio, text, or live streaming — including paid, subscription, or pay-per-view access to it.
- Generated Material: Material of the kind described above is prohibited whether it was recorded or synthetically generated. How it was made makes no difference.
2.8. Intellectual-Property Infringement
- Unlicensed Content: Selling, distributing, or providing access to music, film, television, books, software, games, or any other copyrighted work without the rights holder's authorisation, including routing scanners to sites that do so.
- Counterfeit and Unauthorised Goods: Counterfeit merchandise, replicas presented as genuine, and the unauthorised sale of branded or designer goods and services.
- Marks and Names: Using another party's trade mark, trade name, or get-up in a way that suggests an endorsement, licence, or affiliation that does not exist. Impersonation intended to deceive a scanner is separately prohibited by §2.1.
2.9. Payment Eligibility and Sanctions
- Why §2.6 to §2.8 exist: Gambling, adult material, and infringement are not prohibited here only because they can be unlawful. They are prohibited because our payment processor and the card networks restrict which businesses we may serve, and we cannot keep the Service running for anyone if we ignore those restrictions. The current list is Stripe's Prohibited and Restricted Businesses policy. Those rules change, and this Policy changes with them.
- Sanctioned parties and places: You may not use the Service on behalf of a sanctioned person or entity, or from a country or territory under comprehensive sanctions. The covenant and the representation you give us on this are in the Terms of Service, §4.1.
3. Content You Host With Us
Some features store your own content on our infrastructure and serve it under our domains — today the file hosting add-on, served from content.eqr.link, and lead capture forms. This Section governs that content and applies in addition to Section 2.
3.1. Hosting is ancillary to your QR codes
File hosting exists to carry the material your own QR codes point at. The Service is not a file-sharing, backup, distribution, or general website-hosting service, and you must not use it as one — no redistribution hubs, no using a hosted file as a download mirror or as a free content-delivery network for a site you run elsewhere, and no bulk uploading unrelated to codes in your account.
3.2. No anonymous uploads, no public index
Only a signed-in account holder can upload. Every upload is recorded against the account that made it and the time it was made. We publish no directory, listing, search, or feed of hosted content, and hosted files are served with instructions to search engines not to index them.
3.3. A link is not a lock
Each hosted file has an unguessable address. That is a barrier to discovery, not a permission system: anyone who has the link can open the file, without signing in. Treat a hosted file as published. Do not host material you would not hand to a stranger, and do not use hosting to store other people's identity documents, credentials, health records, or financial records.
3.4. You must have the rights, and you carry the responsibility
You must own what you upload or hold the rights needed to store it with us and to let us serve it to anyone who opens the link. You keep ownership of your content; you grant us only the limited right to store, copy, and transmit it so that the feature works. You are responsible for the accuracy, legality, and safety of everything you host with us, however it was produced.
3.5. Limits we enforce
- 100 MiB per file (about 105 MB), and your account's storage quota across all of your files.
- A limit on how many uploads one account may make per hour, and rate limits on how often a single hosted file may be fetched.
- Only file types we can validate: PDF, PNG, JPEG, GIF, WebP, and SVG that we have sanitised. The name must match the contents — we take the expected type from the file extension, then verify it against the file's own bytes and decode the file in full. What your browser declares the type to be is ignored. Anything we cannot validate is rejected.
- We re-encode uploaded images, which removes their embedded metadata, including any location recorded by the camera. PDFs are checked for structural integrity and are otherwise stored as you sent them.
3.6. Prohibited in hosted content
Everything in Section 2 applies. In addition, you must not host:
- Material that infringes anyone's copyright, trademark, or other intellectual property rights, including pirated media, software, or paid publications.
- Child sexual abuse material, or any material that sexually exploits a minor.
- Malware, exploits, credential stealers, or anything designed to compromise a device.
- Content impersonating another person, business, brand, or public authority.
- Content whose purpose is to deceive someone into surrendering credentials, money, or personal data.
- Terrorist content, as defined by Regulation (EU) 2021/784.
3.7. Our domain, our reputation
Content hosted on our domains borrows their reputation. Material that would cause eqr.link or content.eqr.link to be flagged by a browser, mail provider, or security vendor is prohibited on that ground alone, whatever else it is, because a flag against our domain breaks every customer's QR codes at once.
4. Monitoring, Automated Checks, and Enforcement
We do not review destinations or hosted content before they go live. What follows is what the Service actually does, and the limits are as much a part of it as the controls.
- Structural Validation: Every destination URL and webhook endpoint you configure is checked when you save it — scheme, length, and host. We reject targets that resolve to loopback, private, link-local, or cloud-metadata addresses, and we check a webhook host again before each delivery in case it has since been repointed. This protects our infrastructure from being used to reach networks it should not reach. It tells us nothing about whether a destination's content is lawful.
- No Content or Reputation Screening: We do not check destination domains against malware, phishing, or domain-reputation feeds, and we do not scan destination pages. If that changes, this section will say so.
- Hosted Content: We validate every uploaded file against its own bytes and decode it in full before storing it (§3.5), re-encode images so that embedded metadata does not survive, and serve hosted files from a separate, cookieless domain as downloads, under a policy that prevents them from running code. We do not currently scan uploads for malware and we do not run automated content matching. Hosted content is moderated reactively, on notice — see Section 5 and the Notice & Takedown Policy.
- Access for Investigation: Destination URLs are stored encrypted, but the keys are ours, so our systems can read a destination when we need to act on a report. Encryption is not a reason we cannot investigate.
- Reactive Enforcement: When a report reaches us, or we otherwise learn that a code, link, or hosted file breaks this Policy, we investigate and act — blocking the link, deleting the code or the file, or banning the account. Enforcement is driven by what we are told and what we find, not by continuous surveillance of your content.
5. Reporting Abuse
We take abuse reports seriously. If you find a QR code, redirect link, or hosted file on eqr.link or content.eqr.link that breaks this Policy, tell us:
- Email: abuse@eqr.link
Please include:
- The short URL, the hosted file's full address, or a copy of the QR code image.
- The destination URL, if you know it.
- A short description of the problem (for example, "phishing page mimicking a bank login").
If you are claiming that content is unlawful — copyright or trademark infringement, defamation, illegal goods, terrorist content, or child sexual abuse material — use the Notice & Takedown Policy instead, and write to the same address, abuse@eqr.link. That policy sets out what your notice must contain, how we handle it, and how the person who posted the content can respond.
6. Enforcement and Account Termination
If we determine that you have violated this AUP:
- We will immediately block the offending redirect link(s) and remove the offending hosted content.
- We may suspend or permanently terminate your account.
- We may report illegal activities to relevant law enforcement authorities.
- We tell you why, unless a law forbids us from telling you, and you can contest the decision by writing to abuse@eqr.link or support@eqr.link. A person reads it.
- We will not refund one-time purchases or monthly add-on fees for accounts terminated for violating this Policy.
- Your account balance is different, and we do not keep it. It is money you paid us and have not yet spent, so on termination we return the unspent funded part. We may hold it while we investigate, and we keep it only where a law or a competent authority requires us to withhold it, or where the balance is itself the proceeds of the abuse — topped up with a stolen card, for instance. Bonus credit, which we granted and you never paid for, is not returned. Section 6 of the Refund & Cancellation Policy sets out the whole procedure.
None of this affects rights you have under mandatory consumer law.
6.1. Repeat Infringers
We terminate, in appropriate circumstances, the accounts of users who repeatedly infringe the intellectual property rights of others.
- We keep a record of every infringement notice we act on and of the account whose content it concerned — but the record is one we make, not a by-product of the removal. A notice sent to abuse@eqr.link — the address in §5, and the route we publish — stays in that mailbox. Where a report about a file also reaches our report intake, it is written to a record of its own, and that record stays after the file it concerns is gone: it holds what was reported, the reason given, the address the reporter gave us if they gave one, and when it arrived. Attribution to an account comes from the file's own database row, which names the account that uploaded it and the moment it was uploaded — and we read it while the file still exists, because deleting the file deletes that row. See §6.2.
- Repeated valid infringement notices against the same account lead to termination of that account.
- We may terminate on a single notice where the infringement is flagrant or commercial in scale, or where the account exists to evade an earlier termination.
- A notice does not count against an account where the complainant withdraws it, where we conclude it was invalid, or where the account holder shows us the use was authorised.
- A terminated account holder may not open a new account. We may block re-registration and remove re-uploaded content without further notice.
6.2. What removal means
Removing a hosted file deletes it, including every stored version of it — we do not keep a hidden copy, and we cannot put the file back afterwards. The upload record goes with it. Deleting a file deletes the database row that named the uploading account, the upload time and the file name; there is no tombstone left behind, and we would rather tell you that than let you believe we hold a shadow index of everything anyone has ever deleted. What survives a removal is what we wrote down while acting on it — the report or the notice itself, and how we handled it — which is why §6.1 describes attribution as something we take at the time, not something the database keeps for us afterwards. If we later conclude that a removal was wrong, we will say so and you may upload the material again; it will get a new address, because the old one is gone. Where a competent authority requires us to preserve material, we do not delete it for as long as that requirement lasts, and that is the one case in which the file and its row both stay.