Cookie Policy
Last Updated: August 17, 2026
Note (August 17, 2026): §3 described the scanner's consent banner as offering "Accept All / Reject All / Customize", with a per-category picker. The banner is real and the prior-consent promise is kept structurally — but it was never built with a category picker, and now it never will be: one QR code carries at most one pixel, from one platform, so there is nothing to pick between and offering the choice would have been decoration. §3 now describes what the page actually does: it names the platform by name, loads no third-party code until you answer, sends you straight on to the destination if you decline, and remembers your answer for that one QR code for six months. §2.3 also stops naming LinkedIn — the platforms we accept are Meta, Google and TikTok — and both sections now say plainly that the pixel belongs to the owner of the QR code, not to us. The cookie that stores your answer,
eqr_pixel_consent_<qr_id>, was described in §3 but missing from the table in §2.1; it is listed there now, because a cookie we set belongs in the list of cookies we set.
This Cookie Policy explains how eqr.link ("we", "us", or "our") uses cookies and similar technologies on our website, web application, and services. It should be read alongside our Privacy Policy.
1. What Are Cookies?
Cookies are small text files placed on your device (computer, tablet, or mobile) by websites you visit. They are widely used to make websites work more efficiently, provide secure authentication, and enable certain user features.
2. Classification of Cookies We Use
We classify our cookies into two main categories: Essential Cookies (necessary for the service to function) and User-Configured Third-Party Cookies (enabled by individual QR code creators).
2.1. Essential Cookies (Always Active)
These cookies are strictly necessary to provide the Service, secure your sessions, and maintain system preferences. They do not require consent under applicable laws.
| Cookie Name | Provider | Purpose | Type & Expiry | Security Properties |
|---|---|---|---|---|
eqr_token | eqr.link | Stores the secure PASETO session token to keep you authenticated in your dashboard. | Session / 24 Hours | HttpOnly, Secure, SameSite (Lax/Strict) |
eqr_lead_submitted_<form_id> | eqr.link | Placed on a scanner's browser after they submit a lead capture form. This bypasses the form on future scans of the same QR code. | Persistent / 1 Year | Secure, SameSite (Lax) |
eqr_lang | eqr.link | Remembers the interface language you chose with the language switcher, so the Service keeps using it on your next visit. Written only when you make that choice explicitly — never as a result of us detecting your language. The same value is mirrored in your browser's local storage. | Persistent / 1 Year | Secure, SameSite (Lax) |
eqr_pixel_consent_<qr_id> | eqr.link | Records the answer you gave the retargeting-pixel banner for one QR code, so we do not ask again on every scan. It holds nothing but the word granted or denied, and it is written only when you press one of the two buttons. Section 3 explains the banner. | Persistent / 6 Months | HttpOnly, Secure, SameSite (Lax) |
Note: Since these cookies are strictly functional, they cannot be turned off via our cookie consent banner. You can block them using your browser settings, but doing so will break core site functionality (e.g., you will not be able to stay logged in).
2.2. Third-Party Analytics (Cookieless)
We use Umami Analytics for website usage tracking. Umami is a privacy-first, open-source analytics platform. Umami does not use cookies, does not store individual IP addresses (IPs are hashed and salted), and does not track users across different websites. Consequently, no cookie consent is required for our default analytics tracking.
2.3. User-Configured Retargeting and Marketing Cookies
Our Service allows creators of dynamic QR codes to configure a retargeting pixel on their redirect interstitial page. We accept pixels from three platforms and no others: Meta, Google and TikTok.
- Who sets them: the cookies are set by that platform, not by us, and only if the owner of the QR code has configured a pixel and the scanner has accepted it.
- Whose decision it is: the pixel is chosen and configured by the owner of the QR code. We do not select it, we do not receive what it collects, and we cannot see the advertising audiences it builds.
- How many: one QR code carries at most one pixel, from one platform. There is no arrangement in which several ad networks are loaded from the same code.
- Consent Requirement: nothing loads until the scanner has been asked and has agreed. Section 3 describes exactly how.
3. Cookie Consent Banner (Scanner Experience)
When you scan a QR code whose owner has switched on a retargeting pixel, you do not go straight to the destination. You get a short page that asks you first.
- Nothing loads until you answer. The page you are shown contains no third-party code at all, and the Content-Security-Policy sent with it would not permit any to run. The pixel lives on a second page, which only exists once you have said yes.
- We name the platform. The banner tells you which company is about to be told that you opened this link — Meta, Google or TikTok — because "a tracking pixel" is not something anybody can meaningfully consent to. It also names the site you are heading for either way — the destination's host, printed on the page before you choose.
- Two answers, not three. You can accept the pixel, or continue without it. There is no per-category picker: one QR code carries at most one pixel from one platform, so a category chooser would be a menu with a single dish on it.
- Declining loads nothing at all. If you continue without tracking, we send you on to the destination with a plain redirect — no page, no script, no tracking image, nothing that could report the scan.
- Your answer is remembered for six months, for that QR code only. It is stored in a first-party cookie named
eqr_pixel_consent_<qr_id>that holds nothing but the wordgrantedordenied. Per code rather than per browser is deliberate: accepting one merchant's pixel says nothing about the next merchant's, and treating it as though it did would be manufacturing a consent you never gave.
Changing your mind. You can withdraw consent at any time (GDPR Art. 7(3)), and withdrawing costs you nothing — the destination is the same either way. The record of your answer is the first-party cookie above and nothing else, so deleting cookies for this site in your browser (Section 4) erases it, and the next scan of that code asks you again. If you do nothing, the record lapses after six months and you are asked again anyway.
Whose pixel it is. The pixel is configured by the owner of the QR code, not by us. We do not choose it, we do not receive what it collects, and we cannot see what it builds. What we do is ask you before it runs.
4. How to Manage Cookies via Browser Settings
You can control and manage cookies through your web browser's settings. Most browsers allow you to:
- See what cookies are set and delete them on an individual basis.
- Block third-party cookies.
- Block cookies from particular sites.
- Block all cookies from being set.
- Delete all cookies when you close your browser.
To learn more about how to manage cookies, visit the ICO's cookies guidance.
5. Contact Us
If you have any questions about our use of cookies, please contact us at support@eqr.link.