Privacy Policy
Last updated: 29 August 2026
SWAPQR (qr.bnj.app) is operated by Hugo Software. This page explains what happens to data — yours, and that of the people who scan your codes.
Static and photo codes
A static QR code and a photo (dithered) QR code are generated entirely inside your browser. The text, link or photograph you put into them is never sent to our servers. There is no endpoint that accepts it.
Dynamic codes — what the server stores
A dynamic code points to a short address on qr.bnj.app that forwards the scanner to the destination you chose. To make that work the server stores, for each dynamic code:
- the short code and its destination URL;
- the label you gave it;
- the licence code that owns it;
- creation and last-edit times.
Deleting a code deletes this record and its scan events.
What happens when someone scans a dynamic code
The scanner's phone requests the short address and is forwarded. That request is recorded as a scan event containing only:
- the time;
- a two-letter country code, derived from the request at the network edge (the IP address itself is not stored);
- a device family (phone / tablet / desktop) taken from the browser's user-agent string — not the full string;
- the referring page, if the browser sent one.
No cookie is set on the scanner's device, no identifier is created for them, no camera or location permission is involved, and nothing about who they are is known to us or to you. Counts of "unique" scans are therefore approximate.
If you are the person who scanned a code: the destination you were forwarded to is chosen by the code's owner, not by us, and has its own privacy policy.
Licence records
Pro is unlocked by a licence code (format BNJ-XXXXXXXX). The backend stores the code, the subscription status and plan, and the Stripe customer id. There are no accounts, no passwords and no email addresses; we deliberately do not store the email address Stripe collects for billing.
Payments
Payments are handled by Stripe. Card details are entered on Stripe's own checkout page and never pass through our servers. Stripe processes that data as an independent controller under its own privacy policy (stripe.com/privacy).
Analytics on this site
We use a self-hosted installation of Umami (uma.bnj.app) to count page views of qr.bnj.app itself. It is cookieless and stores aggregate figures only: page views, referrer, country, browser and device type. It is separate from the scan statistics described above.
What we do not do
- No advertising SDKs, no third-party trackers, no data brokers.
- No selling or sharing of personal data.
- No profiling and no automated decision-making.
Legal bases (GDPR / KVKK)
Where the GDPR or Turkish KVKK applies, we rely on performance of a contract for the licence record and the dynamic-code records required to provide the service, and legitimate interest for the minimal, non-identifying scan events and aggregate analytics.
Your rights
You may ask what licence or code data we hold, ask for it to be corrected, or ask for it to be deleted. Please quote your licence code — it is the only identifier we have. Deleting a licence record ends Pro on that code and makes its dynamic codes stop forwarding.
Retention
Dynamic-code records and their scan events are kept while the code exists. Licence records are kept while the subscription is active and for as long as we are required to keep billing records afterwards. Aggregate analytics are kept indefinitely in aggregate form.
Children
SWAPQR is a business tool and is not directed at children.
Changes
If this policy changes, the date at the top of this page changes with it.