Privacy policy

Last updated 17 August 2026. Qrosshatch is a service operated by Foxbit Software.

This explains what Qrosshatch collects, why we have it, and what you can ask us to do about it.

The short version

  • We do not use analytics, advertising, or tracking cookies.
  • Scans are counted, not tracked. We record how many times a code has been used and nothing whatsoever about the person who used it.
  • We check destinations against a published list of phishing and malware sites when you save them, and we never record an IP address in our database.
  • We do not sell your personal information, and we do not share it with anyone for their own purposes.
  • You can ask us to delete your account, and we will do it within 30 days.

Who we are

Qrosshatch is operated by Foxbit Software, based in Manitoba, Canada. Foxbit Software is the organisation accountable for personal information handled through the service under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).

Everything reaches us through the support form, including privacy requests and account deletions.

What we collect

Your account

When you create an account we store your email address, a display name if you set one, a profile image if you upload one, the date the account was created, the number of codes your account is allowed to hold, and flags recording which sign-in methods are turned on.

We never store your password. Sign-in is handled by Google's Firebase Authentication, which holds credentials separately from our own database.

Passkeys and two-factor authentication

If you register a passkey, we store its public key, an identifier, a signature counter, which transports it supports, whether it is backed up, the kind of device it is, and a nickname you choose.

A passkey's private key never leaves your device, and we never receive it. If you unlock a passkey with a fingerprint or with face recognition, that check happens on your own device — the biometric data is never sent to us, and we have no way to access it.

If you turn on two-factor authentication, the shared secret behind your authenticator app is held by Firebase Authentication rather than in our database.

While a passkey sign-in or registration is in progress we store a short-lived challenge. These expire automatically after five minutes and are deleted.

Your QR codes

For each code you create we store the title and description you give it, the destination it points to, whether it is active, the styling you choose, and its scan counts.

Creating a code, and changing where it points

Two things happen when you create a code or change its destination. Both are about preventing abuse of the service, not about running your account. Neither of them happens when someone scans a code — see scan counts below.

We check the destination. The address you enter is sent to Google's Web Risk service, which reports whether it appears on a published list of phishing or malware sites. If it does, we refuse to save it — or stop sending scans to a code that was already pointing there, and tell you why in the editor. We also re-check saved destinations from time to time, because an address that was safe when you set it can be compromised afterwards. Only the address is sent. Nothing identifying you or your account goes with it.

We do this because a redirect service that will forward anyone anywhere becomes a tool for disguising malicious links — and if that happens, browsers begin warning people away from every Qrosshatch code, including yours.

We limit how many codes can be created. To stop automated bulk creation we keep a short-lived count against your account. It records how many codes that account has made in the last hour and the last day, and nothing else — no address, no device, and nothing about the request beyond that it happened.

We do not record your IP address anywhere in our database, for this or for anything else. Creating a code and changing where one points both require you to be signed in, so your account is the only thing we need to count against. Google's own infrastructure logs, described below, are separate from this and are not something we control.

Scan counts

When someone scans one of your codes, we add one to a running total and to a counter for the current month, and update a timestamp. That is the entire record.

We do not record IP addresses, device or browser information, referrers, locations, or any row representing an individual scan. We cannot tell you who scanned a code, where they were, or what they used, because we never collect it. If you need that kind of reporting, Qrosshatch is not the right tool.

Operational logs

Qrosshatch runs on Google Cloud, and Google's own infrastructure produces operational request logs that can include IP addresses. This is true of every request to the service — a scan, a page view, saving a code — and not only of the redirect. Those logs are generated and retained by Google as part of running the platform. They are not written into Qrosshatch's database, we do not use them for analytics or reporting, and nothing we say elsewhere about not storing IP addresses is a claim about them.

Files you upload

Profile images and code logos are stored in a folder specific to your account. Uploads are limited to 1 MB and to PNG, JPEG, or SVG files.

Messages you send us

If you use the support form we receive what you write, and your email address if you give us one, so that we can reply. The form is delivered by Crunchforms, and Cloudflare Turnstile checks that submissions are not automated.

What we do not collect

  • No analytics. There is no analytics package in the site, no measurement of what you look at, and no session recording.
  • No advertising. No ad networks, no pixels, no profiling, no audience building.
  • No tracking cookies, and nothing that follows you between sites. The one third party that can set anything is Cloudflare Turnstile, the spam check on the support page, and only on that page — it is there to tell a person from a bot, not to identify you.
  • No sale of personal information, to anyone, ever.

Your browser stores two things for this site: a Firebase Authentication session, so that you stay signed in, and a small preference recording whether you chose the light or dark theme. Neither is used to track you.

Why we hold what we hold

We use your account information to run your account and to let you sign in. We use your code data to operate the redirects — which is the product. We use scan counts to show you how often a code has been used. We use messages you send us to answer them. We do not use any of it for anything else.

Who else processes it

  • Google (Firebase and Google Cloud) — hosting, database, file storage, authentication, and the Web Risk safety check on destination addresses.
  • Crunchforms — delivery of support-form messages.
  • Cloudflare — the Turnstile bot check on the support form.

Our infrastructure runs in Google's us-central1 region, so personal information is stored and processed in the United States, outside Canada. While it is there it may be accessible to US authorities under US law. PIPEDA allows transfers like this provided the organisation remains accountable for the information, which we do.

Security

Access rules stop one account from reading another's codes, files, or account record. The flags that govern how an account can sign in are server-owned and cannot be changed from a browser. Passkeys and two-factor authentication are available on every account and we would encourage you to use them.

No service can promise perfect security.

Keeping and deleting your information

We keep your information for as long as your account exists.

To delete your account, send a request through the support form and choose Delete my account. We will complete it within 30 days. Deletion removes your account record, your codes, your uploaded files, your registered passkeys, and your sign-in credentials.

Deleting your account stops your codes redirecting immediately, and it cannot be undone. Anything already printed will stop working, so replace it first.

Residual copies may remain in encrypted backups for a short period after deletion, after which they are overwritten in the ordinary course.

Your rights

Under PIPEDA you can ask us to give you a copy of the personal information we hold about you, ask us to correct it if it is wrong, and withdraw your consent to our holding it — which, for this service, means closing your account.

Ask through the support form, choosing Privacy request. We will respond within 30 days.

If you are not satisfied with how we handle a request, you can complain to the Office of the Privacy Commissioner of Canada.

Children

Qrosshatch is not intended for children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account, tell us through the support form and we will remove it.

Changes to this policy

If we change this policy we will update the date at the top. If a change materially affects how we handle your information, we will give you notice by email to the address on your account before it takes effect.

Contact

Privacy questions, access requests, and deletions all go through the support form.