Your privacy matters to us. This Privacy Policy explains what information MrDev.Net LLC collects, how we use it, how we protect it, and what rights you have regarding your data. By creating an account or using the Service, you agree to the collection and use of information as described here.
1. Who We Are
QRGO2 is a dynamic QR code routing platform owned and operated by MrDev.Net LLC, headquartered in Sheridan County, Wyoming, United States. We operate qrgo2.com and provide tools that allow individuals and businesses to generate, manage, and analyze dynamic QR codes.
2. Information We Collect
2.1 Information You Provide Directly
When you register for an account or use our Service, we may collect:
- Account credentials — Username and password. Both are hashed using industry-standard cryptographic algorithms (Argon2/BCrypt) before storage. We never store your password in plain text and cannot retrieve it.
- Profile information — Name, email address, company name, and other details you provide during registration or account management.
- Billing information — Plan selections, billing cycle preferences, and discount codes applied. Payment processing is handled by PayPal, Braintree (a PayPal service), or Google Wallet. MrDev.Net LLC does not store credit card numbers, bank account numbers, or raw payment credentials on our servers. We store only tokenized references provided by the payment processor.
- QR code content — The destination URLs, vCard data, video links, photo albums, HTML snippets, social hub links, and any other content you configure behind your QR codes.
- Route configuration — PIN codes, passwords, or authenticator settings you create for gated content routes. PIN and password values are stored in hashed form and cannot be retrieved in plain text.
- Collection prompt responses — If you configure lead collection prompts on your QR codes, responses submitted by scanners are stored on your behalf. You are the data controller for this information.
- Affiliate information — If you enroll in the QRGO2 Affiliate Program, we collect your referral activity, commission history, and payout information including your PayPal email or other designated payout method.
- Support communications — Any messages, emails, or other communications you send to our support team.
2.2 Information Collected Automatically When Your QR Code Is Scanned
Every time someone scans one of your QR codes, our system automatically logs the following data (“Scan Data”):
- Timestamp — The exact date and time of the scan
- IP Address — Used to derive approximate geographic location. Raw IP addresses are one-way SHA-256 hashed on ingestion; the original address is immediately discarded.
- Geolocation — City and country derived from the scanner’s IP address. We do not collect GPS coordinates.
- Device Type — Whether the scanner is using iOS, Android, or another platform
- Browser — The browser used to open the QR code destination
- Route accessed — Which content route was served, including whether a gated route was accessed (but not the PIN or password used)
- Collection prompt interaction — Whether the scanner submitted or skipped a collection prompt
This Scan Data is aggregated into your analytics dashboard and is associated with your account, not with individual scanners as identified persons.
2.3 Information Collected Automatically From You
When you use the QRGO2 dashboard, we may automatically collect log data, session data, and device information for compatibility and security purposes.
3. How We Use Your Information
We use the information we collect to operate the Service, process billing, provide analytics, enforce usage limits, operate the affiliate program, communicate with you, maintain security, improve the Service, and comply with legal obligations.
We do not sell your personal information to third parties. We do not use your personal information or your QR code content for advertising purposes.
4. Scan Data & Scanner Privacy
When a person scans your QR code they become a “scanner.” Scanners are not QRGO2 account holders and interact with the Service only as visitors to your QR code’s destination.
- QRGO2 automatically collects Scan Data on behalf of the QR code owner every time a code is scanned.
- Scanners are not identified by name. Data is collected at the device and approximate location level only.
- If a QR code owner has configured a Collection Prompt, scanners may be asked to voluntarily provide personal information. Scanners providing information through a Collection Prompt are providing it directly to the QR code owner, not to MrDev.Net LLC.
- MrDev.Net LLC does not share scanner data with any third party except as described in Section 7.
If you are a scanner and believe a QR code is being used to collect data illegally or maliciously, contact us through our contact form.
5. Gated Routes & PIN Authentication
QRGO2 offers the ability to protect QR code routes with a PIN, password, or time-based one-time password (TOTP). When this feature is used:
- PIN and password values you configure are stored in hashed form. We cannot retrieve or display them in plain text.
- Failed authentication attempts are logged for security purposes including enforcement of lockout policies.
- The PIN or password entered by a scanner is never logged or stored after the authentication attempt is processed.
- TOTP secrets are stored in encrypted form and associated with your QR code record.
You are solely responsible for the secure distribution of any PINs or passwords you create and for the content served behind each gated route.
6. Collection Prompts & Third-Party Data
If you use QRGO2’s Collection Prompt feature to gather information from scanners:
- You are the data controller. MrDev.Net LLC acts as a data processor storing this information on your behalf.
- You are responsible for obtaining any required consents and complying with all applicable privacy laws including GDPR, CCPA, and CAN-SPAM.
- MrDev.Net LLC will not use data collected through your prompts for any purpose other than storing and displaying it to you.
- Data export — You may export your collection prompt responses from your dashboard at any time.
7. How We Share Your Information
We do not sell or rent your personal information. We may share it only with payment processors (PayPal, Braintree, Google Wallet), trusted service providers under contractual obligation, legal authorities when required by law, and in the event of a business transfer (with prior notice to you).
8. Data Retention
- Account data — Retained for the life of your account plus a reasonable period after termination
- Scan Data — Raw scan logs retained for a rolling 90-day window; aggregated statistics retained for the life of the account
- Invoice and billing records — Retained for a minimum of seven (7) years
- Collection prompt responses — Retained for the life of your account or until you delete them
- Hashed credentials — Deleted upon account termination
9. Security
Our security practices include credential hashing (Argon2/BCrypt), PIN and password hashing, tokenized payment handling, cookie-based session management with idle timeout, role-based access controls, full audit logging of administrative actions, and authentication lockout after repeated failed login attempts.
While we implement industry-standard security measures, no system is completely immune to breach. In the event of a security incident affecting your data, we will notify you as required by applicable law.
10. Your Rights
Depending on your location, you may have rights to access, correct, delete, port, restrict, or object to the processing of your personal data, and to withdraw consent where processing is consent-based. To exercise any of these rights, contact us through our contact form. We will respond within thirty (30) days.
If you are a resident of the European Economic Area and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection authority.
11. Cookies & Tracking
MrDev.Net LLC uses session cookies (required to maintain your logged-in state) and may use preference cookies to remember dashboard settings. We do not use tracking cookies to serve targeted advertising and do not participate in cross-site advertising networks.
Do Not Track & Global Privacy Control. Because there is no common standard for “Do Not Track” (DNT) and we do not track you across third-party sites, we do not respond to DNT signals. Where required by law, we honor a recognized Global Privacy Control (GPC) signal as an opt-out and disable non-essential analytics for that browser. As noted in Section 16, we do not sell or share your personal information.
12. Children’s Privacy
QRGO2 is not directed at children under the age of 18 and we do not knowingly collect personal information from minors. If you believe a minor has created an account, please contact us through our contact form and we will promptly delete the information.
13. International Users
QRGO2 is operated from the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to this transfer. For users in the EEA or UK, we rely on appropriate safeguards to protect your data during any international transfer.
14. Third-Party Links & Content
Your QR codes may route scanners to third-party websites or content not owned or controlled by MrDev.Net LLC. This Privacy Policy does not apply to those third-party destinations. We encourage you to review the privacy policies of any third-party sites your QR codes link to.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes we will update the “Last Updated” date and notify you by email or through a prominent notice in the dashboard. Your continued use of the Service after any changes constitutes acceptance of the revised policy.
16. Your California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you specific rights over your personal information. This section also serves as our notice at collection.
Categories of personal information we collect
In the preceding 12 months we have collected these statutory categories:
- Identifiers — name, email address, username, account ID, IP-derived location
- Commercial information — plan selection, billing cycle, subscription and payment history
- Internet or network activity — dashboard usage, log data, scan events on your QR codes
- Geolocation data — approximate city/country from IP address (not precise geolocation)
- Sensitive personal information — account log-in credentials, used only to secure and provide the Service
- We do not collect biometric, professional, education, or other statutory categories.
Sources: you, your devices, scanners of your QR codes, and our payment processors. Business purposes: to operate and secure the Service, process billing, provide analytics, answer support, and comply with law.
We do not sell or share your personal information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as “sell” and “share” are defined under the CCPA/CPRA, and have not done so in the preceding 12 months. Because we do not sell or share, no “Do Not Sell or Share My Personal Information” opt-out is required; if this ever changes we will provide that link and honor opt-out signals, including Global Privacy Control (GPC).
Your California rights
- Know / access the personal information we hold and how we use it
- Delete your personal information, subject to legal exceptions
- Correct inaccurate personal information
- Opt out of the sale or sharing of personal information (not applicable — we do neither)
- Limit use of sensitive personal information — we use credentials only to provide the Service and never to infer characteristics, so this does not change our practices
- Non-discrimination — we will not deny service, change pricing, or degrade quality because you exercised a right
Shine the Light (Cal. Civ. Code §1798.83): we do not disclose personal information to third parties for their own direct marketing.
To exercise your rights, submit a request through our contact form. We respond within 45 days (extendable where permitted) and may verify your identity. You may use an authorized agent with proof of authorization.
17. Other U.S. State Privacy Rights
Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana, among others as they take effect — may have rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, sale of personal data, and certain profiling.
We do not conduct targeted advertising, sell personal data, or profile in ways that produce legal or similarly significant effects, and we do not process sensitive data beyond what is needed to provide the Service. Where required, we honor recognized universal opt-out mechanisms such as Global Privacy Control (GPC).
Right to appeal. If we decline your request, submit a request through our contact form and note “Appeal” in your message. We respond within the period your state requires (generally 45–60 days). If your appeal is denied, you may complain to your state Attorney General.
18. Contact Us
If you have questions, concerns, or requests related to this Privacy Policy or the handling of your personal data, please contact us at:
This Privacy Policy was last updated July 5, 2026.