1. Who we are
QRaware is an independent educational website about QR-code scams, quishing and related online fraud. For this policy, “we”, “us” and “our” mean the operator of the QRaware website.
We are the data controller for personal information processed through this website, except where a third-party service (such as our hosting provider) processes information as an independent controller.
To contact us about privacy, email contact@qraware.com. For guidance on what to include in your message, see the contact page.
2. What this policy covers
This policy applies to:
- visits to the QRaware website;
- messages you send us, including email.
It does not cover third-party websites we link to, such as banks, government sites or other organisations. Those sites have their own privacy policies.
3. Information we collect
QRaware does not require an account, does not take payments, and does not currently run advertising or analytics tools.
Information you give us
If you email or otherwise contact us, we may receive:
- your name and email address;
- the content of your message, including any attachments;
- any page URL, screenshots or other details you choose to include, for example when reporting a scam or requesting a correction.
Please do not send passwords, one-time codes, full payment card numbers, bank login details or copies of identity documents. We do not need that information to respond, and we cannot help recover accounts or reverse payments.
Information collected automatically
When you visit the website, our hosting provider may record standard server logs. These can include:
- IP address;
- date and time of the request;
- pages or files requested;
- browser type, device type and referring website;
- general location inferred from IP address (for example, country).
We use this only to operate, secure and troubleshoot the website. We do not use server logs to build marketing profiles or to identify you as an individual in the ordinary course of running the site.
What we do not collect
We do not currently:
- create user accounts or login sessions;
- process payments or store payment card details;
- use advertising cookies or sell personal information;
- run third-party analytics such as Google Analytics, Meta Pixel or similar tracking tools;
- knowingly collect special-category (sensitive) personal data.
4. Cookies and similar technologies
QRaware is a static informational website. We do not set analytics, advertising or tracking cookies.
Your browser may store ordinary technical data needed to display the site, such as cached files. That is controlled by your browser, not by a QRaware cookie banner.
If we later add cookies that are not strictly necessary (for example analytics), we will update this policy and, where required, ask for consent first.
5. How we use information
We use personal information to:
- operate, maintain and secure the website;
- respond to enquiries, corrections and scam reports;
- investigate abuse, fraud or security incidents affecting the site;
- comply with legal obligations.
We do not sell, rent or trade personal information. We do not use it for automated decision-making that produces legal or similarly significant effects.
6. Legal bases (UK GDPR)
If UK GDPR or the EU GDPR applies, we rely on these legal bases:
- Legitimate interests — to host the website, keep it secure, review server logs, and respond to messages that are not a contract or a legal claim.
- Consent — if we later use non-essential cookies. You can withdraw consent at any time.
- Legal obligation — where we must keep or disclose information to comply with the law.
You may object to processing based on legitimate interests. See Your rights below.
7. Who we share information with
We share personal information only where needed:
- Hosting and infrastructure providers — to store and deliver the website and related logs. The site is currently hosted by Hostinger.
- Email providers — if you email us, your message is processed by the email service we use to receive and reply.
- Professional advisers or authorities — if required by law, or to protect our rights, users or the public, for example in a genuine fraud or security investigation.
Anyone who processes personal information for us is expected to do so only on our instructions and with appropriate security, except where they act as an independent controller (for example, a hosting provider’s own server security logs).
8. International transfers
Some providers may process information outside the United Kingdom. Where that happens, we expect appropriate safeguards to be in place, such as an adequacy decision or standard contractual clauses, depending on the destination.
9. How long we keep information
- Server logs — kept only as long as our hosting provider retains them for security and operations, typically a short period unless needed to investigate an incident.
- Correspondence — kept for as long as needed to deal with your request and for a reasonable period afterwards, in case of follow-up, then deleted or archived if we have a legal reason to retain it.
10. Security
We take reasonable technical and organisational steps to protect personal information, including using HTTPS and limiting who can access messages sent to us. No website or email system is completely secure. Please do not send highly sensitive credentials or financial details to us.
11. Children
QRaware is a general educational resource. It is not aimed at children under 13, and we do not knowingly collect personal information from children. If you believe a child has sent us personal information, contact us and we will delete it where appropriate.
12. Your rights
Depending on where you live, you may have rights over your personal information. Under UK GDPR these typically include the right to:
- access a copy of the personal information we hold about you;
- have inaccurate information corrected;
- ask us to erase information in certain circumstances;
- restrict or object to certain processing;
- receive information you provided in a portable format, where the right applies;
- withdraw consent where we rely on consent;
- complain to a supervisory authority (in the UK, the Information Commissioner's Office).
To exercise these rights, email contact@qraware.com. We may need to confirm your identity before we can act on a request. We will respond within the time required by law, usually one month.
ICO contact details: ico.org.uk. You do not have to complain to us first, but we would appreciate the chance to put things right.
13. Links to other sites
Articles may link to official guidance, banks, government bodies or other organisations. We are not responsible for their content or their privacy practices. Check their policies before you provide information to them.
14. Changes to this policy
We may update this policy from time to time, for example if we add analytics or a new hosting provider. The “Last updated” date at the top will change. Continued use of the site after an update means you should review the new policy. If a change is material, we will make that clear on this page.
15. Contact
Privacy questions, requests or complaints: email contact@qraware.com. The contact page explains what to include in your email.
Related: Terms of Service.