Privacy Policy
Last updated: 9 October 2026
Reroutly provides dynamic QR codes and scan analytics at www.reroutly.com.au. Reroutly (ABN 78 511 064 879) is operated from Queensland, Australia (“Reroutly”, “we”, “us”). We are based in Australia and handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This policy explains what we collect, why, who we share it with and the choices you have.
1. Information we collect
When you create and use an account
- Your name (optional) and email address.
- Your password, which we store only as a one-way cryptographic hash. We can't see or recover your password.
- The QR codes you create: their names, destination links, device-specific links and design settings, including any logo you upload.
- Whether your email is confirmed, and the date your account was created.
When someone scans a QR code
When anyone scans a code created on Reroutly, we record the time of the scan and its approximate location (country and city, derived from the network by our hosting provider), the device type (for example mobile or desktop), operating system and browser. We do not store IP addresses, set cookies on people who scan codes, or try to identify them. Account holders see this information in aggregate in their dashboard.
When you subscribe to a paid plan
Payments are handled by Stripe. Your card details go directly to Stripe and never reach our servers. We receive and store your Stripe customer and subscription identifiers, your plan, subscription status and renewal or cancellation dates.
When you contact us or report a code
If you email us, use our contact form or submit an abuse report, we keep what you send (including your email address, if you give it) so we can investigate, reply and keep a record.
2. How we use your information
- To provide the service: run your account, redirect scans to your chosen destinations and show you scan analytics.
- To secure your account: sign-in sessions, email confirmation and password resets.
- To send service emails, such as confirming your email address, password reset links, security notices and billing receipts.
- To manage subscriptions and plan limits.
- To prevent misuse: we check QR code destinations against Google's list of known phishing and malware sites when they are saved and daily afterwards, and we review abuse reports.
- To protect sign-in and other forms from automated attacks: we count recent attempts using a one-way, keyed hash of your IP address and email (never the raw values), which is deleted within 24 hours.
- To meet legal, tax and accounting obligations.
We don't sell personal information and we don't use it for advertising.
3. Cookies
We use a single essential cookie to keep you signed in. It is set only when you log in and is removed when you log out or it expires after 30 days.
Our website also uses Google Tag Manager to load Google Analytics, which uses cookies to tell us how visitors find and use our website (for example, which pages are visited). This information is aggregated and we don't use it to identify you. You can opt out with your browser's cookie settings or Google's Analytics opt-out add-on. People who scan QR codes are redirected straight to the destination and are not given any cookies.
4. Who we share information with
We use trusted providers to run Reroutly. They process information only to provide their service to us:
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Website and application hosting | Japan (Tokyo) and global edge network |
| Turso | Database hosting | Japan (Tokyo) |
| Resend | Sending account and security emails | Japan (Tokyo) |
| Stripe | Payments, subscriptions, invoices and tax. For payments, Stripe may act as the seller of record and handle sales tax. | United States and other countries |
| Google Web Risk | Checking QR code destination links (only the link itself is sent) against known unsafe sites | United States and other countries |
| Google Tag Manager and Google Analytics | Website usage statistics | United States and other countries |
| Google Workspace | Our support email | United States and other countries |
We may also disclose information if required by law, to protect the rights and safety of our users or others, or as part of a sale or restructure of our business (in which case this policy would continue to apply).
5. Overseas storage
As shown above, your information is stored and processed outside Australia, mainly in Japan and the United States. We choose providers with strong security and privacy practices and take reasonable steps to ensure they handle your information consistently with the Australian Privacy Principles.
6. How long we keep information
- Accounts that haven't confirmed their email within 7 days are deleted automatically.
- Account information, QR codes and scan data are kept while your account is open.
- Email confirmation and password reset links expire after 24 hours and 1 hour respectively.
- When you delete your account, your account, QR codes and scan data are deleted immediately. Billing records are kept by Stripe (and by us where needed) for as long as tax and accounting laws require.
7. Security
We protect your information with encryption in transit (HTTPS), hashed passwords, hashed session and email tokens, and access controls that limit who can reach production systems. No system is perfectly secure, but we take reasonable steps to protect personal information from misuse, loss and unauthorised access. If a data breach is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as required by law.
8. Your choices and rights
- You can view and update your QR codes at any time from your dashboard.
- You can ask for a copy of the personal information we hold about you, or ask us to correct it.
- You can delete your account at any time from Account in your dashboard. This immediately deletes your account, QR codes and scan data and cancels any subscription.
- You can update your billing details, view invoices or cancel your subscription from “Manage billing”.
We respond to requests within 30 days and may need to confirm your identity first.
9. Children
Reroutly is a business tool and is not intended for children under 16. We don't knowingly collect their information.
10. Changes to this policy
We may update this policy as Reroutly changes. We will update the date at the top of this page and, for significant changes, email account holders before they take effect.
11. Contact and complaints
Questions, requests or complaints: support@reroutly.com.au. If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
See also our Terms of Service.