Qbit

Privacy Policy

Last updated: August 19, 2026

Qbit is operated by Hill Country Ranch LLC, a Texas limited liability company doing business as Qbit ("Qbit," "we," "us," "our"). This policy explains what personal data we handle, why, and what rights you have.

Contact: privacy@qbit.codes
Security contact: security@qbit.codes
Report abuse: support@qbit.codes

1. Two different relationships

Qbit handles personal data in two distinct roles, and which one applies determines who is responsible and where to direct requests.

When you have a Qbit account, we decide what we collect and why. We are the controller of that data. Sections 2 through 4 apply to you.

When you scan a QR code, open a page, or fill in a form created by a Qbit customer, we handle that data on that customer's behalf and on their instructions. They are the controller; we are their processor. Section 5 applies, and requests about that data go to the business whose code you scanned - not to us.

If you're not sure which applies to you: if you never signed up for Qbit, it's the second one.

2. Data we collect as controller

You give us

  • Account data - name, email address, and password or Google sign-in identifier.
  • Billing data - billing name, address, and country. Card details go directly to our payment processor; we never receive or store full card numbers.
  • Content - the pages, QR codes, media, and settings you create in the Service.
  • Support and correspondence - anything you send us by email or through support channels.

We collect automatically

  • Usage data - IP address, browser and device type, operating system, pages viewed within the Qbit application, timestamps, referring URLs, and diagnostic data.
  • Cookies and similar technologies - see Section 6.

We receive from third parties

  • Google Sign-In - if you register using Google, we receive your name, email address, and profile identifier. We do not receive your Google password or contact list.
  • Connected integrations - if you connect a platform such as Canva or Untappd, we receive OAuth tokens and the limited data needed to provide that feature. See Section 8.

3. Why we use it, and our legal basis

Where the GDPR or UK GDPR applies, we rely on the following bases.

PurposeLegal basis
Creating and administering your account; providing the ServicePerformance of a contract
Processing payments and managing subscriptionsPerformance of a contract
Sending service, security, and billing noticesPerformance of a contract
Responding to your support requestsPerformance of a contract; legitimate interests
Securing the Service, preventing fraud and abuse, investigating misuseLegitimate interests in operating a secure service
Understanding how the application is used so we can improve itLegitimate interests in improving our product
Non-essential cookies and analyticsConsent
Marketing emails about QbitConsent, or legitimate interests where permitted for existing customers
Keeping tax, accounting, and transaction recordsLegal obligation
Responding to lawful requests from authoritiesLegal obligation

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and you may object at any time (Section 9). Where we rely on consent, you may withdraw it at any time without affecting processing that already took place.

We do not sell personal data, and we do not use your personal data or your end users' personal data to train machine learning models.

4. Who we share it with

  • Subprocessors and service providers. Our current list, including each provider's location and function, is published at https://www.qbit.codes/legal/subprocessors. Each is bound by written data protection terms.
  • Payment processing. Our payment processor handles card data as an independent controller under its own privacy policy.
  • Legal and safety. We may disclose data where required by law or valid legal process, or where necessary to investigate abuse, enforce our terms, or protect the rights and safety of users or the public.
  • Business transfers. If Qbit is involved in a merger, acquisition, or sale of assets, personal data may transfer as part of that transaction. We will give notice before your data becomes subject to a different policy.

We do not share your data with advertising networks or data brokers.

5. QR code scans, page visits, and form submissions

This section is about people who interact with pages our customers publish. If that's you, read this one.

We act on our customer's instructions. A Qbit customer creates a QR code and a page, chooses whether to enable analytics, and decides what fields to put on a form. We store and process what results, on their behalf. They are the controller. Our obligations to them are set out in our Data Processing Agreement at https://www.qbit.codes/legal/dpa.

What flows through our systems when you scan or visit:

  • IP address and the approximate geographic location derived from it (typically city or region level)
  • Device type, operating system, and browser
  • The QR code scanned and the page visited
  • Date and time
  • Referring source, where available

If you submit a form, we store whatever the customer's form asks for and you choose to provide - commonly a name, email address, or phone number, but the fields are set by the customer, not by us.

Analytics on published pages. Customers may enable Google Analytics on pages they publish. Where they do, and where consent is required, that tracking should not run until you have given consent through the banner shown on the page.

Exercising your rights. Because the customer is the controller, requests to access, correct, or delete this data should go to the business whose code you scanned - the one whose page you landed on. If you contact us at privacy@qbit.codes instead, we will forward your request to that customer and tell you we've done so, but we cannot act on it ourselves without their instruction.

Special categories. Qbit is not designed to collect data revealing health, religion, ethnicity, political opinions, trade union membership, sex life, biometrics, or genetics. Our Acceptable Use Policy prohibits customers from using forms to collect it.

6. Cookies and similar technologies

On qbit.codes and the Qbit application we use:

  • Strictly necessary cookies - authentication, session management, security, and load balancing. These cannot be turned off and do not require consent.
  • Preference cookies - remembering settings such as language or interface choices.
  • Analytics cookies - understanding how the application is used. These run only with your consent where consent is required.

On pages published by our customers, what runs depends on what that customer has enabled. Where required, a consent banner appears before non-essential cookies or analytics are set.

You can withdraw or change your cookie choices at any time through the cookie settings link in our footer, or by clearing cookies in your browser. Blocking strictly necessary cookies will prevent parts of the Service from working.

7. Retention

  • Account and profile data - kept while your account is active.
  • Content you create - kept while your account is active or until you delete it.
  • Scan and analytics data - kept for as long as our customer's account is active, or until they delete it, subject to their instructions.
  • Form submissions - kept until deleted by the customer who collected them.
  • Integration data - kept only while the integration remains connected.
  • Usage data and logs - kept for a limited period for security, troubleshooting, and analytics, then deleted or aggregated into anonymized statistics.
  • Billing and transaction records - kept for the period required by tax and accounting law.

When you delete content, it is removed from our active systems.

When you close your account, we delete your account and associated personal data from active systems within 30 days, except where we are required to retain it to meet legal obligations, resolve disputes, or enforce our agreements.

Backups. After deletion from active systems, residual copies may persist in encrypted, access-controlled backups. These are retained on a rolling basis and are overwritten or purged within 90 days, after which the data is not recoverable.

8. Third-party integrations and OAuth tokens

When you connect a platform such as Canva or Untappd using OAuth, we receive access and refresh tokens that let the Service act on your behalf, plus the limited personal data needed for the feature. We store tokens in protected form and use them only for the functionality you enabled.

If you disconnect an integration or delete your account, we revoke the tokens and delete personal data obtained through that integration from active systems within 30 days. You can also revoke access directly in the third-party platform's security settings.

9. Your rights

If you are in the EEA, UK, or Switzerland, you have the right to access your data; correct inaccurate data; request erasure; restrict processing; object to processing based on legitimate interests; receive your data in a portable format; and withdraw consent at any time.

Contact privacy@qbit.codes. We respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension.

You may also complain to your local supervisory authority. In Spain this is the Agencia Española de Protección de Datos (www.aepd.es). A list of EEA authorities is at edpb.europa.eu.

If you are in California, you have the right to know what personal information we collect and how we use it; to request deletion; to request correction; to opt out of sale or sharing; and to be free from discrimination for exercising these rights. We do not sell or share personal information as those terms are defined under the CCPA. Where we handle data on behalf of a business customer, we act as a service provider.

If you are in another US state with a comprehensive privacy law, you have comparable rights. Contact us at the address above and we will apply them.

We do not charge for these requests and will not treat you differently for making one. We may need to verify your identity before acting.

10. International transfers

Qbit is based in the United States, and personal data is processed there and in other locations where our subprocessors operate. Locations for each subprocessor are listed at https://www.qbit.codes/legal/subprocessors.

For transfers of personal data out of the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses, incorporated into our Data Processing Agreement, together with supplementary measures including encryption in transit and at rest.

You may request a copy of the relevant transfer mechanism by writing to privacy@qbit.codes.

11. Security

We apply administrative, technical, and physical safeguards designed to protect personal data:

  • Encryption in transit using HTTPS/TLS, and encryption at rest.
  • Hosting on enterprise-grade cloud infrastructure in access-controlled data centers.
  • Role-based, least-privilege access limited to authorized personnel.
  • Authentication controls, including sign-in through trusted identity providers.
  • Protected storage of integration credentials and OAuth tokens, with prompt revocation on disconnection.

No method of transmission or storage is completely secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities where the law requires it.

To report a vulnerability or a suspected breach, write to security@qbit.codes.

12. Children

Qbit is not directed at children and we do not knowingly collect personal data from them.

You must be at least 16 to create a Qbit account, or the minimum age set by the law of your country if that is lower - 14 in Spain, 13 in the United States and several EEA member states.

If you believe a child has provided us with personal data, contact privacy@qbit.codes and we will delete it.

13. Links to other sites

The Service contains links to sites we do not operate, and our customers may link their pages to any destination they choose. We are not responsible for the privacy practices of those sites. Review their policies before providing personal data.

14. Changes to this policy

We may update this policy. We will post the new version here and update the date at the top. For material changes affecting account holders, we will give notice by email or a prominent notice in the Service before the change takes effect.

15. Contact

Privacy questions and rights requests: privacy@qbit.codes
Security: security@qbit.codes
Abuse reports: support@qbit.codes\

© Hill Country Ranch LLC. Qbit is a trademark of Hill Country Ranch LLC.

© Qbit 2026. All rights reserved.  Privacy Policy | Terms of Service |