Last updated: August 19, 2026
Qbit is operated by Hill Country Ranch LLC, a Texas limited liability company doing business as Qbit ("Qbit," "we," "us," "our"). This policy explains what personal data we handle, why, and what rights you have.
Contact: privacy@qbit.codes
Security contact: security@qbit.codes
Report abuse: support@qbit.codes
Qbit handles personal data in two distinct roles, and which one applies determines who is responsible and where to direct requests.
When you have a Qbit account, we decide what we collect and why. We are the controller of that data. Sections 2 through 4 apply to you.
When you scan a QR code, open a page, or fill in a form created by a Qbit customer, we handle that data on that customer's behalf and on their instructions. They are the controller; we are their processor. Section 5 applies, and requests about that data go to the business whose code you scanned - not to us.
If you're not sure which applies to you: if you never signed up for Qbit, it's the second one.
Where the GDPR or UK GDPR applies, we rely on the following bases.
| Purpose | Legal basis |
|---|---|
| Creating and administering your account; providing the Service | Performance of a contract |
| Processing payments and managing subscriptions | Performance of a contract |
| Sending service, security, and billing notices | Performance of a contract |
| Responding to your support requests | Performance of a contract; legitimate interests |
| Securing the Service, preventing fraud and abuse, investigating misuse | Legitimate interests in operating a secure service |
| Understanding how the application is used so we can improve it | Legitimate interests in improving our product |
| Non-essential cookies and analytics | Consent |
| Marketing emails about Qbit | Consent, or legitimate interests where permitted for existing customers |
| Keeping tax, accounting, and transaction records | Legal obligation |
| Responding to lawful requests from authorities | Legal obligation |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and you may object at any time (Section 9). Where we rely on consent, you may withdraw it at any time without affecting processing that already took place.
We do not sell personal data, and we do not use your personal data or your end users' personal data to train machine learning models.
We do not share your data with advertising networks or data brokers.
This section is about people who interact with pages our customers publish. If that's you, read this one.
We act on our customer's instructions. A Qbit customer creates a QR code and a page, chooses whether to enable analytics, and decides what fields to put on a form. We store and process what results, on their behalf. They are the controller. Our obligations to them are set out in our Data Processing Agreement at https://www.qbit.codes/legal/dpa.
What flows through our systems when you scan or visit:
If you submit a form, we store whatever the customer's form asks for and you choose to provide - commonly a name, email address, or phone number, but the fields are set by the customer, not by us.
Analytics on published pages. Customers may enable Google Analytics on pages they publish. Where they do, and where consent is required, that tracking should not run until you have given consent through the banner shown on the page.
Exercising your rights. Because the customer is the controller, requests to access, correct, or delete this data should go to the business whose code you scanned - the one whose page you landed on. If you contact us at privacy@qbit.codes instead, we will forward your request to that customer and tell you we've done so, but we cannot act on it ourselves without their instruction.
Special categories. Qbit is not designed to collect data revealing health, religion, ethnicity, political opinions, trade union membership, sex life, biometrics, or genetics. Our Acceptable Use Policy prohibits customers from using forms to collect it.
On qbit.codes and the Qbit application we use:
On pages published by our customers, what runs depends on what that customer has enabled. Where required, a consent banner appears before non-essential cookies or analytics are set.
You can withdraw or change your cookie choices at any time through the cookie settings link in our footer, or by clearing cookies in your browser. Blocking strictly necessary cookies will prevent parts of the Service from working.
When you delete content, it is removed from our active systems.
When you close your account, we delete your account and associated personal data from active systems within 30 days, except where we are required to retain it to meet legal obligations, resolve disputes, or enforce our agreements.
Backups. After deletion from active systems, residual copies may persist in encrypted, access-controlled backups. These are retained on a rolling basis and are overwritten or purged within 90 days, after which the data is not recoverable.
When you connect a platform such as Canva or Untappd using OAuth, we receive access and refresh tokens that let the Service act on your behalf, plus the limited personal data needed for the feature. We store tokens in protected form and use them only for the functionality you enabled.
If you disconnect an integration or delete your account, we revoke the tokens and delete personal data obtained through that integration from active systems within 30 days. You can also revoke access directly in the third-party platform's security settings.
If you are in the EEA, UK, or Switzerland, you have the right to access your data; correct inaccurate data; request erasure; restrict processing; object to processing based on legitimate interests; receive your data in a portable format; and withdraw consent at any time.
Contact privacy@qbit.codes. We respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension.
You may also complain to your local supervisory authority. In Spain this is the Agencia Española de Protección de Datos (www.aepd.es). A list of EEA authorities is at edpb.europa.eu.
If you are in California, you have the right to know what personal information we collect and how we use it; to request deletion; to request correction; to opt out of sale or sharing; and to be free from discrimination for exercising these rights. We do not sell or share personal information as those terms are defined under the CCPA. Where we handle data on behalf of a business customer, we act as a service provider.
If you are in another US state with a comprehensive privacy law, you have comparable rights. Contact us at the address above and we will apply them.
We do not charge for these requests and will not treat you differently for making one. We may need to verify your identity before acting.
Qbit is based in the United States, and personal data is processed there and in other locations where our subprocessors operate. Locations for each subprocessor are listed at https://www.qbit.codes/legal/subprocessors.
For transfers of personal data out of the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses, incorporated into our Data Processing Agreement, together with supplementary measures including encryption in transit and at rest.
You may request a copy of the relevant transfer mechanism by writing to privacy@qbit.codes.
We apply administrative, technical, and physical safeguards designed to protect personal data:
No method of transmission or storage is completely secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities where the law requires it.
To report a vulnerability or a suspected breach, write to security@qbit.codes.
Qbit is not directed at children and we do not knowingly collect personal data from them.
You must be at least 16 to create a Qbit account, or the minimum age set by the law of your country if that is lower - 14 in Spain, 13 in the United States and several EEA member states.
If you believe a child has provided us with personal data, contact privacy@qbit.codes and we will delete it.
The Service contains links to sites we do not operate, and our customers may link their pages to any destination they choose. We are not responsible for the privacy practices of those sites. Review their policies before providing personal data.
We may update this policy. We will post the new version here and update the date at the top. For material changes affecting account holders, we will give notice by email or a prominent notice in the Service before the change takes effect.
Privacy questions and rights requests: privacy@qbit.codes
Security: security@qbit.codes
Abuse reports: support@qbit.codes\
© Hill Country Ranch LLC. Qbit is a trademark of Hill Country Ranch LLC.