Scanmelon
My codes

Privacy

This privacy notice explains how Scanmelon processes personal data when you use scanmelon.com or contact us. We keep that as limited as possible and in line with the General Data Protection Regulation (GDPR).

1. Controller

The controller is Scanmelon, operator of the website www.scanmelon.com.

For privacy questions, access, or deletion: [email protected].

2. What this notice covers

This notice covers use of our website, making a QR code on the homepage, email sign-in, stored codes, paid plans, and email contact. There is no contact form.

3. QR codes: processing in your browser

The QR preview runs in your browser. Destination, color, style, and any logo stay on your device until you save. After sign-in we store destination, appearance, and live hop URLs so you can download and edit later.

A downloaded or printed QR code contains the destination you entered. What happens when someone scans that code depends on that destination (for example a site of yours or a third party). We are not the controller for that.

4. Personal data we process

We only process what we need to run the website and to reply to you.

  • Technical visit data. Each request to the website creates server logs such as IP address, time, requested page, HTTP status, referrer, and browser data (user-agent). That is inherent to hosting a website.
  • Email contact. If you write to [email protected] we process your email address, the message and any attachments, plus email metadata such as the send date.
  • Account. If you sign in we process your email address to send a magic link, to attach saved QR codes to your account, and to email you when your scan limit is nearly used or reached.
  • Payments. Paid plans and extra-usage packs are billed by Stripe. Stripe processes payment details. We store a Stripe customer id and plan status on your account, not card numbers.
  • Language preference. If you pick a language or we follow your browser language, we store that preference in a strictly functional cookie (scanmelon-locale) so we can show the same language next time. That cookie is not used to track you.

We do not ask for a name or phone number. We do no tracking, remarketing, or profiling. We do not sell personal data.

5. Purposes and legal bases

We process personal data only with a GDPR legal basis.

  • Keeping the website available and secure (technical logs): legitimate interest, Article 6(1)(f) GDPR. The interest is a stable, safe service without abuse. Your interest does not outweigh this: the logs are limited, short-lived, and not meant to follow you.
  • Answering your email : legitimate interest, Article 6(1)(f) GDPR, namely handling correspondence. If you ask us to do something that resembles a contract (for example a product question), Article 6(1)(b) GDPR may also apply.
  • Running your account , including emails when scan limits are nearly used or reached: performance of a contract, Article 6(1)(b) GDPR.
  • Remembering the site language : legitimate interest, Article 6(1)(f) GDPR, namely showing the site in the language you expect.
  • Understanding how the website is used (Vercel Web Analytics): legitimate interest, Article 6(1)(f) GDPR, namely improving the site. The measurements are aggregated, cookieless, and without personal data that identifies you.
  • Legal obligations , for example if we must retain correspondence: Article 6(1)(c) GDPR.

We do not ask for consent for tracking cookies, because we do not set them. Consent (Article 6(1)(a) GDPR) is not a basis we currently use.

6. Cookies and similar technologies

Scanmelon does not set tracking cookies or advertising cookies. We use Vercel Web Analytics for aggregated page views: cookieless, without cross-site tracking, and without a cookie banner.

The only cookie we set ourselves is scanmelon-locale: a strictly functional preference for the website language, stored for at most one year. You can delete it in your browser; we will then follow your browser language again.

Your browser or our hosting environment may keep strictly functional technical data needed to show the page. Those techniques are not used to follow you across sites.

7. Recipients

We do not share personal data with third parties for their own marketing. Processors may help us host the website or deliver email. They may only process data on our instructions, under a data processing agreement or equivalent safeguards.

Public authorities get access only where the law requires it.

8. Transfers outside the EEA

Our hosting or email infrastructure may sit (in part) outside the European Economic Area, for example in the United States. If that happens, we only do so with a valid transfer mechanism: an adequacy decision (such as the EU-US Data Privacy Framework, where applicable) or the European Commission’s standard contractual clauses, plus extra measures where needed.

9. Retention

  • Technical logs: as short as hosting allows for security and incidents, then deletion or anonymization. In practice that is days to a few weeks, unless an incident needs longer investigation.
  • Email correspondence: until the request is handled, then up to two years for follow-up and administration, unless a legal duty or dispute requires longer. You can ask for earlier deletion; we honor that unless we must keep the data.
  • QR design data: not with us. It exists only in your browser session until you close the page, unless you download a file yourself.
  • Language cookie: up to one year, or sooner if you delete the cookie.

10. Your rights

Under the GDPR you can ask us for:

  • access to the personal data we hold about you;
  • correction of inaccurate data;
  • erasure (the right to be forgotten);
  • restriction of processing;
  • portability of data you provided to us, in a common format, where that right applies;
  • objection to processing based on legitimate interest.

Send your request to [email protected]. We reply within one month. We may ask for extra details to check that the request is from you. We do not charge a fee unless a request is manifestly unfounded or excessive.

We do not take automated decisions with legal or similarly significant effects, and we do no profiling.

11. Complaints

You have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) (autoriteitpersoonsgegevens.nl) or with your local supervisory authority if you believe we do not comply with the GDPR. We would appreciate it if you contact us first so we can try to fix it.

12. Children

Scanmelon is not directed at children under 16. We do not knowingly collect their data. If you think we have a child’s data, email us and we will delete it.

13. Changes

If we expand the product (for example accounts, dynamic codes on our servers, or statistics), we will update this notice before that processing starts. The date below is authoritative. Material changes will also be noted on this page.

14. Contact

Scanmelon — privacy
Email: [email protected]

This notice was last updated on 16 September 2026.