QRForge

Privacy Policy

Last updated: October 10, 2026

About QRForge

QRForge is a Shopify app that lets merchants create QR codes for the products in their Shopify store. When a customer scans one of these QR codes, QRForge sends them to the product page or to checkout with the product in their cart, and counts the scan. This policy explains what information QRForge handles and why. In this policy, "we" means the team that provides QRForge.

Information QRForge stores

QR codes

For each QR code a merchant creates, QRForge stores:

  • the store's Shopify domain (for example, example.myshopify.com)
  • the QR code's title, which only store staff see
  • the ID of the Shopify product, and of a variant if one was chosen
  • where a scan leads: the product page or checkout
  • a random code used in the QR code's link
  • the number of times the QR code has been scanned
  • when the QR code was created and last changed

Shopify connection

To work with a store, QRForge stores the store's Shopify domain and the access credentials that Shopify issues to the app when it is installed: an access token, a refresh token, the permission granted and their expiry times. QRForge uses offline access, so it does not store information about individual staff members.

Plans and billing

QRForge currently offers a Free plan. If paid plans are enabled, Shopify will handle plan selection and billing. QRForge does not receive payment-method information, such as card or bank details. While plans aren't enabled for QRForge, it applies no plan limits and doesn't look up subscriptions. When they are enabled, each store's plan decides how many QR codes it can save.

To apply a store's plan, QRForge reads the store's subscription details from Shopify (see "Shopify data QRForge accesses") but doesn't store them.

A store can have at most one billing record, and only some stores have one: a store that was recorded as having installed QRForge before its plans were enabled, or a store whose subscription to one of QRForge's plans QRForge has confirmed with Shopify. The record contains the store's Shopify domain and when the record was created, and may also contain when the store was recorded as an earlier installation and when QRForge first confirmed its subscription. It helps QRForge recognise an existing installation, so that a store without a current subscription gets the Free plan instead of being asked to choose one. It doesn't contain the store's plan, price or billing dates.

How QRForge uses information

  • to show merchants their QR codes and scan counts in the Shopify admin
  • to check the product when a QR code is scanned and send the customer to the right page
  • to count scans
  • when plans are enabled, to apply each store's limit on saved QR codes and show its plan and billing details
  • to answer support requests

QRForge does not sell information or use it for advertising.

Shopify data QRForge accesses

Store data

QRForge asks Shopify only for permission to read products (read_products). It reads product and variant details, such as titles, product handles, whether a product is active and whether a variant is available for sale. With this permission it cannot read or change orders, customers or payments, and it does not change products.

QRForge subscriptions

A store's QRForge subscription is handled separately, through Shopify's Partner API, which is available to Velqora Labs as the developer of QRForge. It doesn't use or extend the read_products permission. QRForge uses it only for the store's QRForge subscription, as described below, and not to read the store's orders, customers or payments.

When plans are enabled, QRForge uses it to look up the store's current QRForge subscription: the plan, monthly or yearly billing, the price and any discount, trial and billing-cycle dates, and whether a cancellation or plan change is scheduled. To make this lookup, QRForge reads the store's Shopify ID and sends it to Shopify; the ID isn't stored. Confirmed subscription details may be reused from the server's memory for up to five minutes, so QRForge doesn't ask Shopify on every page; after that it asks again. An older copy can stay in the server's memory, unused, until it is replaced or the server restarts. Subscription details are never written to the database.

If a merchant chooses to cancel their QRForge subscription on QRForge's Billing page, QRForge asks Shopify, through the Partner API, to cancel that subscription at the end of the current billing cycle. This applies only to the store's QRForge subscription; QRForge doesn't change any other charges or payments.

Customers who scan a QR code

QRForge does not store personal information about people who scan a QR code. When a QR code is opened, QRForge looks at the request's browser identifier (user agent) and prefetch headers to avoid counting search engine crawlers, link previews and prefetches. These are used for that check only and are not stored. The only thing recorded is the QR code's total scan count.

Like any website, the pages are delivered by our hosting provider, which receives technical request information such as IP addresses. QRForge's own error pages, such as "QR code not found", load a font from Shopify's content delivery network.

Support requests

If a merchant sends a request from the Support page in the app, QRForge emails it to support@velqoralabs.com. The email contains the store's Shopify domain and the name, email address, issue category, QR code reference (if given) and message that were entered. The email address entered is used to reply. Support requests are not stored in the QRForge database. To limit misuse, the app keeps a short-lived, in-memory count of recent requests per store.

Information QRForge does not collect

  • Shopify customer or order data
  • payment-method information, such as card or bank details (Shopify handles payment for QRForge's plans)
  • personal information about people who scan QR codes

QRForge does not set its own cookies or use browser storage, and it does not use analytics, advertising or tracking services. Inside the Shopify admin, the app runs alongside Shopify's own scripts, which are covered by Shopify's privacy policy.

Service providers

QRForge uses these services to operate:

  • Shopify: the platform QRForge is built for, including the Shopify admin and APIs
  • Vercel: hosts the QRForge application (United States)
  • Neon: provides the PostgreSQL database that stores QR codes, Shopify connection data and billing records (United States)
  • our email hosting provider for velqoralabs.com: delivers support requests

How information is protected

  • All connections to QRForge use HTTPS.
  • QRForge requests only the Shopify permission it needs.
  • Each store can see only its own QR codes.
  • Shopify access credentials are kept on the server and never sent to the browser.
  • Messages from Shopify, such as data deletion requests, are checked for Shopify's signature before they are acted on.

How long information is kept

  • QR codes are kept until the merchant deletes them, or until Shopify asks QRForge to delete the store's data after the app is uninstalled. Shopify sends that request 48 hours after an uninstall.
  • Shopify access credentials are deleted as soon as the app is uninstalled.
  • A store's billing record, if it has one, is kept after an uninstall, so a reinstall within 48 hours is still recognised as an existing installation. The record doesn't keep a paid plan: QRForge always reads the store's current subscription from Shopify. The record is deleted with the store's QR codes when Shopify sends its data deletion request.
  • Support emails are kept in our support mailbox.
  • Our hosting and database providers keep technical logs and backups under their own retention practices.

Your choices

  • Merchants can delete any QR code at any time in the app.
  • Uninstalling QRForge removes its access to the store, and the store's QR codes and any billing record are deleted when Shopify sends its data deletion request.
  • To ask about or request deletion of information QRForge holds, email support@velqoralabs.com.

Changes to this policy

If this policy changes, the updated version is published on this page with a new "Last updated" date.

Contact

Questions about this policy: support@velqoralabs.com