Legal

Privacy Notice

What Code Forger collects, why, and what you can ask us to do about it. Last updated 10 August 2026.

Who we are

Codeforge is a barcode and QR code generator operated by Code Forger ("Code Forger", "we", "us"). Code Forger is the data controller for the personal data described in this notice. You can contact us about privacy at privacy@codeforger.app.

What stays on your device

Single barcode and QR code generation runs entirely in your browser. The text, URLs, product numbers, Wi-Fi credentials, contact details and logo images you enter into the free generators are not sent to our servers and we never see them. Bulk lists you paste or upload as CSV on the free tier are also processed locally in your browser.

Personal data we collect

Account data — email address, hashed password or Google sign-in identifier, and account creation date. Purpose: to create and secure your account and give you access to your plan. Legal basis: performance of our contract with you.

Subscription data — plan, subscription status, renewal dates and the subscription identifier from our payment provider. Purpose: to know which features to unlock and to support you on billing questions. Legal basis: contract performance.

Saved and dynamic codes — for account holders, the codes you choose to save and, for dynamic QR codes, the destination URL plus aggregated scan events (timestamp, approximate country, device type). Purpose: to provide saved codes, redirects and scan analytics. Legal basis: contract performance.

Support messages — your email address and the content of what you send us. Purpose: to answer you and keep a record of the issue. Legal basis: contract performance and our legitimate interest in supporting customers.

Technical and usage data — IP address, browser and device type, pages viewed, referring page, API request counts and error logs. Purpose: keeping the service secure, preventing fraud and abuse, enforcing plan limits, diagnosing faults and improving the product. Legal basis: our legitimate interests in security and service improvement.

Marketing — if you opt in, your email address so we can send product updates. Legal basis: consent, which you can withdraw at any time via the unsubscribe link.

Who we share data with

Service providers (subprocessors) — hosting, database and authentication infrastructure, error monitoring and email delivery, acting on our instructions under contract.

Merchant of Record — our order process is conducted by our online reseller Paddle.com. Paddle.com is the Merchant of Record for all our orders and handles checkout, subscription management, payments, invoicing, sales tax and VAT compliance, refunds and billing support. Payment card details are collected and processed by Paddle, not by us; we never see or store card numbers.

Professional advisers — legal and accounting advisers where necessary.

Authorities — where we are required to disclose data by law, or to establish or defend legal claims.

We do not sell your personal data.

International transfers

Our providers may process data outside your country, including in the United States. Where data leaves the UK or EEA we rely on appropriate safeguards such as UK/EU Standard Contractual Clauses or an adequacy decision. Contact us if you would like details of the safeguards for a specific provider.

How long we keep data

Account, saved-code and subscription data is kept while your account is active and for up to 12 months after closure, so you can reactivate and so we can meet legal and accounting obligations; billing records held by Paddle may be retained longer where tax law requires. Support messages are kept for up to 24 months. Technical logs and aggregated scan analytics are kept for up to 12 months. When data is no longer needed it is deleted or anonymised.

Security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit (HTTPS), encryption at rest, hashed credentials, row-level access controls in our database, and restricting staff access to what is needed. No system is perfectly secure, so please use a strong, unique password and keep your API keys private.

Cookies

We use essential cookies and local storage to keep you signed in, remember your generator preferences, and secure forms — these are required for the site to work. We may use privacy-friendly analytics cookies to understand which pages and formats people use; we do not use advertising or cross-site tracking cookies. You can clear or block cookies in your browser settings, though signing in will not work without the essential ones.

Your rights

Subject to the law where you live, you can request access to your personal data, correction of inaccurate data, erasure, restriction of processing, a portable copy, and you can object to processing based on our legitimate interests or withdraw consent for marketing. To exercise any of these, email privacy@codeforger.app. We respond within one month. If you are in the UK or EEA you also have the right to complain to your data protection supervisory authority.

Children

Codeforge is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has created an account, contact us and we will delete it.

Changes to this notice

We will post any update to this notice on this page with a new effective date, and notify account holders by email where the change is material.