Privacy Policy

WelcomeQR — event registration, QR tickets, and gate check-in. Effective August 31, 2026.

What this covers

This policy covers the WelcomeQR Android app, the organizer dashboard at welcomeqr.vercel.app, and the WelcomeQR API. WelcomeQR lets event organizers create events, register attendees, issue QR-code tickets, and check people in and out at gates.

Data we collect

Account information. When you create an account we store your email address, your password (as a cryptographic hash — we never store or see the password itself), and optionally your full name and phone number.

Event registration answers. When you register for an event, we store your answers to the registration form. The questions on that form are defined by the event organizer, not by WelcomeQR, and your answers are visible to that organizer.

Tickets and check-in records. Each registration gets a QR ticket. When your ticket is scanned at a gate, we record the time, the gate, the scan result (allowed in, allowed out, or denied), and which staff account performed the scan. Organizers see these records for their own events.

Organizer and staff data. For organizer and gate-staff accounts we additionally store which organization you belong to, your role, and which gates you are assigned to.

Camera permission

The Android app uses the camera for one purpose: scanning QR-code tickets at gates. Scanning happens entirely on the device. The app does not take, store, or upload photos or video.

Offline data on staff devices

So that check-in keeps working without internet, gate-staff devices cache the event data needed for scanning (tickets and gate rules) and queue scans locally until they can sync with the server. This cached data is scoped to the gates that staff member is assigned to.

What we don't do

WelcomeQR contains no advertising, no analytics or tracking SDKs, and no social-media integrations. We do not sell, rent, or trade your personal data, and we do not use it for advertising or profiling.

Who your data is shared with

Event organizers. If you register for an event, the organizer of that event can see your registration details and check-in history for that event. That is the core purpose of the service. How an organizer uses your data outside WelcomeQR is governed by their own privacy practices.

Infrastructure providers. Our servers run on Amazon Web Services and the dashboard is hosted on Vercel. These providers process data on our behalf to run the service; they are not permitted to use it for their own purposes.

We may also disclose data if required by law. There are no other third parties.

Security

All traffic between the apps and our servers uses HTTPS. Passwords are stored only as salted hashes. QR ticket payloads are encrypted with AES-256-GCM using a separate key per event, so a ticket QR code cannot be read or forged outside the system.

Retention and deletion

We keep your data for as long as your account exists or as long as the events you are part of need it. To delete your account and associated personal data, email us at mscosian@gmail.com from the account's email address and we will process the request — see Delete Your Account for the exact steps. Note that an organizer may need to retain minimal records of past events (for example attendance counts) even after personal details are removed.

Children

WelcomeQR is not directed at children under 13, and we do not knowingly collect personal data from them. Attendees under 13 should be registered by a parent, guardian, or the event organizer.

Changes to this policy

If we change this policy, we will update this page and its effective date. Significant changes will be announced in the app or by email.

Contact

Questions or requests about your data: mscosian@gmail.com