Privacy Policy

Last updated 11 August 2026

QRtub is run by Teralis Pty Ltd. This explains what we collect, why, and what you can ask us to do about it.

The short version

QRtub connects a physical QR code to wherever you want it to point. Most of what we store is information about physical things and places, not about people.

  • We do not track people who scan your codes. No scan analytics, no visitor logging, no cookies on the pages a code opens, and we do not retain the IP address of anyone who scans.
  • We hold an email address and name for people who have an account, so they can sign in.
  • We hold whatever you choose to put in your own records — which is yours, not ours.
  • Data is hosted in Sydney, Australia.

Who we are

QRtub is a product of Teralis Pty Ltd (ABN 76 152 898 649, ACN 152 898 649), an Australian private company based in Sydney, New South Wales. In this policy “we”, “us” and “QRtub” mean Teralis Pty Ltd.

You can reach us about anything in this policy at hi@qrtub.com.

Our two roles

This distinction matters, because different rules apply to each.

For account information, we are the controller. We decide what we collect from the people who sign up and why.

For the content you put into QRtub, we are a processor. If you add an owner’s name or a site contact’s phone number to your records, you decide that — we simply store and display it on your instruction. Your organisation is the controller for that information, and if someone wants it corrected or removed they should contact you. We will help you do it.

What we collect

If you have an account

  • Your email address and name, so you can sign in and so teammates can see who is who
  • Which teams you belong to and your role in them
  • Email invitations you send or receive, until they are accepted or expire
  • Billing details, handled by Stripe — we never see or store your card number

Content you create

Your Tubs, Items, Links, Pages, uploaded images and any custom fields you define. This is mostly information about physical things and places — a machine, a vehicle, a room, a site, a product. Where it includes information about people, that is your choice and your responsibility as controller.

Technical information

  • Rate limiting. We use your IP address to limit how often sensitive actions can be attempted — signing in, checkout, searching for users, sending invitations. These records are held briefly and expire automatically. This protects accounts from abuse.
  • Errors and operational alerts. When something breaks, a report may be sent to our internal Slack so we can fix it. These can include an account email address or user identifier.
  • Server logs kept by our hosting providers in the ordinary course of running the service.

What we do not collect

Worth stating plainly, because it is unusual:

  • We do not record who scans a QR code, when, or from where
  • We do not keep scan counts, visitor histories or location data from scans
  • We do not set cookies or store anything on the device of someone who scans a code
  • We do not use third-party analytics or advertising trackers anywhere in the product
  • We do not sell personal information, and we never will

When someone scans one of your codes we work out what to show them — using, for example, whether they are on a phone or a desktop — and then we forget. None of it is written down.

Cookies

We use cookies for one purpose: keeping you signed in. They are strictly necessary for the service to work, which is why you are not asked to consent to them. They are HTTP-only, so scripts cannot read them, and marked secure in production.

There are no analytics, advertising or tracking cookies, and no cookie banner, because there is nothing to consent to.

Why we are allowed to use it

Where UK or EU law applies, our lawful bases are:

  • Contract — we need your account details to provide the service you signed up for
  • Legitimate interests — keeping the service secure and working, including rate limiting and error reporting
  • Legal obligation — tax and accounting records

We do not rely on consent, because we do not do the things that would require it.

Who else is involved

We use a small number of suppliers to run the service. Each may handle personal information on our behalf, and each is bound by contract to protect it. The current list, with what each one does and where it operates, is kept on a separate page so it stays accurate: sub-processors.

Other than these suppliers, we do not share your information with anyone unless you ask us to, or the law requires it.

Where your information is held

QRtub is hosted on Supabase infrastructure in AWS ap-southeast-2 (Sydney, Australia). Some of our suppliers operate in other countries — see the sub-processors page.

If you are in the United Kingdom or the European Economic Area, this means your information is transferred outside your region. Australia does not have a UK or EU adequacy decision, so we rely on standard contractual protections — the UK Addendum to the EU Standard Contractual Clauses, or the International Data Transfer Agreement — for those transfers. Those terms are set out in our data processing agreement, which applies automatically and needs no signature.

How long we keep it

  • Account information — while your account is open, and for a reasonable period afterwards in case it is reopened
  • Your content — until you delete it or close your account
  • Rate-limiting records — minutes to hours, then they expire automatically
  • Billing records — as long as tax law requires, generally seven years in Australia

When you close your account we delete your content. Backups age out on their own cycle.

Keeping it safe

  • Encrypted in transit and at rest
  • Database-level access rules so one customer’s data cannot be reached from another’s account
  • Sign-in sessions held in HTTP-only cookies
  • Rate limiting on sensitive actions
  • Access to production systems limited to people who need it

No system is perfectly secure, but we would rather tell you what we actually do than make broad promises.

Your rights

Wherever you are, you can ask us to:

  • Give you a copy of the personal information we hold about you
  • Correct it if it is wrong
  • Delete it
  • Export it in a portable format
  • Stop or limit how we use it

Email hi@qrtub.com and we will respond within 30 days. We will not charge you, and we will not make it difficult.

If the request concerns information held in another organisation’s QRtub account, ask them — they control it. Tell us and we will help them action it.

United Kingdom and European Economic Area

UK GDPR and the EU GDPR give you the rights above, plus the right to object to processing based on legitimate interests, and the right not to be subject to automated decision-making — which we do not do.

You can complain to a supervisory authority. In the UK that is the Information Commissioner’s Office (ico.org.uk). We would rather you raised it with us first, but it is your right either way.

Australia

We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988. If you are not satisfied with how we have handled a complaint, you can contact the Office of the Australian Information Commissioner (oaic.gov.au).

Children

QRtub is a tool for organisations managing physical things and places — equipment, vehicles, products, facilities, sites. It is not intended for children, and we do not knowingly collect information about them.

Changes

If we change this policy we will update the date at the top. For anything that materially affects you, we will email account holders rather than relying on you noticing.

Contact

hi@qrtub.com — questions, requests, or complaints. It reaches a person.