↳ Qrivo privacy policy
Privacy for every scan.
Qrivo is a Shopify app operated by SolidCraftLabs. This policy explains what information Qrivo collects from Shopify, merchants, and buyers; why it is used; how long it is kept; and the choices available to individuals.
Last updated August 30, 2026
01
Who this policy covers
This policy applies to the Qrivo Shopify app, its QR creation tools, dynamic redirect service, scan analytics, optional conversion attribution, and support requests. SolidCraftLabs operates Qrivo.
Shopify merchants control how they use Qrivo and the QR destinations they publish. Shopify and each merchant have their own privacy practices. A merchant's privacy policy may also apply when someone visits its store or scans one of its QR codes.
02
Information from Shopify
Through Shopify's APIs and app platform, Qrivo receives the merchant's permanent shop domain, Shopify-provided session and access credentials, granted access scopes, app installation state, web pixel identifier and settings, plan, subscription state, and usage.
When a merchant uses Shopify catalog features, Qrivo accesses the selected product or variant identifiers, titles, status, and public storefront URLs. It also accesses active discount code information, such as the code, title, status, and summary, so the merchant can add an eligible discount to a QR destination. Qrivo does not request or store Shopify customer profiles. It does not store order records by default. If a merchant enables automatic order QR — a Pro-plan capability on limited rollout that also requires Shopify order access — Qrivo may receive the order identifiers needed to create a customer-safe order-status QR.
03
Information merchants provide
Qrivo stores the settings and content a merchant submits, including QR destinations, selected product or variant identifiers, optional discount codes, campaign names, private notes, appearance settings, logo references, and whether a dynamic QR code is active or paused.
We also receive information a merchant or other requester chooses to send in a support, security, or privacy request, such as contact details, shop domain, screenshots, and a description of the issue.
04
Information from buyers and devices
When someone scans a dynamic QR code, Qrivo records the QR and campaign identifiers, scan time and hour, coarse country, device category, and aggregate scan counts. The country and device category are derived from request headers. Network infrastructure necessarily receives an IP address to deliver and protect the redirect, but Qrivo does not include the raw IP address or full user-agent string in the stored scan event.
If a merchant enables conversion attribution, Qrivo's Shopify Web Pixel reads only Qrivo attribution parameters from the page URL and temporarily stores a QR identifier and capture time in Shopify-provided session storage. Qrivo does not set its own buyer cookies. The pixel runs as analytics—not marketing or sale of data—and is subject to Shopify's customer privacy controls. Stored attribution is removed after a successful match or when the browser session ends, and Qrivo does not use attribution older than 30 days.
When an attributed checkout completes, Qrivo receives a Shopify event identifier, event time, QR identifier, and an opaque store token. It does not receive or store the buyer's name, email address, postal address, payment details, raw IP address, browser fingerprint, precise location, customer profile, or order record for this feature.
05
How information is used
We use information to authenticate merchants, create and manage QR codes, operate dynamic redirects, provide analytics and exports, attribute conversions when enabled, administer plans and usage limits, respond to support, investigate failures, protect the service, and comply with Shopify and legal requirements.
Qrivo uses this information only to provide, secure, support, and improve the service or to meet legal and platform obligations. Qrivo does not sell personal information or share service data for third-party behavioral advertising.
06
Service providers and disclosures
Shopify and Amazon Web Services process data as needed to provide the app, redirects, storage, queues, monitoring, and security. Our email and professional service providers may process information when needed to handle a request or operate the business.
We may also disclose information when required by law, to protect the rights or safety of users and the service, or as part of a business reorganization or transfer subject to appropriate protections.
07
Retention and deletion
Raw scan events expire after 30 days. Aggregate scan analytics expire according to the merchant's plan: 30 days on Free, 365 days on Starter, 730 days on Pro, and 1,095 days on Business. Conversion event records used for deduplication expire after 90 days.
Aggregate conversion counts and merchant configuration are retained while needed to provide the service. Uninstalling Qrivo removes its Shopify app sessions and ends its access to the merchant's Shopify store. Shopify's mandatory privacy webhooks initiate the applicable customer or shop-data deletion workflow.
Support, security, billing, diagnostic, and business records are kept only as long as reasonably needed for their purpose and applicable legal obligations. Limited logs and backups may remain until their normal retention periods end.
08
Security
Qrivo uses encryption in transit and at rest, blocks public access to service storage, separates merchant data, limits access, and stores credentials in managed secrets. No transmission or storage system can be guaranteed completely secure.
09
Controls and privacy rights
Merchants can update or pause QR codes and manage the app through Shopify. Depending on where an individual lives, they may have rights to access, correct, delete, export, restrict, or object to processing of their personal information. To make a request about information submitted directly to Qrivo, contact us. We may need to verify the requester and may retain information where permitted or required by law.
Visitors should normally direct requests about a merchant's store to that merchant. Shopify also sends Qrivo authenticated privacy webhooks; Qrivo acknowledges those requests without retaining the customer payload because it does not store customer profiles. Order identifiers are kept only when a merchant has enabled automatic order QR.
10
International processing
SolidCraftLabs operates Qrivo from the United States. Qrivo's primary application data is hosted by Amazon Web Services in its US East (N. Virginia) Region. Shopify and other service providers may process information in the United States and other countries where they operate. As a result, information may be transferred outside the country where a merchant or buyer is located.
11
Children, changes, and contact
Qrivo is designed for Shopify merchants and is not directed to children.
We may update this policy as the service or legal requirements change. We will post the revised policy at this URL and update the revision date above.
For privacy questions or rights requests, contact:
SolidCraftLabsSevern, Maryland, United States
support@solidcraftlabs.com
For product help, visit Qrivo support.
