1. Who We Are

uTraLink ("uTraLink", "we", "us") operates the website utralink.com and the uTraLink platform — a service for creating, managing and analysing dynamic QR codes, smart links, bio-link pages and related campaigns. We are based in Berlin, Germany.

You can reach us at:

If you are a resident of the European Economic Area (EEA), uTraLink acts as the data controller for the personal data described in this policy, except for scan analytics data described in Section 5, where our customers act as controllers.

2. Data We Collect

2.1 Account data

When you register we collect your name, email address and a hashed password. If you subscribe to a paid plan, billing details are processed by our payment processor; we do not store full card numbers on our servers.

2.2 Content you create

We store the QR codes, links, bio-link pages, forms, campaigns and related assets you create, including any content you upload (images, text, links) and leads you collect through lead-capture features.

2.3 Usage and technical data

We automatically collect technical data needed to operate the service: IP address, browser type and version, device type, operating system, referring pages, and timestamps of requests. This data is used for security, abuse prevention, diagnostics and service improvement.

2.4 Support communications

When you contact us we keep the correspondence and the contact details you provide in order to respond and maintain a support history.

3. Cookies and Similar Technologies

We use the following categories of cookies:

  • Strictly necessary cookies — session cookies and CSRF-protection tokens required for login, security and core functionality. These cannot be disabled.
  • Preference cookies — remember choices such as your cookie consent.
  • Third-party / marketing pixels — uTraLink lets account holders embed their own tracking pixels (e.g. Meta, Google, TikTok) on their QR landing pages. These are configured by the QR code owner, not by uTraLink, and are only active if the owner enables them.

Where required by law we ask for your consent before setting non-essential cookies. You can withdraw consent at any time via the cookie settings or by deleting cookies in your browser.

4. How We Use Your Data

  • Provide, operate and secure the uTraLink service (performance of a contract).
  • Authenticate your account and maintain your workspace.
  • Process payments and manage subscriptions (performance of a contract).
  • Send transactional emails: verification, password reset, receipts, service and security notices.
  • Deliver your own email campaigns where you use our email features.
  • Prevent abuse, fraud and malicious content on QR landing pages (legitimate interest).
  • Improve the product through aggregated, non-identifying usage analysis (legitimate interest).

We do not sell your personal data.

5. Scan Analytics — Data Processed on Behalf of QR Code Owners

When an end user scans a QR code or opens a link created on uTraLink, we record technical scan data on behalf of the QR code owner: date and time, approximate location derived from the IP address (country/city), device type, operating system, browser, and referrer. The QR code owner can view this data in their analytics dashboard.

For this scan data, the QR code owner is the data controller and uTraLink acts as a data processor. If you scanned a QR code and have questions about the related data processing, please contact the QR code owner; you may also contact us and we will forward your request where possible.

We do not use scan data to build advertising profiles and do not combine it with account data for marketing purposes.

6. Recipients and International Transfers

We use the following categories of service providers (processors):

  • Infrastructure & hosting — our servers are hosted in the European Union (Contabo GmbH, Germany).
  • Content delivery & security — Cloudflare, Inc. (USA) provides CDN, DNS and DDoS protection. Data may be processed in the USA; transfers rely on Standard Contractual Clauses and Cloudflare's Data Processing Addendum.
  • Email delivery — transactional email is sent via Google (Gmail SMTP). Data may be processed in the USA under equivalent safeguards.
  • Payment processing — where paid plans are enabled, payments are handled by our payment processor under its own privacy policy.

Where data is transferred outside the EEA we rely on adequacy decisions or Standard Contractual Clauses.

7. Data Retention

We keep account data for as long as your account is active. After account deletion we remove or anonymise personal data within a reasonable period, except where legal retention obligations apply (e.g. invoicing records) or where backups cycle out within their normal rotation. Scan analytics may be retained in aggregated form.

8. Your Rights (GDPR)

If you are in the EEA or UK you have the right to:

  • Access your personal data and receive a copy (data portability).
  • Rectify inaccurate data.
  • Erase your data ("right to be forgotten").
  • Restrict or object to processing, including objection to direct marketing.
  • Withdraw consent at any time, without affecting prior lawful processing.
  • Lodge a complaint with a supervisory authority — for us, the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI).

To exercise your rights contact [email protected]. We respond within one month.

9. Security

We use TLS encryption in transit, hashed password storage, access controls and regular updates to protect your data. No method of transmission or storage is 100% secure; if we become aware of a personal-data breach we will notify affected users and authorities as required by law.

10. Children

The service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be announced on this page and, where appropriate, by email. The "last updated" date above shows the current version.