Draft — awaiting owner approval. This text describes how QRiva works today; it is not yet the final legal wording.
Cookie policy
Last updated: [date of approval]
The small files and browser storage QRiva uses, what each one does and how long it lasts. QRiva sets no advertising cookies.
1.About cookies
Cookies are small files a website stores in your browser. Local storage is similar, but its contents stay in your browser and are not sent to us.
QRiva uses cookies only on its own address. They're first-party, and none are used for advertising or to follow you across other websites.
2.Cookies QRiva sets
This is every cookie QRiva itself sets:
| Name | What it's for | How long | Type |
|---|---|---|---|
| sb-…-auth-token | Keeps you signed in to the app. | Until you sign out, renewed while you use the app | Strictly necessary |
| qws | Remembers which workspace you're working in. | 1 year | Strictly necessary |
| qm | Marks a team member's browser so their own test scans aren't counted in analytics. | 1 year | Functional |
| qtd | Marks a device the workspace chose as a test device, so its scans aren't counted. | 5 years | Functional |
| qpk | Holds a one-time challenge while you sign in with a passkey. | 5 minutes | Strictly necessary |
| qu_… | Remembers that you entered the right password for a protected link. | 12 hours | Strictly necessary |
| qv | Set when you scan a dynamic code, so the business that published it can count returning visitors without storing IP addresses. Not set by workspaces that use strict privacy mode. | 400 days | Analytics (for the publishing business) |
3.Local storage
QRiva also keeps a few things in your browser's local storage, which is never sent to us:
- Your light, dark or automatic theme, and whether the sidebar is collapsed.
- Whether you've dismissed the welcome tour.
- A draft of a long form you're filling in, so you don't lose your answers.
- On a business's own website that uses the QRiva conversion snippet: the scan reference, so a later purchase or sign-up can be connected to the scan.
4.Tags added by businesses
Businesses can add their own analytics or advertising tags — such as Google Analytics, Google Ads, Meta Pixel or TikTok Pixel — to the pages, passports and redirects they publish with QRiva.
Those tags and their cookies are controlled by that business and the tag provider, not by QRiva. The business is responsible for asking for consent where the law requires it.
5.Your choices
You can block or delete cookies in your browser settings. Blocking strictly necessary cookies will stop you signing in to the app or opening password-protected links.
[Owner: confirm with legal advice whether the visitor cookie needs consent in the countries you serve, and whether a consent notice is required on scans.]
6.Changes
We'll update this page whenever we add, change or remove a cookie.