Privacy Policy

Last updated: September 5, 2026

1. Introduction

This Privacy Policy is issued by Dasecure Solutions LLC (“Dasecure”, “we”, “our”, or “us”), the company that operates PassQR and PassQR Tag. PassQR provides a digital pass creation and management platform; PassQR Tag lets a tag owner receive an alert when someone scans a tag on their own property. This policy explains how we collect, use, and protect your information when you use our services at passqr.com and in the PassQR Tag app.

2. Information We Collect

Account Information: When you sign up, we collect your email address and business name.

Pass Data: Information you enter when creating passes, including holder names, email addresses, and custom fields you define.

Scan Data: When passes are scanned, we record the time and result for analytics purposes.

Mobile Number (PassQR Tag, optional): If you turn on text alerts, the mobile number you enter and the date it was verified. See Section 5.

Usage Data: We collect basic usage analytics to improve our service.

3. How We Use Your Information

  • To provide and maintain the PassQR service
  • To create and manage digital passes on your behalf
  • To generate Apple Wallet and Google Wallet passes
  • To provide scan validation and analytics
  • To deliver the PassQR Tag scan alerts you opted into
  • To communicate with you about your account
  • To improve and optimize our service

4. Data Sharing

We do not sell your personal information. We may share data with:

  • Apple & Google: Pass data is shared with Apple/Google when generating wallet passes
  • Supabase: Our database provider, which stores your data securely
  • Twilio: Our messaging provider, which receives your mobile number only to deliver the text alerts you opted into
  • Legal Requirements: If required by law or to protect our rights

5. Text Messages (SMS)

PassQR Tag can send text-message alerts to the owner of a tag. This section describes how Dasecure Solutions LLC handles the phone numbers used for that service. The program is also described on our SMS program page.

What we collect and why: If you choose to receive text alerts, we store the mobile number you provide and the date it was verified. We use it for one purpose only: to notify you when someone scans a tag you own and the alert has not already been answered on another channel.

Consent: You provide your number yourself in the PassQR Tag app and confirm it by entering a one-time code we text to it. We do not send alerts to any number that has not completed this verification, and we never obtain numbers from third parties, purchased lists, or other users.

What the messages contain: Every text is generated by PassQR from a fixed template. It names the alert category the scanner selected from PassQR's list and includes a link to read and reply in the app. Free-text written by the person who scanned your tag is never sent by SMS.

We do not share it: No mobile information and no SMS consent data is sold, rented, or shared with third parties or affiliates for marketing or promotional purposes. Phone numbers are shared only with our messaging provider (Twilio) for the sole purpose of delivering the messages you asked for, and where required by law.

Frequency and cost: Message frequency varies and depends on how often your tags are scanned. Message and data rates may apply.

Stopping messages: Reply STOP to any message to stop them, or remove your number in the app at any time. Reply HELP for help, or email support@passqr.com. Removing your number deletes it from our records; it does not delete your account or your tags.

People who scan a tag are never asked for a phone number and are never sent text messages. Their identity is not disclosed to the tag owner.

6. PassQR Tag: location, photos and voice notes

PassQR Tag lets someone who finds a tagged object reach its owner without either person learning who the other is. The permissions below exist to serve that, and each is used only at the moment a person taps the control that starts it.

Location. When someone scans a tag, the app may ask for their location so that it can be compared with the tag’s registered location and the message marked as coming from someone actually standing at it. Only a coarse location is kept, and only alongside that one message — it is not a record of anyone’s movements, and it is never shown to the tag’s owner as a precise position. The tag’s own location is never sent to the person scanning. A tag owner may separately allow background location so that a tag which travels with them, such as one on a vehicle, keeps a current location to compare against.

Camera and photos. A person sending a message may be asked to take a live photo showing the tag’s own code, as evidence that they are at it. The photo is taken in the moment through the camera; the app does not read your photo library. It is attached to that one message and to nothing else.

Microphone and voice notes. Either party may add a short voice note to a message or a reply. Recording happens only while you hold the record control, it is never added by default, and the other party will hear your voice — which is why the app says so next to the control every time.

Notifications. If you allow notifications, we store the push token your device issues, so that an owner can be alerted to a scan and a person who sent a message can be told when it has been answered. The token identifies a device, not a person.

Anonymity. A person who scans a tag is known to us only by a pseudonym derived from their device and that one tag. The same device gets a different pseudonym on every tag, so scans cannot be linked across tags, and the tag’s owner never sees it. It exists so that blocking, rate limits and abuse reports can work without anyone having to be identified.

7. Data Security

We use industry-standard security measures including encryption in transit (TLS) and at rest. Access to your data is restricted to authenticated users through Row Level Security policies.

8. Data Retention

Your data is retained as long as your account is active. You can request deletion of your account and associated data at any time by contacting us.

PassQR Tag conversations delete themselves. A set number of days after a conversation closes — two by default, and anywhere from one to thirty at the tag owner’s choosing — the message, any reply, the photo, any voice notes, the coarse location and the presence record are erased. The clock starts when the conversation closes, never while an alert is still being escalated to the owner. Conversations that have been reported for abuse are held until the report has been dealt with.

9. Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Export your data
  • Object to processing of your data

10. Cookies

We use essential cookies for authentication and session management. We do not use third-party tracking cookies.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the “Last updated” date.

12. Contact

If you have any questions about this Privacy Policy, please contact Dasecure Solutions LLC at privacy@passqr.com.