Cookie policy
Updated 8 October 2026
Version 8 October 2026. Keep a copy for your records.
1. Who operates this website
VOVOS PANTRY trading as QR YOURS, South African private company 2026/404842/07, operates QR Yours. This policy covers our application and explains cookies and similar browser storage. Read it with our Privacy Policy.
Business, service and correspondence address: 71 MELVILE ROAD, ILLOVO, SANDTON, GAUTENG, 2196, South Africa. Contact by email: team@qryours.com.
2. Your choices
The application offers Accept all, Only essential and Reject all, with equally prominent buttons. No optional advertising or analytics-cookie integration is currently enabled, so all three choices leave optional cookies off. Only essential and Reject all have the same effect on optional storage. Necessary sign-in, security and service storage remains available; rejecting optional cookies does not sign you out or cancel an account.
Open Cookie settings in the website footer or dashboard navigation to change your choice. We remember it for up to 180 days in this browser, not across accounts or other browsers. Clearing browser storage, an expired choice or a changed policy version makes us ask again. If your browser blocks storage, the choice lasts only on the current page. Browsing or dismissing a page is not acceptance. Any future optional integration must be disclosed and gated behind a fresh, specific choice; this version does not authorise future tracking.
3. Cookies and storage used for the service
- Cookie choice: qr-yours-cookie-choice-v1 in local storage contains only this policy version, your button choice and its expiry. It contains no account identifier or marketing preference. We stop using an expired value; the browser may keep its bytes until it is overwritten or you clear storage.
- Static download limit: qr-yours-static-downloads-v1 stores local download timestamps to apply the browser's three-per-hour courtesy limit. Only timestamps from the preceding hour are used. Older bytes may remain until the next download or browser cleanup. QR content, Wi-Fi passwords, contacts, destinations and logos are not stored in this counter. The counter has an in-memory fallback when browser storage is unavailable.
- Authentication: Clerk manages session cookies such as __session and __client_uat to provide sign-in and keep sessions working. Cookie lifetimes depend on the session and provider configuration. Signing out or expiry ends the relevant session.
- Delivery and security: Cloudflare may use security cookies to deliver pages and protect the service. Protected operator and test routes use CF_Authorization for Cloudflare Access.Security challenges may use cf_clearance; Turnstile's standard widget issues a one-time token, with a clearance cookie only where pre-clearance is configured. Durations depend on the applicable session and security settings; not every visitor receives every cookie.
- QR measurement objection: after a choice on a QR's privacy page, __Host-qr_scan_ plus that QR's slug records an allow/deny preference in a secure session cookie. It is specific to that QR and does not identify a visitor for analytics. Browser session restoration can preserve session cookies; you can change the choice on that QR's privacy page.
- Payments: when you choose checkout or a payment-management action, Paddle provides its own payment interface and necessary payment/security processing. Its cookies and storage are governed by its notices. Our cookie panel does not change choices on another provider's website.
Provider descriptions are at Clerk cookies, Cloudflare cookies and Paddle privacy. Provider names and durations can change with the feature and provider configuration; we review this policy when our integrations change. The script-free public legal-review site does not run the application cookie panel or introduce optional tracking scripts.
4. QR scans are a separate choice
Current grouped scan reporting records eligible link-open counts, activity times grouped into 15-minute periods and approximate country, region and city from network metadata. It does not set an analytics tracking cookie or save a visitor identifier for new opens. Accept all on the website does not switch on device/browser collection, unique estimates or additional scan measurement. Do Not Track, Global Privacy Control and existing QR-specific refusals remain respected. Use the QR's privacy page or email team@qryours.com to object. See Scan Privacy for coverage, retention and rights. Necessary provider request/security logs are separate from the scan database.
5. Browser controls and questions
Your browser can clear or block cookies and local storage. Blocking necessary storage can prevent sign-in, checkout or protected forms from working. Clearing a local saved choice does not delete account-saved QR codes. Contact team@qryours.com for cookie or privacy questions. Cookie choices are not terms acceptance or an email marketing subscription.