Privacy Policy

Last updated:

This policy explains what personal data KachingQR collects, why, and how long we keep it. It follows Singapore's Personal Data Protection Act (PDPA).

Who we are

KachingQR is a free tool that makes PayNow QR codes. It also has an API for developers. In this policy, "we" and "us" mean KachingQR.

For any question about your personal data, email support@kachingqr.com. This is our contact for data protection.

The short version

  • We never store your QR codes. We do not keep what you type into the form, except for a short time while you sign in.
  • We do not sell your data. We do not use analytics, ads or tracking.
  • You can delete your account at any time.

What we collect, why, and for how long

Your account

  • What: your name and email address. If you sign in with Google, also your Google account ID and the web address of your Google profile photo. If you sign in with email, your name is the part of your email address before the "@".
  • Why: to sign you in and to show who is signed in.
  • How long: until you delete your account.

Sign-in sessions

  • What: a session ID, your account ID when you are signed in, the time of your last visit, and data the site needs while you use it. We do not store your IP address or browser details with your session.
  • Why: to keep you signed in, and to protect forms from misuse.
  • How long: a session ends 2 hours after your last visit. After that, it can no longer be used, and we delete it soon after. Signing out ends it at once. To keep you signed in, a cookie can start a new session for up to 90 days.

While you sign in

  • Email sign-in: your email address waits in your session between the two sign-in pages. It is removed when you enter the right code, or when your session ends.
  • Your QR form: if you reach a guest limit and choose to sign in, your form input waits in your session, so you do not need to type it again. This includes your UEN or mobile number, amount and reference. It is removed when you come back to the generator page, or when your session ends.

Sign-in codes

When you sign in with email, we email you a code. We keep only a scrambled copy of the code, never the code itself. (We use an HMAC: a one-way code made with a secret key.) The code expires after 10 minutes, or as soon as you use it.

API keys and API usage

  • What: for each API key, the name you give it, a hash of the key, when you made it and when it was last used. A hash is a one-way code: no one can read your key back from it, not even us. For each key and each day (Singapore time), we count the requests and the QR codes made. We never store what your requests contain.
  • Why: to check API keys, to apply the limits, and to show your usage on your dashboard.
  • How long: a key is deleted when you revoke it. The daily counts are kept for 13 months, then deleted. This is also true for counts of revoked keys.

Limit counters

  • What: to apply the free limits, we count requests for a short time. For guests and for email sign-in, a counter uses only a scrambled form (HMAC) of your IP address, browser session or email address, never the real value. For signed-in users and the API, a counter uses your account ID.
  • Why: to stop misuse and keep the service free for everyone.
  • How long: up to one day.

Server logs

  • What: we keep two logs on our server.
    • The web server log records each request: the IP address, the time, the page, and the browser type.
    • The error log records errors in the app: for example the time, what went wrong, and your account ID if you are signed in.
  • Why: for security, for example to find and stop attacks, and to find and fix errors.
  • How long: 14 days. Then we delete them.

Emails you send us

  • What: the emails you send to support@kachingqr.com, and our replies.
  • Why: to answer your questions.
  • How long: up to 2 years after our last reply. Then we delete them.

What we never store

  • Your QR codes. We make the image when you ask for it, and we do not keep it.
  • What you type into the QR form, such as your UEN, mobile number, amount or reference. The only exception is the short wait during sign-in, above.
  • What your API requests contain.
  • Your payments. We never receive, hold or move money, so we cannot see payments.

Cookies

We use only the cookies the site needs to work. We do not use analytics, ads or tracking cookies, so we do not show a cookie banner.

  • kachingqr-session: keeps your session. It ends 2 hours after your last visit.
  • XSRF-TOKEN: protects forms from misuse by other websites. It ends 2 hours after your last visit.
  • remember_web_59ba36addc2b2f9401580f014c7f58ea4e30989d: keeps you signed in. We set it only when you sign in. It lasts up to 90 days, and we remove it when you sign out.

Who else handles your data

We use a few service providers. They handle data only to provide their service to us.

  • Google: Google sign-in, if you choose it. If you sign in with Google, your profile photo loads from Google's servers. Google can then see your IP address.
  • Amazon Web Services (AWS): Amazon SES sends our sign-in emails, so it receives your email address and the code. Our servers also run on AWS, in Singapore.
  • Google Workspace: our support inbox. It holds the emails you send us.

The site loads no other scripts or fonts from other companies.

Some of these providers may store or process data outside Singapore. When this happens, we take steps to make sure that they protect it to a standard comparable to the PDPA, for example through their data protection terms.

We do not sell your data

We do not sell or rent your personal data. We do not send marketing emails. We only send sign-in codes and replies to your emails.

We share data with the police, courts or other authorities only when the law requires it.

How we protect your data

  • The site uses HTTPS, so data is encrypted between your browser and our server.
  • We store API keys only as a hash.
  • Limit counters for guests and for email sign-in use an HMAC instead of your real IP address, session or email address.
  • We keep sign-in codes only as an HMAC.

If a data breach may harm you, we will tell you and the Personal Data Protection Commission (PDPC), as the law requires.

Your choices

  • Delete your account: sign in and open your Account page. This deletes your account, your API keys, your API usage history and your sessions on all devices. Your API keys stop working at once. You cannot undo it. Emails you sent us are not deleted this way. Ask us if you want them deleted.
  • See or correct your data: email support@kachingqr.com. We reply within 30 days.
  • Withdraw your consent: delete your account and stop using KachingQR. We then stop collecting and using your personal data. Limit counters and server logs are deleted at the times above.

Children

KachingQR is not meant for children under 13. We do not knowingly collect personal data from children under 13.

Changes to this policy

When we change this policy, we update the "Last updated" date at the top. For important changes, we also show a notice on the site.

Contact

Questions about this policy or your personal data? Email support@kachingqr.com.