privacy policy
effective date: march 30, 2026 · last updated: march 30, 2026
1. introduction
Glyph (“we,” “our,” or “us”) is a product of Calyvent. This Privacy Policy explains how we collect, use, and protect information when you use our QR code platform at glyph.calyvent.com (the “Service”).
2. information we collect
account information
When you create an account, we collect your email address and an encrypted password. We do not access or store plaintext passwords.
qr code data
When you create QR codes, we store the destination URL, title, short code, style configuration (colors, logo), and creation timestamp. QR codes created without an account are not stored.
scan analytics
When someone scans a dynamic QR code created through Glyph, we collect:
- Approximate geographic location (country and city, derived from IP via Cloudflare headers — we do not store IP addresses)
- Device type (mobile, tablet, or desktop)
- Browser name and operating system
- Timestamp of the scan
- Referrer URL (if available)
This data is associated with the QR code, not with the person who scanned it. We do not identify or track individual scanners.
payment information
Payment processing is handled by Stripe. We do not store credit card numbers or payment details. We receive only your email address and subscription status from Stripe. For CashApp and cryptocurrency payments, we receive transaction references provided by you.
3. how we use information
- To provide and maintain the Service
- To authenticate your account and manage subscriptions
- To display scan analytics for your QR codes
- To process payments and manage billing
- To communicate service updates (only if necessary)
We do not sell, rent, or share your personal information with third parties for marketing purposes.
4. data storage and security
Your data is stored in Supabase (PostgreSQL) hosted in the United States. The Service is delivered via Cloudflare Workers with global edge deployment. We use encryption in transit (TLS/SSL) and at rest. Passwords are hashed using bcrypt. API keys are stored as SHA-256 hashes.
5. third-party services
- Cloudflare — hosting and CDN (may collect technical data per their privacy policy)
- Supabase — database and authentication
- Stripe — payment processing
- Coinbase Commerce — cryptocurrency payment processing
Each third-party service operates under its own privacy policy. We encourage you to review them.
6. data retention
Account data and QR codes are retained for as long as your account is active. Scan analytics data is retained indefinitely for active QR codes. Upon account deletion, your data will be removed within 30 days. Anonymized, aggregate analytics may be retained for operational purposes.
7. your rights
You have the right to:
- Access and download your data
- Correct inaccurate information
- Delete your account and associated data
- Object to data processing
To exercise these rights, contact us at hello@calyvent.com.
8. children’s privacy
The Service is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
9. changes to this policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date. Continued use of the Service constitutes acceptance of the revised policy.
10. contact
For privacy-related inquiries, contact us at hello@calyvent.com.
© 2026 Calyvent. All rights reserved. Glyph™ is a trademark of Calyvent.