Policy

Acceptable use policy

The short list of things a QR code may not point at, and the only reason we will ever switch a working code off.

Last updated 8 September 2026


Why this document exists

We promise that your codes keep redirecting after you stop paying. A promise like that is only worth something if the exception is written down plainly instead of buried, so here it is: we disable codes used for abuse, whether the account is paid, free, lapsed or dormant. Everything below is that exception, in full.

A QR code is scanned by someone who cannot see where it goes. That asymmetry is what makes abuse here worth taking seriously, and it is why this list is short and enforced rather than long and decorative.

Prohibited uses

Phishing and credential theft

Pages that imitate a bank, a delivery company, a government service, an employer or any other organisation in order to collect passwords, card numbers or personal details. Codes stuck over the top of someone else’s legitimate code - on a parking meter, a menu, an invoice - are the version of this we act on fastest.

Malware and unwanted software

Anything that distributes malware, spyware, ransomware, cryptominers, or software installed without informed consent, including drive-by downloads.

Fraud and deception

Fake shops, advance-fee scams, fake invoices and payment requests, counterfeit goods, deceptive investment or cryptocurrency offers, and pages designed to obtain money by misrepresentation.

Illegal content

Content that is unlawful where it is published or accessed, including child sexual abuse material, non-consensual intimate imagery, incitement to violence or terrorism, and the sale of goods or substances you are not licensed to sell.

Impersonation

Presenting yourself as another person, business or public body, or using a brand, logo or name you have no right to use, in a way likely to mislead.

Spam campaigns

Bulk unsolicited distribution, link schemes, deceptive redirect chains, and cloaking - showing our scanners or reviewers one destination and real visitors another.

Security abuse

Using redirects to disguise an attack, evade a security filter or reputation system, chain into an open redirect, or to probe, overload or interfere with our infrastructure or anyone else’s.

Also not allowed

  • Reselling access to the redirect service as your own link shortener.
  • Automated creation of codes at a volume that is not plausible use, or attempts to work around plan limits with multiple accounts.
  • Pointing a code at content that is legal but that we are not willing to serve, such as material that is gratuitously violent or that targets an individual for harassment.

How we enforce it

  • We screen destinations when a code is created and re-check them periodically, because a destination can turn hostile long after it was approved.
  • Anyone can report a code, with no account and no sign-in, using the report form or by writing to abuse@example.com. Reports are reviewed by a person. Include the scanned link or the code image and, if you can, where you found it.
  • Confirmed phishing and malware are disabled immediately and without notice. A disabled code serves a neutral page explaining that it has been switched off.
  • For anything less clear-cut we contact the account first and give a chance to fix it, unless doing so would put people at risk.
  • Repeat or deliberate abuse ends the account, and the codes stay disabled. In those cases the never-dies promise does not apply.

If we get it wrong

Automated screening makes mistakes, and a wrongly disabled code on printed material is a real cost to you. Reply to the notice or write to support@example.com and a person will look at it. We aim to answer appeals within one working day and to restore a code the moment we are satisfied it is legitimate.

Related

This policy forms part of the terms of service. What we record about scans is described in the privacy policy.