Skip to content

Policy

Cookie policy

What QRSalt stores in your browser and why. Most of it keeps you signed in. The only optional part is ad measurement, which stays off in Europe until you say yes.

Last updated 11 September 2026


Your current choice

Checking which rules apply to you…

You can also reopen this choice from Cookie settings at the foot of every page. Changing your mind is one click, the same as deciding the first time.

How the choice works

  • In the EEA, the UK and Switzerland, the Google Ads tag does not load and sets nothing until you accept. If you reject, or never answer, it stays off.
  • Everywhere else, ad measurement is on unless you switch it off in Cookie settings.
  • Global Privacy Control is honoured everywhere. If your browser sends it, ad cookies stay off and nothing about your visit is shared with ad partners, and we do not ask you again.
  • We work out which rules apply from the country Cloudflare reports for your connection. We do not store it. If it cannot be worked out, we assume the European rules.
  • We remember your answer for about 6 months, then ask again.
  • The signed-in dashboard, and the pages people reach by scanning a customer's code, never load ad tags at all. They only use the strictly necessary cookies below.

Strictly necessary

These make the site work, so they do not need your consent and cannot be switched off. None of them is used for advertising or shared with anyone.

NameWhat it doesLasts
qr_sessionKeeps you signed in. Holds a random token; we store only a hash of it. Not readable by scripts.30 days, renewed while you use it
qr_signed_inLets the public site show "Dashboard" instead of "Sign in". Holds only "1" and grants no access.Same as your session
qr_restoreSet only if you sign in to an account that is scheduled for deletion, so we can ask whether to restore it. Not readable by scripts.Until the account can no longer be restored, 30 days at most
qr_wsWhich of your workspaces you last opened.1 year
qr_nextWhere to take you after you sign in.15 minutes
qr_pendingThe email address you are signing in with, so the code page can show it without putting it in the address bar.15 minutes
qr_g_state, qr_g_nonce, qr_g_verifier, qr_g_modeProtect a Sign in with Google against forgery and replay.10 minutes
qr.newkeyShows a new API key once, right after you create it. Sent only to the API page.1 minute
qr.inviteShows a new team invitation link once. Sent only to the team page.5 minutes
qr_consentRemembers your cookie choice.About 6 months
qr.draft (session storage)Keeps a half-designed code while you create an account, so you do not lose it.Until you close the tab

Set by Cloudflare

Cloudflare sits in front of the site to protect it. It may set these, only for security, under its own cookie policy:

NameWhat it doesLasts
__cf_bmTells people from automated traffic.30 minutes
_cfuvidApplies rate limits fairly to visitors who share an internet connection.Until you close the browser
cf_clearanceSet only if Cloudflare shows you a security check, to record that you passed it.Usually 30 minutes

The anti-bot check on sign-in, forms and abuse reports (Cloudflare Turnstile) runs in a frame from challenges.cloudflare.com. It is used only to tell people from bots.

Ad measurement (optional)

We advertise on Google, and these tell us which ads lead to someone signing up or subscribing, so we stop paying for the ones that do not. They follow the choice you make above.

NameSet byWhat it doesLasts
_gcl_auGoogle Ads, on our domainConnects a visit to a later conversion on this site.90 days
_gcl_aw, _gcl_gs, _gcl_dcGoogle Ads, on our domainHold the identifier of the Google ad you clicked to get here.90 days
Google's own cookies, such as IDE and test_cookieGoogle, on its domainsAd delivery and measurement, under Google's cookie policy.Up to 13 months
qr.gclid, qr.gclid.at (local storage)UsThe Google ad click that brought you, and when. Sent with your signup so a later purchase can be credited to that ad, which means it is uploaded to Google Ads.90 days
qr.source, qr.source.at (local storage)UsThe site or campaign that first sent you. Saved with your account and never shared. In Europe it waits for your yes like the rest of this table.90 days

We may also use Whop's ad pixel on the public pages. It is switched off today. If we switch it on, it follows exactly the same choice, and it will be listed here first.

When you withdraw consent, the tag is told to stop, and the Google cookies above are deleted from our domain. Cookies Google set on its own domains can only be removed by Google or in your browser.

What we do not use

No analytics cookies, no session recording, no fingerprinting, and no tracking pixels in our emails. Scanning a customer's dynamic code sets no cookie at all.

More

How we handle personal data generally is in the privacy policy. Questions: [email protected].