Privacy Policy

QR Wall is a live event wall: guests scan a QR code and post photos, videos, and messages that appear on a display. Guests never create an account, and by default they can post without giving us any personal information at all. The event host controls what their wall collects and can delete any of it — a single post, a whole event, or their entire account — at any time, which permanently removes the stored media as well as the database records.

Last updated: September 2026

Who we are

QR Wall (qrwall.live) is operated by Trying Things, LLC, 131 Continental Drive, Suite 305, Newark, Delaware 19713, United States. For anything in this policy, including access and deletion requests, contact us at [email protected].

There are two kinds of people in this policy, and the difference matters. An event host signs in, creates a wall, and decides its settings. A guest scans that host's QR code and posts to their wall without signing in. For the content and contact details collected at an event, the host decides what is collected and why; we process it on their behalf. In GDPR terms the host is normally the controller and we are the processor. For host account and billing data, we are the controller.

What we collect

From event hosts, when you sign in and use the product:

  • Your name, email address, and profile image, passed to us by the sign-in provider when you authenticate. We never receive or store your password.
  • Your plan, and the customer and subscription identifiers issued by our payment processor. We never see or store card numbers.
  • The events you create and their settings — title, theme, moderation strictness, and whether contact capture is on.

From guests, when they post to a wall:

  • The content they submit: a message, photo, or video, plus the time it was submitted.
  • A contact detail — one email address or phone number — but only if the host has turned on attendee capture for that event. This is off by default.
  • A device identifier stored on the guest's own phone, used only to recognise a returning guest so they are not asked for their contact detail again and so the host's attendee list is deduplicated.
  • A record of which disclosure wording the guest was shown at the moment their contact detail was first captured. That record is deliberately never rewritten, so a host changing the setting later cannot alter what an earlier guest actually agreed to.

If the host has not turned on attendee capture, a guest can post to a wall without providing any personal information whatsoever. There is no guest account, no sign-up, and no email required to participate.

Guest contact details, and what guests are told

When a host turns on attendee capture, guests are shown one of two disclosures before they can post, depending on the host's setting. The first is a notice: “The event organizer will receive your contact details along with your posts.” The second requires the guest to actively tick a box reading: “I agree that the event organizer may store my contact details and posts, and contact me about this event.”

Contact details collected this way are made available to that event's host, who can export them. They are not shared with other hosts, not combined across events, not sold, and not used by us to market anything to the guest. Whether the host's own later use of those details is lawful — including under GDPR, CCPA, CAN-SPAM, or TCPA — is the host's responsibility, and our Terms of Service say so explicitly.

How we use what we collect

  • To run the product: show submissions on the wall, keep the live connection open, generate QR codes and galleries, and produce downloads.
  • To screen submitted content before it is displayed, so that a projected wall in a public room does not show something harmful. See the moderation section below.
  • To take payment and manage subscriptions.
  • To send transactional email — download links, receipts, and replies to your support requests — and, to hosts only, occasional product email you can unsubscribe from.
  • To understand which pages and features are used, in aggregate, so we can improve them. We do not run advertising on QR Wall and we do not sell personal information.

Automated moderation of submitted content

On walls whose host has AI moderation switched on (a Professional-plan feature), submissions are screened automatically before they reach the wall. Message text, images, and sampled frames from videos are sent to OpenAI's moderation service for classification, and a language model is used to judge tone. This is a classification step only: it returns a category and a confidence score that decide whether the item is shown, held, or blocked. Posts to the try-it demo wall on our homepage are screened the same way.

We use OpenAI's API, and content submitted through an API is not used to train their models. Hosts on paid plans can additionally hold every submission for their own manual approval before it appears. On a wall without either, what a guest posts appears as posted, and the host can remove any item at any time.

Who else processes this data

We use the following subprocessors. Each one receives only what it needs to do its job, and none of them are permitted to use it for their own purposes.

ServiceWhat it handles
ReplitApplication hosting
NeonThe PostgreSQL database holding accounts, events, submissions, and attendee rows
Google Cloud StorageStored photos and videos
CloudflareContent delivery and caching in front of the site
StripePayments and subscriptions. Card details go directly to Stripe; we never receive them
ResendTransactional and product email
OpenAIAutomated content moderation, as described above
PostHogProduct analytics
Google AnalyticsWebsite analytics
Meta PixelAdvertising measurement on marketing pages, active only when configured
Google FontsWeb fonts on marketing pages

We also disclose information where the law requires it, and to protect the safety of people or the integrity of the service. We do not sell personal information, and we do not share it for cross-context behavioural advertising.

How long we keep it, and how to delete it

Event content does not expire on any plan. It stays until someone deletes it, which is a deliberate choice — a wedding wall should still be there a year later. That also means deletion is the mechanism that matters, so we made it complete rather than partial.

  • Delete a single post — removes the post and its stored media file.
  • Delete an event — removes the event, every submission on it, every attendee row collected at it, its download tokens, and all of its media files in storage.
  • Delete your account, from the Account page — deletes every event you own by the process above, then removes your user record. Nothing is retained in a recoverable form.

Sign-in sessions expire one week after they are created. Records we are required to keep for tax or accounting reasons — invoices and payment records held by our payment processor — are retained for as long as the applicable law requires, independently of the above.

Cookies and analytics

We set a session cookie when a host signs in; it is required for the product to work and lasts one week. Marketing pages load analytics as listed in the table above. Guests posting to a wall are not required to sign in and are not given a login cookie.

Your rights

Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, obtain a portable copy, object to or restrict certain processing, and — under CCPA — to know what is collected and to opt out of sale or sharing. We do not sell personal information, so there is nothing to opt out of. You will never be treated differently for exercising any of these rights.

Hosts can exercise most of these directly: your data is visible in the product, exportable, and deletable from the Account page without asking us. For anything else, or for any request about a guest's information, email [email protected] and we will respond within 30 days. If you are a guest at someone's event and want your contact detail or a post removed, contact the event host, or write to us and we will pass the request on and act on it ourselves where we can.

International transfers

Our subprocessors operate in several countries, including the United States, so your information may be processed outside the country where you live. Where a transfer is from the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses or an equivalent approved mechanism.

Children

QR Wall is not directed at children under 13, and hosts must not knowingly configure attendee capture to collect contact details from them. If you believe a child's information has been collected at an event, email [email protected] and we will delete it.

Security

Traffic is encrypted in transit with TLS and stored content is encrypted at rest. Our security practices are described in more detail on the Security page. To report a vulnerability, email [email protected].

Changes to this policy

If we change this policy we will update the date at the top of the page, and for material changes affecting hosts we will send an email to the address on the account.

Still have a question?

We answer email from a real person, usually the same day.

Get in touch