Privacy Policy
Last updated 17 September 2026
Scan2Return is a free service that puts a QR code on your key ring, so that anyone who finds your keys can get in touch with you. This page says what we keep, why we keep it, who else gets to see it, and how to have it deleted. It covers everything on scan2return.duckdns.org.
In short
- We hold only what the service needs to work: the contact details you choose to publish, and some technical details about each scan.
- Anyone who scans your QR code can see the contact details on your listing. That is the whole point of the service. So please do not put anything on it that you would not want a stranger to see.
- There are no advertising or analytics trackers, and we never sell or rent your data.
- You can change or deactivate your listing yourself at any time, or ask us to remove it.
1. What we collect
When you register a key ring (owner)
- Your name and your email address. These are required.
- At least one way for a finder to contact you: a phone or WhatsApp number, or a Telegram username. If you would rather not publish a phone number, give a Telegram username instead.
- An alternate phone number and a return address. Both are optional, and if you fill them in they are shown to the finder.
- What the keys are for, an optional reward amount, and an optional “in support of” line.
- If you use “Continue with Google”: the name, email address and profile picture URL from your Google account. We never see your Google password.
- A one-time verification code, emailed to you, and a login link if you use the email login. Both are stored only as hashes that cannot be turned back into the original.
When someone scans a QR code (finder)
Every scan of a QR code records:
- the IP address the scan came from;
- the approximate location worked out from that IP address (city, country, rough coordinates), plus the internet provider and time zone;
- what we can tell about the device and browser: device brand and model, operating system and version, browser and version, and language;
- a random visitor-cookie value, so we can tell a first visit from a return visit;
- the date and time of the scan.
If the finder presses the optional “share my exact location” button, we also record the precise GPS coordinates their browser reports. That only happens if they press it, and only for that one scan.
Security and anti-abuse records
We keep the IP address and time of requests used for rate limiting and captcha checks, and a count of failed verification attempts. These exist to keep bots and abuse out of the service, and they are not linked to your listing or your identity.
We do not collect payment details (we take no payments), your contacts, your photos or files, or anything from other apps on your device.
2. Cookies
We set three cookies and nothing else. There is no advertising or analytics cookie anywhere on this site, and no tracking pixel.
- PHPSESSID keeps you signed in while you manage your listing. It is a session cookie.
- s2r_v is a random value that lets us tell a new visitor from a returning one when a QR code is scanned. It holds no personal data.
- s2r_lang remembers whether you chose English or 中文.
All three are set Secure, HttpOnly and SameSite=Lax. We use no local storage.
3. What the finder sees
When someone scans your QR code they are shown your name, what the keys are for, and your email address. They also see whichever contact options you chose to publish: a call button and a WhatsApp button if you gave a phone number, and a Telegram button if you gave a Telegram username. If you did not give a phone number, no phone number is shown anywhere.
If you filled them in, they also see your alternate phone number, your return address, your reward amount and your “in support of” line.
Anyone holding the QR code or its link sees this without signing in. Treat the QR code like a poster on a lamppost: put it on your keys, not on anything you would not want a stranger to know. The finder learns nothing about when or how often your codes have been scanned.
4. What we send to you
When your QR code is scanned we email you the time, the approximate location (and the exact spot if the finder shared it), the device and browser we detected, and the finder's IP address, so you can judge whether a scan looks genuine. Scan notifications are switched on for the service as a whole. If you would rather not receive them, use our contact form and we will turn them off.
5. Who else receives your data
The list is short, and we do not sell or rent personal data to anyone for marketing.
- Google, only if you choose “Continue with Google”. It handles the sign-in.
- hCaptcha, for bot protection on registration and login. It receives the visitor's IP address and the captcha answer.
- ip-api.com, where we send the finder's IP address to work out the approximate location. On the plan we use, that query is not encrypted.
- OpenStreetMap static map service, which draws the map picture in your scan notification email from the approximate coordinates.
- Our email provider (mxrouting.net), which carries the notification and verification emails.
- Our hosting provider (RackNerd LLC). The server, and therefore the database, sits in Dallas, Texas, United States.
- The finder, who sees your published contact details, as described in section 3.
Because the server is in the United States, your information is stored there. By using the service you understand that your information may be handled outside Hong Kong.
6. How long we keep it
- Your listing, its scans and its notification history live for as long as the key ring exists. Deleting the key ring deletes its scan and notification records with it.
- One-time verification codes expire after 10 minutes. Login links expire after 15 minutes and work once.
- Security and rate-limit records are kept only as long as they are useful for blocking abuse.
Nothing wipes old scan records on a timer. If you want them gone, deactivate or delete the key ring, or ask us.
7. Your choices and your rights
- Edit anything on your listing with the manage link we email you. Each edit issues a fresh link and retires the old one, so a link you have lost is a link nobody else can use.
- Deactivate a key ring from the same page. The finder page then stops showing your details and the QR code shows a “no longer active” page instead.
- Ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete your listing and its scan history.
For a copy, a correction or a deletion, use our contact form and we will answer within 30 days.
8. Security
Your manage page is unlocked by a single-use 256-bit token sent to your email. Treat that link as your password and do not forward it. Server access is restricted and protected by two-factor authentication, and the site is served over HTTPS. No system is perfect: if you think your listing or your link has been compromised, contact us and we will reissue it.
9. Children
This service is for adults. It is not intended for anyone under 18, and we do not knowingly hold information about children.
10. Changes to this policy
If we change how the service handles data, we will update this page and the date at the top of it. If you carry on using the service after a change, you accept the updated policy.
11. Contact
For anything to do with privacy, please use our contact form.