Privacy Policy
Last updated 27 August 2026
OneFlyer is run by a small team. This page describes what we actually store and who actually sees it — not what a generic template says a company might do.
What we collect
- Your account. Email address and a password. Passwords are never stored as text — we keep a PBKDF2-SHA256 hash, so we cannot read yours or recover it for you.
- What you tell us about your business.Business name, trade, services, target audience, phone number, and optionally an address, website and social handles. This is used to generate your marketing and is reused on later campaigns so you don't re-type it.
- Files you upload. Photos you add to a campaign. Stored privately and served through our own server rather than from a public bucket.
- Your website, if you ask us to read it. The website-scan step fetches your public pages to pre-fill onboarding. We keep what it extracted, not a copy of your site.
- QR scan counts.For each flyer's QR code we count how many times its offer page was opened and how many times the call-to-action was tapped. Two numbers. We do not log who scanned, their IP address, their location, or their device.
Analytics
We use Google Analytics to see which pages people visit and where they give up, so we know what to fix. It sets cookies and sends Google your IP address, page URL and general location. We do not send it your email, your business details, or anything you type into the product.
If you are in the UK or the EEA, analytics cookies are switched offfor you by default — we use Google's consent mode with storage denied for those regions, so you are counted without being individually tracked unless you later opt in. Advertising and personalisation signals are switched off for everyone, everywhere, because this site runs no advertising.
We also use Vercel Web Analytics, which is cookieless and does not identify individual visitors.
What we don't collect
No advertising trackers, no ad retargeting, no selling or renting of your data to anyone, ever. We do not collect payment card details — when billing goes live it will be handled by Stripe, and card numbers will go to Stripe rather than to us.
Who processes it
- Vercel — hosting, and file storage for uploaded photos.
- Upstash — the database holding your account, campaigns and counts.
- Anthropic — the AI models that write and design your campaign. Your business details and your promotion are sent to generate it.
- Resend — transactional email, such as password resets.
- Google Analytics— which pages get visited and where people drop off. See the Analytics section above for what is and isn't sent.
- Higgsfield — only if you are on Pro and explicitly opt in to AI-generated photos. Otherwise it is never called.
Anyone who scans one of your QR codes
The offer page behind your QR code is public — that's the point of a QR code on a flyer. It shows the offer you created. Visitors are not asked for anything and are not individually identified or tracked.
How long we keep things
For as long as your account exists. Pausing your account changes nothing about storage — it stops new campaigns, and everything you've made stays exactly as it was. If you ask us to delete your account, we delete your account record, brand profile, campaigns, uploaded photos and QR tracking records. See the Cancellation & Refund Policy for what that means for QR codes already printed on paper.
Your choices
Email support@oneflyer.orgto get a copy of your data, correct it, or have it deleted. We'll confirm from the address on the account before acting on any of those.
Children
OneFlyer is a tool for businesses and is not directed at anyone under 18.
Changes
If this policy changes in a way that affects what we collect or who we send it to, we'll email account holders rather than quietly changing the date at the top.
Questions about any of this? Email support@oneflyer.org.