Trust & safety
SweQR Abuse & Takedown Policy
Notice, safety action and human review
Effective date: 26 August 2026 · Last updated: 26 August 2026
Report a code
No account needed. Give us the short link exactly as printed, for example qrswe.link/abc123. For a formal illegal-content notice or a human-review request, use the email route in section 3 below.
1. Purpose and scope
This Policy explains how SweQR receives and assesses reports concerning SweQR-managed Dynamic QR identities, destinations, uploaded customer content, Custom Domains and use of the Service, and how an affected account holder may request human review of a restriction.
A true Static QR created in the public Design Studio does not use a SweQR-managed redirect after download. SweQR cannot disable or change the encoded destination merely because the artwork was created using the Design Studio. Reports about misuse of SweQR’s Service or branding may still be submitted, but concerns about content reached directly through a Static QR should also be directed to the destination operator, hosting provider or competent authority.
This Policy forms part of the Terms of Use. SweQR may act under applicable law, a valid authority order, the Terms, this Policy, or a combination of them. SweQR does not determine whether third-party content is lawful in every jurisdiction.
2. What may be reported or restricted
You may report content or conduct that you reasonably believe is illegal, unsafe, deceptive or prohibited by the Terms. This includes:
- phishing, including QR-based phishing (sometimes called quishing), credential theft, malware, malicious downloads, technical exploitation or deceptive redirects;
- fraud, impersonation, scams, spam, evasion of safety controls, cloaking, chained shorteners or misleading destination changes;
- child sexual abuse material, terrorist content, unlawful threats, trafficking or unlawfully offered controlled goods or services;
- content that unlawfully infringes intellectual-property, privacy, publicity or other rights;
- attempts to damage scanners, customers, SweQR infrastructure, redirect-domain reputation or third parties; and
- other content or activity prohibited by applicable law or the SweQR Terms of Use.
Control of a Custom Domain does not exempt a customer from this Policy. Where necessary, SweQR may restrict individual codes, restrict account actions, or stop serving a customer-controlled hostname through SweQR.
3. How to submit a notice
The public report form at sweqr.com/legal/abuse is available without an account. It asks for a SweQR short link or code, a category and optional details. It is a quick safety-signal route for managed Dynamic identities. Include the exact short code and hostname where possible so the affected identity can be located reliably.
The public form deliberately returns the same on-screen acknowledgement whether a code exists, is clean, is already restricted, the report is rate-limited, the request lacks a trusted ingress source, or a network failure occurs. The acknowledgement is therefore not proof that a code exists, a report was stored or a human-review item was created. The form does not collect the reporter’s name or email address and cannot provide an individual outcome response.
An authenticated support case may be used for ordinary account support, but hello@sweqr.com is the formal route for a substantiated illegal-content notice or review request.
A formal notice should include:
- A sufficiently substantiated explanation of why the information is illegal or violates the Terms, including the legal or policy basis where known.
- The exact electronic location, such as the full SweQR URL, hostname and short code, and the destination URL if known.
- Supporting evidence such as screenshots, dates, ownership records or threat-analysis results, where available and lawful to share.
- The reporter’s name and email address, except where applicable law permits a notice without those details, including the relevant exception for notices concerning offences referred to in Articles 3–7 of Directive 2011/93/EU.
- A statement confirming the reporter’s good-faith belief that the information and allegations are accurate and complete.
Do not send passwords, full card data, unnecessary identity documents, illegal material or more personal data than necessary. Contact us before transmitting especially sensitive evidence.
Where a formal notice includes usable electronic contact details, SweQR will send a confirmation of receipt without undue delay. Acknowledgement and decision communications are sent manually by email where required. A notice may give actual knowledge or awareness only for the specific information it identifies with sufficient precision and support; submission does not guarantee removal or a particular outcome.
4. How SweQR assesses reports
Reports are processed as signals, not takedown switches. Where actually stored, repeated reports are deduplicated and rate-limited to reduce brigading and create or update a human-review item. No number of reports can by itself change a QR code’s safety state, block a destination or restrict an account.
Review priority depends on apparent severity, credibility, scanner exposure, legal urgency, current activity and available evidence. SweQR may request clarification, combine related reports, preserve relevant evidence or take an interim reversible measure while a matter is assessed.
4.1. Confirmed or urgent harm
A confirmed malicious verdict from the Google Web Risk Lookup API or another approved trusted provider, clear technical evidence, an apparently valid binding authority order, an authorised human decision, or an immediate and serious safety risk may result in an immediate block or other restriction without prior notice. A confirmed provider verdict may trigger an automated hard block. Such a block is never automatically reversed; reversal requires an authorised human decision.
4.2. Uncertain or heuristic signals
An unverified report, weak or heuristic signal, unusual activity, provider outage or incomplete evidence is suspicion rather than a confirmed verdict. It ordinarily results in a warning, interstitial, pending review, request for information, increased monitoring or another reversible and proportionate measure rather than an unsupported final block. Payment status does not establish trust and does not prevent safety action.
4.3. Insufficient notices
If a notice does not identify the information precisely or provide enough support for a decision, SweQR may request clarification or take no action. The public form’s anti-oracle response does not disclose which result occurred.
5. Measures we may take
Depending on the circumstances, SweQR may:
- show a safety interstitial or warning before redirecting;
- place a QR identity or destination in pending review;
- temporarily or permanently block a destination or QR identity;
- prevent destination changes, code creation, Custom Domain service or other account actions;
- suspend or close an account for serious or repeated abuse;
- preserve relevant records and report or disclose information where legally required or permitted; or
- take no action where the report is unsubstantiated or the content is not shown to be illegal or prohibited.
Safety, billing and QR identity are separate. Cancellation, non-payment or a refund does not automatically block an issued QR identity. Conversely, payment does not prevent a safety restriction. A restriction imposed for abuse does not automatically create a refund right, without limiting mandatory consumer rights or Paddle’s applicable transaction process.
6. Notice to affected customers and reasons
Where applicable law requires it and SweQR has usable electronic contact details, SweQR will inform the affected account holder of a restriction and provide a clear, specific statement of reasons. Depending on the action, this may identify the measure, territorial scope and duration; the facts and circumstances relied on; whether it followed a third-party notice or SweQR’s own detection; whether automation was used; the legal or contractual ground; and available review/redress.
Information may be delayed, limited or omitted where disclosure is prohibited, would undermine security or abuse prevention, prejudice an investigation, expose a reporter or another person to harm, or where applicable law otherwise permits. SweQR may act before notice where advance warning would materially increase harm.
SweQR records internal decision reasons and audit information. Where a customer-facing statement of reasons is required, it may be delivered manually by email using the account contact details.
7. Human review
An authenticated support case may be used for ordinary account support. For a formal human-review request, email hello@sweqr.com so that the request can be identified and handled under this Policy. There is no separate public appeal form. Include the QR URL or code, any decision reference, why the decision should change and supporting evidence.
An authorised person will review the available information and may uphold, modify or reverse the measure. Where practicable, the reviewer will not be the person who made the original human decision. A review request does not itself suspend the safety measure. A confirmed automated block can be reversed only by an authorised human decision.
SweQR will communicate the outcome where it has usable contact details and is legally permitted to do so. No fixed public decision time is promised.
8. Intellectual-property notices
Rights holders may use the notice route in section 3 and should identify the protected work or right, the exact SweQR location, the allegedly infringing destination or material, the basis of ownership or authority to act, contact details, supporting evidence and a good-faith accuracy statement. Affected customers may submit counter-information through the review route in section 7.
SweQR handles intellectual-property notices under applicable law. Nothing in this Policy represents that SweQR has appointed or registered a United States DMCA agent unless a live SweQR legal page expressly states that registration has been completed.
9. Misuse of reporting and review systems
Do not knowingly submit false, deceptive, harassing or manifestly unfounded notices, evidence or appeals. SweQR may disregard abusive submissions, restrict repeated misuse and preserve or disclose relevant records where permitted by law. Honest mistakes and good-faith disagreement are not misuse.
10. Evidence, privacy and confidentiality
The public form does not collect a reporter’s name or email address. It derives a keyed, day-rotated pseudonymous reporter value for rate control and deduplication. That value is stored with an accepted abuse report and follows the report’s configured 180-day retention, rather than the 48-hour period used by separate reusable source-control tables.
Administrative action logs, submitted evidence and authority correspondence are retained only for as long as reasonably necessary for safety, audit integrity, legal obligations, dispute handling or the establishment, exercise or defence of claims.
Email notices and support cases contain the contact information and evidence supplied by the sender. Access is limited by role and need. SweQR does not promise anonymity and may disclose information where strictly necessary for due process, legal defence, investigation or a valid order. Where legally permitted and practicable, SweQR will inform the reporter before disclosing identity information.
12. Contact
Public quick-report form: sweqr.com/legal/abuse
Formal illegal-content notices and human-review requests: hello@sweqr.com
Security vulnerabilities or suspected compromise of SweQR infrastructure: security@sweqr.com
Operator: Thomas Johansson, sole trader trading as SweQR
Public business address: Mejramvägen 16, 611 45 Nyköping, Sweden
Digital Services Act contact point for recipients of the Service and, where applicable, for Member State authorities, the European Commission and the European Board for Digital Services: hello@sweqr.com. Communications may be submitted in Swedish or English. This mailbox is monitored by a person.