Legal

SweQR Terms of Use

Terms governing the SweQR Service

Effective date: 26 August 2026 · Last updated: 26 August 2026

1. Who we are and what these Terms cover

These Terms of Use (the “Terms”) govern access to and use of SweQR, including sweqr.com, the public QR Design Studio, SweQR accounts and dashboards, managed Dynamic QR features, Custom Domains, and redirect services operated through SweQR-controlled or customer-controlled hostnames connected to the Service (together, the “Service”).

The Service is operated by Thomas Johansson, a sole trader established in Sweden and trading as SweQR, with public business address Mejramvägen 16, 611 45 Nyköping, Sweden (“SweQR”, “we”, “us” or “our”). Contact: hello@sweqr.com.

By creating an account, using the Service, or accepting these Terms during checkout, you agree to these Terms. If you use the Service for an organisation, you confirm that you have authority to bind that organisation. If you do not agree, do not use the Service.

Additional policies form part of these Terms where relevant, including our Privacy Policy at sweqr.com/legal/privacy, our Refund Policy at sweqr.com/legal/refunds, and our Abuse & Takedown Policy at sweqr.com/legal/abuse. Plan descriptions and order information shown at checkout also apply to your purchase. If mandatory law gives you rights that cannot be excluded by contract, those rights prevail over conflicting provisions in these Terms.

2. Eligibility and accounts

You must be at least 18 years old to create a SweQR account, purchase a paid plan or manage a Dynamic QR identity. A person under 18 may use the public Design Studio only with the involvement and permission of a parent or legal guardian where required by applicable law.

You must provide accurate, current information and keep your account details up to date. You are responsible for safeguarding your login credentials, recovery methods and active sessions, and for activity carried out through your account unless caused by our breach of duty. Notify us promptly at hello@sweqr.com if you suspect unauthorised access.

You may not transfer, sell, share or make an account available in a way that defeats plan limits, identity controls, safety controls or access restrictions. We may require email verification, re-authentication, multi-factor authentication or other reasonable security checks.

3. The Service

SweQR offers two materially different QR products: true Static QR codes created through the public Design Studio, and managed Dynamic QR codes issued to eligible accounts. Product access and capacity are determined by the applicable plan, entitlement and account status and are enforced by the Service. Trust, reputation and safety controls are separate from commercial entitlement. Payment does not increase trust or exempt an account, code or destination from safety review.

3.1. True Static QR codes

The public Design Studio can create a true Static QR code without requiring an account. The final URL or other payload is encoded directly into the downloaded QR artwork. Static QR codes may be downloaded in the formats currently offered by the Design Studio, including PNG and SVG.

A true Static QR code does not receive a SweQR short code or redirect hostname, does not create a managed QR record, does not appear in the Dynamic QR dashboard, and does not reserve a permanent SweQR identity. When somebody later scans it, the scanner’s device handles the encoded content directly. A scan does not contact SweQR merely because the QR artwork was created in the Design Studio, unless the creator deliberately encoded a SweQR address or the scanner separately visits SweQR.

SweQR cannot change, redirect, deactivate, restore or provide Dynamic analytics for a true Static QR code after download. To change its destination or payload, you must create and distribute new QR artwork. You remain responsible for testing the final artwork and encoded content before printing or distribution.

3.2. Managed Dynamic QR codes

New managed Dynamic QR identities require an eligible paid entitlement and available capacity. A Dynamic QR encodes a managed redirect identity rather than the final destination. SweQR stores and operates the mapping between that identity and its current permitted destination.

A Dynamic QR destination may be changed only while the account has the entitlement, access and status required by the Service. Analytics, capacity, Custom Domains, team features and other management functions are available only as stated for the applicable plan. Server-side entitlement and capacity enforcement is authoritative.

New Dynamic identities issued on SweQR’s normal shared redirect infrastructure ordinarily use qrswe.link. Existing identities previously issued on sweq.link continue to use that hostname, but sweq.link is not a higher-plan host and is not the normal host for new shared issuance. An identity issued on one hostname is never silently migrated to another.

Dynamic identities issued under an earlier Free offering are grandfathered and may continue to exist and resolve under their applicable lifecycle and safety status. Grandfathering does not create a right to issue additional Dynamic identities without a currently eligible paid entitlement.

3.3. Permanent issued identity and testing

Once SweQR issues a Dynamic QR identity, its short code and assigned redirect hostname are permanent. They cannot be changed, migrated, recycled or reassigned, including after a plan change, cancellation, account closure or deletion. A printed Dynamic QR therefore remains tied to the exact hostname and short code encoded in that physical artwork.

You are responsible for testing every QR code, destination, design and final printed output before distribution or production. Use a representative final-size print proof and suitable devices and scanning conditions. A successful on-screen test does not guarantee that every printer, material, size, colour combination, camera, network or scanning environment will work.

3.4. Plan changes, billing status and redirect continuity

Ending or downgrading a paid plan, cancellation, a failed payment, a refund or a chargeback does not delete, reassign or recycle an already issued SweQR-hosted Dynamic QR identity. Subject to these Terms, an issued identity may continue to redirect to its last permitted destination after paid management entitlements end.

This continuity does not preserve destination editing, new issuance, plan-limited analytics, Custom Domains, team features, exports or other paid management functions. If the number of issued Dynamic identities exceeds the capacity of a later plan, those identities remain issued and non-reusable, but no additional identities may be issued beyond the applicable capacity.

Continuity does not prevent SweQR from blocking or restricting a code, destination, account or hostname because of illegality, abuse, a confirmed safety finding, sanctions, a valid legal requirement, loss of hostname control, an infrastructure or domain incident, or another lifecycle or enforcement ground stated in these Terms. Billing status, trust status, safety status and QR lifecycle are separate controls.

3.5. Customer-controlled Custom Domains

An account with the required Custom Domain entitlement may connect a domain or subdomain that the customer owns or controls. SweQR may require DNS verification, continued proof of control and other technical validation before issuing or serving Dynamic QR identities on that hostname.

A short code issued on a Custom Domain remains permanently tied to that hostname. SweQR does not migrate it to qrswe.link, sweq.link or another host. Continued operation depends on the customer maintaining registration, control and the required DNS configuration. SweQR cannot serve a hostname that the customer no longer controls.

Under the current service configuration, loss of the required Custom Domain entitlement starts a 90-day grace period for existing issued identities on a verified hostname. Existing scans continue during grace, no new identities may be issued on that hostname, and restoring an eligible entitlement during grace may reactivate it. The account can export a CSV list of affected codes and destinations while account access remains available; this is not a self-hosting resolver or an automated DNS migration.

When grace ends without restored eligibility, SweQR moves the hostname to a neutral continuity state: scans reach a neutral lifecycle page instead of the customer destination. The issued hostname and short-code identities remain reserved and are not reassigned. Safety, legal, loss-of-control or infrastructure restrictions may take effect earlier where justified.

4. Your content and destinations

You retain ownership of URLs, logos, text, images and other material you submit or upload to the Service (“Customer Content”). For a true Static QR created entirely in the browser, SweQR does not acquire rights merely because the browser generated the artwork. To the extent Customer Content is transmitted to or stored by SweQR for a managed feature, you grant SweQR a worldwide, non-exclusive, royalty-free licence to host, copy, process, transmit, resize and display it only as reasonably necessary to provide, secure and maintain the Service, comply with law, and enforce these Terms. This licence ends when the relevant material is deleted, except for information lawfully retained for security, evidence, audit, legal compliance or the permanent issued-identity record.

You represent that you have all rights and permissions needed for Customer Content and destinations, and that their use through SweQR does not violate law, third-party rights or these Terms. You remain responsible for the destination content, offer, product, campaign and statements reached through your QR codes. SweQR does not endorse or control third-party destination sites.

5. Acceptable use

You must not use, attempt to use, or help another person use the Service to:

  • facilitate phishing, credential theft, impersonation, fraud, deceptive redirects, malware, unwanted software, malicious downloads or other cyber abuse;
  • link to, promote or distribute illegal content, child sexual abuse material, terrorist content, unlawful threats, trafficking, controlled goods sold unlawfully, or content that infringes intellectual-property, privacy or other rights;
  • evade a safety warning, review, block, domain restriction, rate limit, plan limit, account restriction or enforcement decision;
  • use URL shorteners, redirect chains, cloaking, obfuscation or domain manipulation to conceal the final destination or defeat validation;
  • scan, probe, disrupt, overload or interfere with the Service or its infrastructure, or access accounts, data, APIs or systems without authorisation;
  • reverse engineer the Service except to the limited extent such restriction is prohibited by mandatory law;
  • use automated means to create accounts or codes, scrape the Service, or generate abusive traffic except through an expressly authorised API or written permission;
  • misrepresent affiliation with SweQR or another person, or use SweQR in a way likely to mislead scanners about the identity or purpose of a destination; or
  • use the Service in breach of sanctions, export-control rules or other applicable law.

This list is not exhaustive. We may publish more detailed and reasonably proportionate safety rules in the Abuse & Takedown Policy or within the Service.

5.1. Resource use and proportionate controls

To protect the Service and apply plan limits, SweQR may use rate controls, queueing, batching, caching, temporary delays or other proportionate technical measures for automated requests, scan-related analytics, safety checks, e-mail, API calls and background processing. These measures may be used where activity is abusive, automated, disproportionate or threatens the Service, its providers or other customers. SweQR will distinguish ordinary customer use from apparent abuse where reasonably possible. A high scan count alone does not automatically disable an already issued QR identity under section 3.2, but non-essential analytics and background processing may be limited or delayed. No plan promises unlimited API calls, safety checks, analytics processing, e-mail delivery or infrastructure capacity unless the applicable plan information expressly says otherwise. Mandatory rights and the specific safety, legal and infrastructure exceptions in these Terms remain unaffected.

6. Safety checks, moderation and enforcement

For managed Dynamic QR codes, SweQR may normalise and validate destinations; check destinations and redirect chains; assess domain, homograph, punycode, reputation and abuse signals; impose cool-off periods; require verification; show an interstitial; limit editing or issuance; queue a matter for human review; or take another proportionate protective measure.

A true Static QR does not pass through SweQR when it is later scanned. SweQR therefore cannot continuously recheck, warn on or disable the encoded destination after download. Safety reports about a SweQR-managed Dynamic identity can be submitted at sweqr.com/legal/abuse. Concerns about content reached directly through a true Static QR should ordinarily also be reported to the destination operator, hosting provider or competent authority.

Heuristic suspicion, unverified reports and unusual activity are not confirmed malicious verdicts. They may trigger an interstitial, temporary restriction or human review. A confirmed malicious verdict from an approved trusted threat-intelligence provider may trigger an immediate automated block. Payment does not establish trust and does not exempt an account or destination from safety action. An automated confirmed block may be reversed only by an authorised human decision.

Where notice is required, it may be delivered manually by email or through another durable account communication channel.

7. Plans, fees, taxes and Paddle

Unless expressly stated otherwise, SweQR reference prices are in US dollars. Paddle automatically determines whether the transaction price is presented as tax-inclusive or tax-exclusive based on the buyer’s location and applicable local expectations. In a tax-inclusive location, applicable VAT or similar tax is included within the price presented for the transaction; in a tax-exclusive location, applicable tax is added to the price. The final amount, tax treatment, billing interval and recurring commitment are shown at checkout before purchase, and consumer-facing prices include tax where required by law.

The order and payment process for paid SweQR plans is conducted by Paddle as authorised reseller and Merchant of Record. For the transaction, Paddle is the seller of record and handles checkout, payment collection, applicable taxes, transaction receipts, recurring charges, buyer payment support, cancellations and transaction refunds under the Paddle Buyer Terms and Paddle Refund Policy. SweQR remains the supplier and operator of the SweQR Service and is responsible for product delivery, account access, QR functionality and product support under these Terms. SweQR does not receive or store full payment-card details.

You authorise recurring charges for a subscription at the interval and price shown at checkout until cancelled. We or Paddle will provide the legally required order and renewal information. Price changes apply only as permitted by applicable law and after any required notice. If a payment fails, paid features may be restricted after applicable notices and retry periods, but billing status alone will not automatically terminate an already issued QR identity.

8. Subscription cancellation, refunds and withdrawal

This section should be read together with the SweQR Refund Policy at sweqr.com/legal/refunds and the Paddle Buyer Terms and Refund Policy presented for the transaction.

You may cancel a recurring subscription through the billing controls made available in your account or through the Paddle customer portal. Unless the cancellation confirmation states otherwise, cancellation takes effect at the end of the current paid billing period and prevents the next renewal. Paid features continue until then, subject to these Terms and any mandatory right that applies earlier.

Paddle handles the purchase transaction, payment and transaction refund as Merchant of Record. A scheduled cancellation leaves the paid entitlement active through the confirmed paid period. A full refund of the current paid period ends the corresponding paid entitlement when the refund is confirmed. A partial refund or adjustment does not by itself end the subscription or entitlement unless the confirmation states otherwise. A disputed or ambiguous billing event may be held for manual reconciliation.

No refund, cancellation or billing adjustment deletes, recycles or reassigns an issued Dynamic QR identity. Shared-host redirect continuity remains subject to section 3.4, while management entitlement follows the confirmed billing state.

If you are a consumer in the EU or EEA, you generally have a right to withdraw from a distance contract within 14 days of concluding it, subject to applicable exceptions and rules for services begun at your express request. If you ask for performance to begin before the withdrawal period ends and then withdraw, you may be required to pay a proportionate amount where the legal conditions are met. Mandatory remedies for a defective or non-conforming digital service remain unaffected.

To exercise a withdrawal right, send an unequivocal statement before the applicable deadline to hello@sweqr.com or use the cancellation or support route identified by Paddle in the checkout or receipt. SweQR and Paddle will coordinate the legally required transaction handling. This does not limit any easier method or model withdrawal form made available to you.

9. Service availability, changes and maintenance

We aim to operate a reliable service, but do not promise 100% uptime, uninterrupted redirects, universal scan compatibility or error-free operation. Availability can be affected by maintenance, incidents, internet and DNS failures, registries, registrars, hosting and security providers, browser or device behaviour, third-party blocking, destination availability and events beyond our reasonable control.

9.1. Changes to the Service

We may change, replace, limit or discontinue features for legitimate business, economic, legal, regulatory, security, abuse-prevention, technical or infrastructure reasons. For a consumer receiving a paid digital service continuously, a change is permitted only on the grounds stated in these Terms, without additional charge, and with the information and termination rights required by mandatory law. Valid grounds include adapting to a changed technical environment or usage level, complying with law, addressing a vulnerability or abuse risk, and replacing a third-party component that is unavailable or no longer available on reasonable terms.

If a change negatively affects a consumer’s access to or use of a paid Service beyond a minor extent, SweQR will provide clear information in reasonable time and any free termination right required by law. Information about a material change will be provided in a durable form where required. SweQR will take reasonable steps to reduce avoidable disruption to issued QR identities, but no change clause promises indefinite operation.

9.2. Permanent discontinuation and orderly wind-down

SweQR may permanently discontinue all or a material part of the Service for legitimate business, economic, legal, regulatory, security, technical or infrastructure reasons, including where continued operation is commercially unsustainable. Except where an urgent event, legal restriction, loss of critical infrastructure, insolvency or another circumstance outside SweQR’s reasonable control makes this impracticable, SweQR will aim to give affected paid customers at least 30 days’ advance notice before a planned permanent discontinuation.

For a planned discontinuation, SweQR will stop new sales and renewals as appropriate, seek to provide paid features through the already-paid period where reasonably practicable, and offer any export or transition information that is technically available and proportionate. If SweQR ends a paid period early, SweQR and Paddle will provide any refund for unused prepaid time required by mandatory law or the applicable transaction terms. No refund exceeds the amount actually paid for the affected unused period unless mandatory law requires otherwise.

An issued Dynamic QR identity remains permanently reserved and will not be recycled or reassigned. That identity rule is not a promise that SweQR will continue operating its domains, DNS, certificates, databases, edge resolver or redirects indefinitely. After a permanent service shutdown, a SweQR-hosted Dynamic QR may stop resolving and long-term redirect continuity cannot be guaranteed. SweQR is not required to transfer ownership of a SweQR-controlled hostname, disclose proprietary source code, or provide a self-hosted resolver.

For a Custom Domain, the customer remains responsible for registration and control of the hostname. Where reasonably practicable before a planned shutdown, SweQR will allow available code/destination export and provide information needed for the customer to reconfigure its own DNS or adopt another service. SweQR does not guarantee automatic migration, certificate continuity or continued resolution after the shutdown date.

9.3. Events beyond reasonable control

To the maximum extent permitted by law, neither party is liable for delay or failure caused by an event beyond its reasonable control, including widespread internet, power, DNS, domain-registry, registrar, cloud, payment, email or security-provider failure; natural disaster; war; civil disorder; labour disruption; government action; or a cyberattack that could not reasonably have been prevented by appropriate safeguards. The affected party must take reasonable steps to limit the impact. This clause does not excuse payment already due, mandatory data-protection or security duties, or consumer rights that cannot be excluded.

10. Suspension and termination

You may stop using the Service at any time and may submit an account-deletion request. Account deletion is a staged, human-reviewed process rather than an immediate database cascade because issued Dynamic identities must never be recycled and printed codes may remain in use.

SweQR’s current deletion process does not automatically cancel a subscription at Paddle. If a paid subscription remains active, deletion completion is blocked until the subscription has been cancelled through Billing or Paddle and the resulting billing status has been reconciled. Account deletion does not itself create a refund right. Mandatory cancellation, withdrawal and refund rights remain unaffected.

When requesting deletion, the account owner must choose whether all issued Dynamic QR codes for the account should keep resolving or be deactivated. If kept active, they continue to use their last permitted destinations, subject to safety and lifecycle rules. If deactivated, scans stop redirecting and show the applicable unavailable response. The current flow does not support a different choice for each code.

Issued QR records retain their permanent identity, a pseudonymous internal account reference required for referential integrity and identity-reservation proof, and necessary lifecycle and safety state. If deactivation was selected, SweQR replaces the former destination in the issued-code mapping with a neutral non-resolving value and redacts destination and host values from the destination-change history; if keep-active was selected, the last permitted destination remains because the code continues resolving. Custom Domain records carrying issued identities are retained. Support, billing, security, safety and audit records may also be retained for the purposes and periods described in the Privacy Policy.

These retained records are access-restricted and may be kept only while necessary for identity non-reuse, redirect continuity, safety, dispute handling or another lawful purpose described in the Privacy Policy.

We may suspend account access, feature access, issuance, editing or particular destinations where reasonably necessary because of a material breach, non-payment, security risk, suspected compromise, abuse, legal obligation or risk to users or infrastructure. Account access, billing entitlement, trust, safety status and QR lifecycle remain separate.

Where appropriate and operationally supported, we will give notice and an opportunity to remedy or request human review. We are not required to restore access where the breach cannot be cured, there is confirmed malicious use, restoration would violate law, or continued access would create a material safety or security risk.

11. Intellectual property

SweQR and its licensors own the Service, software, interface, documentation, branding, templates and all related intellectual-property rights, excluding Customer Content. Subject to these Terms, we grant you a limited, non-exclusive, non-transferable and revocable right to use the Service during the applicable account or plan period for its intended purpose.

Feedback may be used by SweQR without restriction or payment, provided we do not identify you publicly as its source without permission. No rights are granted except those expressly stated in these Terms.

SweQR does not intentionally use Customer Content to train its own machine-learning models and does not sell or license Customer Content to third parties for their own purposes. A service provider may process Customer Content only for the contracted service and under its applicable terms and data-protection obligations.

12. Privacy

Our Privacy Policy explains how SweQR processes account, support, security, billing and managed Dynamic QR data. A later scan of a true Static QR does not reach SweQR merely because its artwork was generated in the Design Studio. Paddle independently processes buyer and payment data for transactions under its own privacy notice. Do not place sensitive personal data in destinations, QR labels or other fields unless lawful and necessary.

13. Third-party services

The Service may depend on or link to third-party services such as payment, hosting, domain, email, analytics, security and destination providers. Their own terms may apply. We are not responsible for third-party websites or services outside our control, but this does not exclude responsibility that mandatory law places on us.

14. Disclaimers

To the maximum extent permitted by law, the Service is provided on an “as available” basis. SweQR does not warrant that every QR code will scan in every condition, that every external destination will remain available, that a redirect hostname will never be blocked by a third party, or that the Service will meet requirements not expressly agreed in writing.

Safety systems reduce risk but cannot detect or prevent every malicious destination, false positive, compromised website or later change to third-party content. You must maintain appropriate controls for your own campaigns, destination accounts and printed materials.

These disclaimers do not limit statutory conformity rights, remedies for digital services, or other rights that cannot lawfully be waived.

15. Limitation of liability

Nothing in these Terms excludes or limits liability for fraud, wilful misconduct, death or personal injury caused by negligence, breach of mandatory consumer law, or any other liability that cannot lawfully be excluded or limited.

15.1. Consumers

If you are a consumer, SweQR is responsible for foreseeable loss caused by our breach of these Terms or failure to use reasonable care, subject to mandatory law. We are not responsible for business losses arising from consumer use, or for loss caused by your unlawful use, failure to follow reasonable instructions, destination content, or circumstances outside our reasonable control, except where mandatory law provides otherwise.

15.2. Business users

If you use the Service for business purposes, neither party is liable for indirect or consequential loss, loss of profit, revenue, business, goodwill, anticipated savings or data, except where such exclusion is prohibited by law. SweQR’s aggregate liability arising from the Service during any 12-month period will not exceed the greater of (a) the fees attributable to your use of the Service during the 12 months before the event giving rise to the claim, or (b) USD 100.

For business users, SweQR is not liable for printing, packaging, labels, signage, advertising, installation, recall, replacement, production or distribution costs resulting from a QR code, destination, design, outage, third-party block or campaign issue. You are responsible for proofing, staged deployment, maintaining source files and destinations, and deciding whether the Service is suitable before committing to physical production. This paragraph does not apply where liability cannot lawfully be excluded.

16. Indemnity for business users

If you use the Service for business purposes, you will indemnify SweQR against third-party claims, losses and reasonable costs arising from your Customer Content, destinations, products, campaigns, infringement of third-party rights, unlawful use or material breach of these Terms, except to the extent caused by SweQR’s own breach, negligence or unlawful conduct. This section does not apply to consumers acting outside a trade or profession.

17. Governing law and disputes

These Terms are governed by Swedish law, without regard to conflict-of-law rules. If you are a consumer, this choice does not deprive you of mandatory protections available under the law of your country of habitual residence.

Please contact hello@sweqr.com first so that SweQR can try to resolve the matter. A consumer may refer an eligible dispute to the Swedish National Board for Consumer Disputes (Allmänna reklamationsnämnden, ARN) at arn.se, subject to ARN’s applicable requirements. SweQR will provide any case-specific alternative-dispute-resolution information required by law when a consumer complaint is rejected in whole or in part.

Business disputes that cannot be resolved amicably shall be submitted to the competent courts of Sweden where legally permitted.

18. Changes to these Terms

We may update these Terms for legal, security, operational or service reasons. We will post the updated version and change the “Last updated” date. For material changes affecting an active paid service, we will provide reasonable advance notice where required. Changes will not retroactively remove accrued rights or override mandatory law. If you do not agree to a material change, you may stop using the Service and cancel renewal before the change takes effect, subject to any additional rights required by law.

19. General

If a provision is held invalid or unenforceable, the remaining provisions remain in effect and the invalid provision will be applied to the maximum extent permitted. Failure to enforce a provision is not a waiver. You may not assign these Terms without our consent, except where mandatory law permits. We may assign them as part of a reorganisation, financing, merger, acquisition or transfer of the Service, provided consumer rights are not reduced unlawfully.

These Terms, incorporated policies, applicable plan terms and checkout information form the agreement governing your use of the Service. They do not create rights for third parties except where expressly stated or required by law.

20. Contact

SweQR

Operator: Thomas Johansson, sole trader trading as SweQR

Public business address: Mejramvägen 16, 611 45 Nyköping, Sweden

Email: hello@sweqr.com

Abuse reports: sweqr.com/legal/abuse. Formal illegal-content notices, human-review requests and legal correspondence: hello@sweqr.com.

Digital Services Act point of contact for recipients of the Service and, where applicable, for Member State authorities, the European Commission and the European Board for Digital Services: hello@sweqr.com. Communications may be submitted in Swedish or English. This mailbox is monitored by a person and does not rely solely on automated tools.