2D Ready

Privacy policy

The short version: when someone scans a code we serve, we do not know who they are and we do not try to find out. No cookies, no stored IP addresses, no fingerprinting. For account holders we keep the minimum needed to run the service, and you can export or delete all of it yourself.

Updated 19 July 2026.

Who we are

2D Ready is operated by Loxima Limited (registered in England and Wales, company number 10039334), the data controller for the personal data described here. We run 2dready.com, app.2dready.com, tools.2dready.com and the gtin.codes resolver. For anything in this policy: hello@2dready.com.

When someone scans a code

A scan reaches our resolver, which reads the identifiers in the URL and either redirects to the brand's chosen destination or serves a hosted product page. For each scan we record one aggregate analytics event: the time, the product's GTIN and lot, whether a serial was present, the requested link type, a coarse location (country, region and city, derived at the network edge), a device class and operating-system family rather than the full browser signature, and the referring site's hostname.

What we do not do: no cookies on scan, no stored IP addresses, no fingerprinting, and no advertising or cross-site identifiers of any kind. We never store serial numbers — analytics record only whether a serial was present, and request logging that would capture full scan URLs is switched off on our resolver, so identifiers carried in the URL do not end up in infrastructure logs either.

Hosted product pages are rendered from the scan URL and cached at the edge for up to five minutes; such a page can show identifiers the URL already carries (a lot or serial number), and nothing about the person scanning is collected or stored.

If a rule you are subject to requires zero scan telemetry — the EU wine e-label is the known case — email us and we will disable scan counting for your account entirely.

When you hold an account

We hold your email address (sign-in is by emailed magic link, so there is no password), your organisation's name, and the products, destinations, rules and page templates you create. Signing in sets one first-party session cookie on app.2dready.com — an essential, HttpOnly cookie holding a signed session id and nothing else. Changes to destinations and links are kept as an audit history so you can see and restore what changed. If you email us, we keep the correspondence.

Billing

Payments are handled by Stripe. Your card details go to Stripe directly and never touch our systems; we hold your subscription state (plan, packs, renewal interval) and Stripe holds the invoices.

Website analytics

2dready.com and tools.2dready.com use Cloudflare Web Analytics, which is cookie-less and does not track visitors across sites. The dashboard itself carries no third-party analytics.

Who processes data for us

Three companies process data on our behalf, each only what its job requires: Cloudflare (hosting, storage and edge delivery), Stripe (payments) and Resend (sending sign-in emails). We do not sell or share personal data with anyone else.

How long we keep things

Sign-in links expire after fifteen minutes and are stored only as hashes. Sessions expire automatically. Account data is kept until you delete your account, which you can do yourself from the dashboard and which takes effect immediately. Scan analytics are aggregate statistics from the moment they are recorded — there is no personal record to delete. You can export your resolver data (products, destinations, rules and scan analytics) at any time.

Your rights

Under UK and EU data-protection law you can ask for access to, correction of, or erasure of your personal data, ask for it in a portable format, and object to or restrict processing. The export and delete controls in the dashboard cover most of this without asking us; for anything else, email hello@2dready.com and we will respond within a month. You can also complain to the Information Commissioner's Office (ico.org.uk) or your local EU supervisory authority.

International transfers

Cloudflare's network is global, and Stripe and Resend process some data in the United States. Where personal data leaves the UK or EEA, the transfer is covered by the providers' standard contractual clauses and the UK addendum.

Changes

If this policy changes materially we will update it here with a new date, and tell account holders by email when the change affects them. Last updated: 19 July 2026.