STAYTAG

Privacy policy

Last updated 29 September 2026

Operator

Nytto Labs, operated by Fredrik Kornelind · F-tax

StayTag is a product of Nytto Labs in Sweden. Nytto Labs is a Swedish sole trader. Approved for F-tax. Registered for VAT.

What StayTag stores

StayTag does not provide accounts and does not store the content of tags in a database. Item names, optional part numbers, replacement dates, intervals, care history, optional photo hashes and marketplace settings are encoded after the # in the URL and QR code. Browsers do not send that fragment to the web server. Anyone with the QR or link can read these fields.

Optional photos

Photo hashing runs locally in your browser using SHA-256. StayTag never uploads or stores the photo. Only its hash is included in the tag and optional local My tags shelf. Keep the original file yourself; a hash cannot reconstruct the photo or certify maintenance.

On-device list

If your browser allows it, StayTag can keep a short list of tags you create so you can reopen or print them later. That list stays in the browser and is not uploaded. Private mode, blocked site data or a full storage quota can prevent saving; the QR and share link still work. Clearing the list, clearing site data or switching browsers removes the local copy. Printed labels are unchanged.

Hosting logs

The hosting provider may process ordinary request metadata such as IP address, user agent, requested path and timestamp for security and service operation. Newly generated tag data is kept in the URL fragment rather than the requested path. StayTag does not add advertising pixels or tracking cookies.

Minimal action counts

On production we send only an allowed event name and a fixed page category for page views, starting and creating labels, opening a tag, logging a replacement, print-dialog requests, PNG downloads, adding to or sharing a refill list, creating a Space, Return Wallet actions (opened, return added, code shown, dropped off, refunded, reminder added), store-link clicks and opening voluntary support checkout. We do not include URLs, QR contents, return codes, store names, amounts, item names, search phrases, part numbers, photo hashes, referrers, account IDs or visitor identifiers in these events. Hosting infrastructure may still process ordinary request metadata as described above. These are action counts, not unique visitors or linked individual journeys. Do Not Track and Global Privacy Control disable this measurement. Preview deployments and QA tabs are excluded. No payment is inferred from a click; payment status is checked in Stripe.

Your language choice is saved locally. Country headers are used transiently to suggest an eBay marketplace; country is not included in action events. The selected region can be changed before printing.

Return Wallet

Return Wallet stores the store name, optional item, return-by date, amount, drop-off method, note, status and the return code you add in this browser’s local storage, and an optional downscaled copy of your screenshot in this browser’s IndexedDB. None of it is sent to StayTag: screenshots and camera frames are decoded on your device, and there is no Return Wallet server or database. The camera is used only while you choose “Scan with camera” and is switched off when a code is found or you stop it. A link found inside a return code is shown with its host name and opened only if you tap it. Calendar files are created on your device and contain the store, item and date, not the code. A backup file you export contains your return codes and screenshots; keep it private. Delete returns individually, use “Delete everything”, or clear this site’s browser data.

StayTag Move

Your move (move name, box numbers, rooms, contents, notes and unpacked marks) is stored only in this browser. Each printed box QR contains that box’s move name, number, room, contents, flags and note after the # in the link, so anyone who scans the box can read them; it contains no name, address or account. If you buy a Move Pass, payment is handled by Stripe under its own privacy policy; we receive the payment and receipt details Stripe provides, never your box list. The pass is remembered in this browser using the checkout reference Stripe returns; our server sends that reference to Stripe once to confirm the payment (and re-checks it occasionally) and does not store or log it.

Refill Relay

Your refill list contains item names, search phrases, marketplaces and quantities. It is saved only in this browser when storage is available; if saving fails, the interface warns you to keep a share link before leaving. Shared lists encode those fields after the # in a link, without a StayTag database. Anyone receiving or forwarding that link can read them. Sharing through another app is your choice and that app processes the information under its own policy. Received lists are snapshots and do not overwrite your saved list. “Got it” checkmarks stay in the current tab and reset on reload; no purchase or delivery confirmation is sent. Remove local items in Refill Relay or clear this site’s browser data. Deleting your copy does not revoke copies already shared.

Marketplace links

When you choose a marketplace link, that marketplace applies its own privacy policy. StayTag currently routes each shopping region to one eBay marketplace (for example Europe / Nordics opens eBay.de). Links may contain an affiliate campaign identifier and a non-personal category label.

Your control

Anyone with a tag link can read the information encoded in it. The create flow previews the item name, search, date, market and share link before the QR is generated. Do not put personal, confidential or sensitive information in a tag. Destroy the printed tag and delete its link to remove your copy. The optional My tags list can be removed one item at a time or cleared on this device; StayTag has no server copy of it. Correcting a typo creates a new QR; previously printed labels continue to open the original details because StayTag cannot rewrite a sticker.

Privacy and GDPR requests

For privacy questions, access requests or deletion requests, email privacy@nyttolabs.com.

Seller Kits

Seller Kits encode the creator-supplied seller name, product, SKU, language and store URLs in the QR link fragment. They are public to anyone with the link and are not verified seller profiles. StayTag does not fetch these destinations. A store click can contribute an action count without recording the destination. Clicking a store link opens that store under its own privacy policy; URLs may contain creator-supplied affiliate or campaign parameters. StayTag does not add or replace affiliate IDs in Seller Kit links. Cards are fixed snapshots and cannot be revoked centrally. The pilot enquiry button opens your email app; it sends nothing until you choose to send.