Privacy Policy
At QRoute, we believe privacy is not an afterthought — it is a core engineering requirement. This policy explains what information we collect, how we process it, and how you retain full control over your data.
Zero Selling of Data
We do not sell, rent, or trade personal data or scanner telemetry to data brokers, ad networks, or third parties under any circumstances.
No Tracking Cookies on Scans
The dynamic QR redirect endpoint is completely clean. We do not drop tracking pixels or third-party cookies onto scanners' mobile devices.
Anonymized Coarse Geo-Location
IP addresses are analyzed in volatile memory to deduce general Country and City, then immediately salted and discarded. Precise GPS is never logged.
Global Compliance (GDPR / DPDP)
Engineered to satisfy the European GDPR, India's DPDP Act 2023, and the California CCPA/CPRA, including full data export and deletion rights.
1. Scope & Two Distinct Categories of Data
To understand our privacy practices, it is important to distinguish between the two separate categories of individuals who interact with QRoute:
A. Account Holders (“Customers”)
Individuals, publishers, brands, and organizations who create an account on QRoute to generate, configure, and manage dynamic QR codes, custom domains, and marketing campaigns.
B. End Scanners (“Visitors”)
End users in the physical world who point their smartphone cameras at a printed QR code on a textbook, packaging box, poster, or restaurant menu to be redirected to a destination link.
2. Information We Collect
2.1 Information Collected from Account Holders
- Identity & Profile Data: Name, work email address, hashed passwords (bcrypt), organization name, and billing contact details.
- Campaign & Project Data: QR code payloads (URLs, vCard data, Wi-Fi credentials, WhatsApp texts), book-edition-chapter hierarchies, tags, and verified custom domain hostnames.
- Billing & Transaction Records: Subscription plan type, billing address, and transaction identifiers. Complete credit card details are processed directly by our PCI-DSS Level 1 compliant processors (Stripe/Razorpay) and never touch our servers.
- API & Developer Data: API key identifiers (one-way SHA-256 hashed), webhook endpoints, and programmatic request metadata.
2.2 Information Collected from End Scanners (Privacy-Safe Telemetry)
When an end user scans a QRoute dynamic QR code, our edge resolution servers automatically extract minimal, anonymized telemetry strictly necessary to execute the redirect and display campaign metrics:
- Coarse Location: Country, state/region, and city deduced from the IP address in memory at the edge node. Raw IP addresses are salted, truncated, and discarded.
- Device & Software Environment: Device category (Mobile, Tablet, Desktop), operating system (iOS, Android, Windows, macOS), and browser type extracted from the standard HTTP
User-Agentheader. - Temporal Data: Timestamp of the scan (used for scan hourly heatmaps and time-based dynamic routing rules).
- Referrer Domain: HTTP Referer header (if passed by the scanner's camera app or browser).
3. How We Use Collected Information
We use collected information exclusively for the following lawful business purposes:
4. Cookies & Tracking Technologies
On the Dashboard (`app.qroute.in` & `qroute.in`): We use strictly necessary session cookies and local storage tokens for user authentication, security CSRF protection, and user preference persistence (e.g. dark/light mode, selected organization).
On the Dynamic QR Redirect Path (`go.yourbrand.com/*`): We strictly DO NOT set any third-party tracking cookies, advertising beacons, or canvas fingerprinting scripts. The redirect is executed via an HTTP 302 Found response for pure speed and zero tracker footprint.
5. Authorized Sub-Processors
We only share data with vetted third-party service providers who assist us in operating our infrastructure under strict Data Processing Agreements (DPAs):
| Sub-Processor | Purpose / Activity | Data Location |
|---|---|---|
| Cloudflare, Inc. | Edge CDN, DNS routing, DDoS mitigation, and TLS termination | United States / Global Anycast Network |
| Amazon Web Services (AWS) | Encrypted cloud database hosting, serverless compute, and object storage | Asia Pacific (Mumbai, ap-south-1) / US East |
| Stripe / Razorpay | PCI-DSS compliant payment processing and subscription billing | United States / India |
| Resend / AWS SES | Transactional account verification emails, password resets, and alert delivery | United States / Global |
6. Data Retention & Erasure Policies
- Active Customer Accounts: Account data, projects, and active dynamic QR routing rules are retained for as long as your account remains in good standing.
- Account Deletion: Upon receiving an account closure or deletion request, your account data, API keys, and custom domain bindings are permanently deleted from active production databases within 30 days.
- Printed Code Continuity: Because dynamic QR codes may be printed on physical packaging or textbooks in circulation for years, organizations may choose to soft-archive codes or permanently release slugs upon request.
- Encrypted Backups: Database backups are automatically overwritten and purged on a rolling 30-day lifecycle.
7. Your Legal Data Rights
Regardless of where you reside, QRouteextends universal data privacy rights under GDPR, CCPA/CPRA, and India's Digital Personal Data Protection Act (DPDP 2023):
Right to Access
Request a complete copy of all personal and organization data stored in your account.
Right to Rectification
Update or correct inaccurate account details directly in your dashboard or via support.
Right to Erasure (Be Forgotten)
Request permanent deletion of your account and all associated project data.
Right to Data Portability
Export your QR codes, scan logs, and metadata in open machine-readable CSV/JSON format.
Right to Restrict Processing
Pause or limit certain data processing operations without closing your account.
Right to Non-Discrimination
We never penalize, downgrade, or deny service for exercising your privacy rights.
8. Security Safeguards
We maintain enterprise-grade physical, technical, and administrative safeguards to protect your information against unauthorized access, destruction, or disclosure. For a full technical whitepaper, please visit our Security Trust Center.
9. Contacting Our Data Protection Officer (DPO)
If you have any questions, concerns, or requests regarding this Privacy Policy or wish to exercise your data subject rights, please contact our dedicated Data Protection Officer:
Entity Name: QRoute Technologies Pvt. Ltd.
Attn: Data Protection & Privacy Officer
Email: privacy@go.qroute.in (or support@qroute.in)
Response Timeframe: We respond to all formal privacy requests within 30 days.
Office Address: Koramangala Tech Enclave, 4th Block, Bengaluru, Karnataka 560034, India