Legal & Transparency

Privacy Policy

At QRoute, we believe privacy is not an afterthought — it is a core engineering requirement. This policy explains what information we collect, how we process it, and how you retain full control over your data.

Last Updated: August 20, 2026Effective Date: August 20, 2026Version: 2.4

Zero Selling of Data

We do not sell, rent, or trade personal data or scanner telemetry to data brokers, ad networks, or third parties under any circumstances.

No Tracking Cookies on Scans

The dynamic QR redirect endpoint is completely clean. We do not drop tracking pixels or third-party cookies onto scanners' mobile devices.

Anonymized Coarse Geo-Location

IP addresses are analyzed in volatile memory to deduce general Country and City, then immediately salted and discarded. Precise GPS is never logged.

Global Compliance (GDPR / DPDP)

Engineered to satisfy the European GDPR, India's DPDP Act 2023, and the California CCPA/CPRA, including full data export and deletion rights.

1. Scope & Two Distinct Categories of Data

To understand our privacy practices, it is important to distinguish between the two separate categories of individuals who interact with QRoute:

A. Account Holders (“Customers”)

Individuals, publishers, brands, and organizations who create an account on QRoute to generate, configure, and manage dynamic QR codes, custom domains, and marketing campaigns.

B. End Scanners (“Visitors”)

End users in the physical world who point their smartphone cameras at a printed QR code on a textbook, packaging box, poster, or restaurant menu to be redirected to a destination link.

2. Information We Collect

2.1 Information Collected from Account Holders

  • Identity & Profile Data: Name, work email address, hashed passwords (bcrypt), organization name, and billing contact details.
  • Campaign & Project Data: QR code payloads (URLs, vCard data, Wi-Fi credentials, WhatsApp texts), book-edition-chapter hierarchies, tags, and verified custom domain hostnames.
  • Billing & Transaction Records: Subscription plan type, billing address, and transaction identifiers. Complete credit card details are processed directly by our PCI-DSS Level 1 compliant processors (Stripe/Razorpay) and never touch our servers.
  • API & Developer Data: API key identifiers (one-way SHA-256 hashed), webhook endpoints, and programmatic request metadata.

2.2 Information Collected from End Scanners (Privacy-Safe Telemetry)

When an end user scans a QRoute dynamic QR code, our edge resolution servers automatically extract minimal, anonymized telemetry strictly necessary to execute the redirect and display campaign metrics:

  • Coarse Location: Country, state/region, and city deduced from the IP address in memory at the edge node. Raw IP addresses are salted, truncated, and discarded.
  • Device & Software Environment: Device category (Mobile, Tablet, Desktop), operating system (iOS, Android, Windows, macOS), and browser type extracted from the standard HTTP User-Agent header.
  • Temporal Data: Timestamp of the scan (used for scan hourly heatmaps and time-based dynamic routing rules).
  • Referrer Domain: HTTP Referer header (if passed by the scanner's camera app or browser).
Important Note on Scanner Privacy:We do NOT collect scanners' GPS coordinates, names, phone numbers, email addresses, or camera sensor feeds. Scanning a code never requires account creation or app installation.

3. How We Use Collected Information

We use collected information exclusively for the following lawful business purposes:

To resolve dynamic QR codes and execute lightning-fast (<150ms) redirects to the customer's specified target URL.
To compile aggregated, non-personally identifiable scan analytics (total scans, unique estimates, device breakdowns, city maps).
To verify DNS ownership and enforce automated TLS/SSL certificate issuance for customer custom domains.
To actively defend against malicious URL injection, phishing, quishing, and automated bot scrapers.
To manage account authentication, billing, subscription renewals, and deliver essential platform operational notifications.

4. Cookies & Tracking Technologies

On the Dashboard (`app.qroute.in` & `qroute.in`): We use strictly necessary session cookies and local storage tokens for user authentication, security CSRF protection, and user preference persistence (e.g. dark/light mode, selected organization).

On the Dynamic QR Redirect Path (`go.yourbrand.com/*`): We strictly DO NOT set any third-party tracking cookies, advertising beacons, or canvas fingerprinting scripts. The redirect is executed via an HTTP 302 Found response for pure speed and zero tracker footprint.

5. Authorized Sub-Processors

We only share data with vetted third-party service providers who assist us in operating our infrastructure under strict Data Processing Agreements (DPAs):

Sub-ProcessorPurpose / ActivityData Location
Cloudflare, Inc.Edge CDN, DNS routing, DDoS mitigation, and TLS terminationUnited States / Global Anycast Network
Amazon Web Services (AWS)Encrypted cloud database hosting, serverless compute, and object storageAsia Pacific (Mumbai, ap-south-1) / US East
Stripe / RazorpayPCI-DSS compliant payment processing and subscription billingUnited States / India
Resend / AWS SESTransactional account verification emails, password resets, and alert deliveryUnited States / Global

6. Data Retention & Erasure Policies

  • Active Customer Accounts: Account data, projects, and active dynamic QR routing rules are retained for as long as your account remains in good standing.
  • Account Deletion: Upon receiving an account closure or deletion request, your account data, API keys, and custom domain bindings are permanently deleted from active production databases within 30 days.
  • Printed Code Continuity: Because dynamic QR codes may be printed on physical packaging or textbooks in circulation for years, organizations may choose to soft-archive codes or permanently release slugs upon request.
  • Encrypted Backups: Database backups are automatically overwritten and purged on a rolling 30-day lifecycle.

7. Your Legal Data Rights

Regardless of where you reside, QRouteextends universal data privacy rights under GDPR, CCPA/CPRA, and India's Digital Personal Data Protection Act (DPDP 2023):

Right to Access

Request a complete copy of all personal and organization data stored in your account.

Right to Rectification

Update or correct inaccurate account details directly in your dashboard or via support.

Right to Erasure (Be Forgotten)

Request permanent deletion of your account and all associated project data.

Right to Data Portability

Export your QR codes, scan logs, and metadata in open machine-readable CSV/JSON format.

Right to Restrict Processing

Pause or limit certain data processing operations without closing your account.

Right to Non-Discrimination

We never penalize, downgrade, or deny service for exercising your privacy rights.

8. Security Safeguards

We maintain enterprise-grade physical, technical, and administrative safeguards to protect your information against unauthorized access, destruction, or disclosure. For a full technical whitepaper, please visit our Security Trust Center.

9. Contacting Our Data Protection Officer (DPO)

If you have any questions, concerns, or requests regarding this Privacy Policy or wish to exercise your data subject rights, please contact our dedicated Data Protection Officer:

Entity Name: QRoute Technologies Pvt. Ltd.

Attn: Data Protection & Privacy Officer

Email: privacy@go.qroute.in (or support@qroute.in)

Response Timeframe: We respond to all formal privacy requests within 30 days.

Office Address: Koramangala Tech Enclave, 4th Block, Bengaluru, Karnataka 560034, India

Have questions about our privacy infrastructure?

Our compliance and security team is available to assist enterprise procurement audits and answer regulatory queries.