Privacy Policy

Last updated: 15 August 2026

This policy explains what ScanzQR collects, why, and what your rights are. We collect the minimum needed to run the Service and we do not sell personal data.

1. Data we collect from account holders

  • Account data: email address, password (stored only as a salted hash), business name.
  • Business content: menus, page content, QR designs, review-suggestion pools you create.
  • Usage data: AI-generation counts and basic logs needed to operate fair-use limits.

2. Data collected when someone scans a QR

When a customer scans a dynamic QR or uses a hosted page, we record on behalf of the business: timestamp, browser user-agent, referrer, and, where the hosting infrastructure provides it, coarse location (country/city). We do not store scan-level precise location and we do not build cross-site profiles of visitors.

On review cards, star ratings are recorded, and any private feedback a customer chooses to submit (message and optional contact details) is delivered to the business that owns the card. That business is responsible for handling it under its own privacy obligations.

3. AI processing

AI features (review suggestions, reply drafts) send the text you provide, such as a pasted review and your business name, to Anthropic's Claude API for processing. We do not use your content to train models.

4. Third parties we rely on

  • Anthropic: AI text generation.
  • Razorpay: payment processing (they receive billing details; we never see your full card number).
  • Email provider: transactional email such as password resets.
  • Hosting and database providers: running the Service.

5. Cookies

We use one essential session cookie to keep you signed in. No advertising or cross-site tracking cookies.

6. Retention and deletion

Account data is kept while your account is active. You can request a copy or deletion of your data at any time by emailing [email protected]; we complete deletion requests within 30 days, except records we must keep by law (such as invoices).

7. Security

Passwords are hashed with bcrypt; session and reset tokens are stored only as SHA-256 hashes; access to production data is restricted. No system is perfectly secure. Report concerns to [email protected].

8. Changes

We will post any changes to this policy on this page and update the date above.