The short version
- We collect what we need to run your page, your QR and the tools you switch on — nothing to sell, no ads.
- Your customers' orders, bookings and messages belong to your business; we process them for you.
- QR scan stats use a daily-changing code, not your visitors' IP addresses or names.
- You can download or delete your data at any time by writing to [email protected].
This summary helps you find your way; the full text below is what applies.
01Who we are
EkQR (ekqr.me) is a product of Digipanda Consulting Private Limited, H-112, Sector 63, Noida, Uttar Pradesh 201301 ("EkQR", "we", "us"). This policy explains how we handle personal data when you use our website, the EkQR app and dashboard, and the pages and QR codes businesses publish with EkQR.
It is written to meet India's Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 and its rules, and to give people outside India the rights their own laws (such as the GDPR) give them.
02Two kinds of data, two roles
- Your account data — when you sign up and run a business on EkQR, we decide why and how that data is used. For this data we are the data fiduciary (the "controller").
- Your customers' data — when someone scans a business's QR and orders, books, leaves feedback or messages that business, the business decides what to collect and why. We process that data on the business's behalf and only on its instructions (we are its "processor"). If you are a customer of a business, the business's own privacy notice applies too, and requests about that data are best sent to the business; we will help it answer.
03What we collect
From business owners and their team
- Sign-in details: your mobile number (when you sign in with a WhatsApp or SMS code) or your Google account's name, email address and profile picture (when you continue with Google). We never see your Google password.
- Business details: name, type of business, address, phone and WhatsApp number, opening hours, and — if you pick your Google listing — the public details Google holds for it (rating, review count, map link).
- What you add: menus and catalogues, prices, photos, videos, PDFs, page text, links, offers, staff and services, automations and message templates.
- Connected accounts you choose to link: Google Business Profile, Instagram, WhatsApp (Meta Cloud API or a self-hosted connection) and similar. We store the access tokens these services give us, encrypted, and use them only to do what you asked (for example, reply to a review or a comment).
- Usage and device data: sign-in sessions, the device name you sign in from, push-notification tokens if you use the app, and basic logs (time, page or API route, error) used to keep the service secure and working.
- Billing details when paid plans are on: plan, invoices and GST details. Card and bank details are entered with our payment provider and never stored by us.
- What you tell support.
From people who visit a business's page or scan its QR
- Scan and visit statistics: the time, which QR or button was used, device type (for example Android or iPhone), browser, language and approximate location (country, region and city, worked out from the IP address on our own servers). To count unique visitors we keep a code made from the IP address and browser that changes every day and cannot be turned back into an IP address. We do not store visitors' IP addresses with these statistics.
- What a visitor chooses to send: for an order, the items, notes, table or delivery details, name and phone number; for a booking, the service, time, name and phone number; for feedback, the rating and message; and whether they agreed to get WhatsApp updates.
- Messages: WhatsApp messages sent to or from a business's connected number, and Instagram comments or direct messages that match the business's auto-reply rules, with the sender's username.
We do not ask for or knowingly collect sensitive data such as health, financial account numbers or government IDs. Please don't put them in notes or messages.
04Why we use it
| Purpose | Data used | Basis |
|---|---|---|
| Create your account, sign you in and keep it secure | Sign-in details, sessions, logs | Your consent and the contract with you |
| Run your page, QR codes, menu, orders, bookings and feedback | Business details, what you add, your customers' submissions | Contract with you (and the business's instructions for customer data) |
| Send the alerts and messages you switched on (new order, booking reminders, review replies) | Phone/WhatsApp numbers, message content | Contract; customer opt-in for WhatsApp updates |
| Show you analytics | Scan and visit statistics | Contract; legitimate use to provide the service |
| AI features you use (draft replies, captions, reading a menu photo) | The text or images you send to the feature | Your request |
| Prevent abuse, fraud, phishing and spam | Logs, page content, reports | Legitimate use; legal obligation |
| Billing, tax and accounting | Billing details | Contract; legal obligation |
| Tell you about important changes | Contact details | Contract |
We do not sell personal data, we do not use it for advertising, and we do not build profiles of the people who scan your QR.
05Data from Google and Meta
If you connect Google services (Sign in with Google, Google Business Profile, Places), we use the data only to provide the features you see in EkQR. EkQR's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use that data for advertising, do not sell it, and do not let people read it except with your permission, for security, or where the law requires.
Instagram and WhatsApp data is handled under Meta's platform terms in the same way: only to run the replies, messages and statistics you set up. You can disconnect any account from the dashboard at any time; we then delete its access tokens.
07Where it is stored
Our servers and storage providers may be in or outside India. Wherever data is processed, we apply the protections in this policy, and we do not transfer data to any country the Government of India has restricted.
08How long we keep it
- Login codes: until used, and at most a few minutes.
- Signed-in sessions: until you sign out, or up to 60 days without use.
- Account and business data: while your account is open. After you ask us to close your account we delete it within 30 days, except what we must keep by law (such as invoices).
- Your customers' orders, bookings, feedback and statistics: while the business's account is open, unless the business deletes them sooner.
- Database backups: kept for a short rolling period (currently 14 days) and then overwritten.
- Server logs: kept for a short period for security and debugging, then deleted.
09How we protect it
- Encrypted connections (HTTPS) everywhere.
- Each business's data is separated at the database level, so one business can never read another's.
- Access tokens for connected accounts are stored encrypted; login codes are stored only as one-way hashes.
- Your long-lived sign-in is kept in a secure, http-only cookie that page scripts cannot read.
- Access to production systems is limited to people who need it.
No system is perfectly secure. If a breach affects your personal data, we will tell you and the authorities as the law requires.
10Your rights
You can ask us to:
- give you a summary or a copy of the personal data we hold about you;
- correct or update it;
- delete it, or close your account;
- stop using it for something you had agreed to (withdraw consent) — this does not affect what was done before;
- nominate someone to act for you if you are unable to;
- and, if you are in a country with further rights (such as the EU or UK), to move your data or object to certain uses.
Write to [email protected] from the phone number or email on your account. We reply within 30 days. If you are not satisfied, you can contact our Grievance Officer (below) and, in India, the Data Protection Board of India.
11Children
EkQR is for businesses and adults. You must be 18 or older to create an account. We do not knowingly collect children's personal data; if you believe a child has given us data, write to [email protected] and we will delete it.
13Grievance Officer
In line with the Information Technology Act, 2000 and its rules, our Grievance Officer is Narender Rana, Digipanda Consulting Private Limited, H-112, Sector 63, Noida, Uttar Pradesh 201301. Email: [email protected]. We acknowledge complaints within 24 hours and aim to resolve them within 15 days.
14Changes to this policy
When we change this policy we update the date at the top. If a change is significant we will tell you in the app or by message before it applies.