Privacy Policy
BarqScanner Technologies operates BarqScanner. This policy explains what information we collect, why we collect it, and how you can control it. We are committed to protecting your privacy and being transparent about our practices.
1. Overview
BarqScanner is a barcode capture platform for warehouses and logistics operations. Our core function is to decode barcodes from images and return structured data. We have designed our system with a privacy-first approach.
Key fact: Barcode images you submit to the API are processed in memory and discarded immediately after decoding — typically within 2 seconds. We do not store a copy of your images on any server or database.
2. What We Collect
We collect the minimum data necessary to operate the service:
Account Information
- Email address (used for login and transactional emails)
- First and last name
- Organization / company name
- Country (used for currency detection and tax calculation)
- Password (stored as a bcrypt hash — we cannot read your password)
Usage Data
- Number of API calls made (for billing and plan limits)
- Scan metadata: timestamp, number of barcodes found, processing time in milliseconds, station ID
- API key identifiers (not the key value itself after creation)
- Station device model and OS version (provided during station pairing)
Billing Information
- Payment is processed by Razorpay. We do not store credit card numbers on our servers
- We retain Razorpay customer ID and subscription status for billing management
- Invoice history is retained for 7 years as required by Indian tax law
Technical Data
- IP address (retained in server logs for up to 30 days for security purposes)
- Browser type and version (for dashboard support)
- Error logs (sanitized — no personal data included)
3. What We Do NOT Collect or Store
Barcode images are never stored. When you POST an image to /v1/scan, it is decoded in memory and the image bytes are discarded. We retain only the count and metadata of what was decoded, not the decoded values themselves.
- We do not store the barcode image you submit
- We do not store the decoded barcode values (GTIN, serial numbers, batch numbers, etc.)
- We do not sell your data to third parties
- We do not use your data for advertising
- We do not track your customers or the products you scan
4. How We Use Data
We use the data we collect to:
- Provide the service: Authenticate requests, enforce plan limits, route scan results to the correct station
- Billing: Calculate usage, generate invoices, process payments via Razorpay
- Communication: Send transactional emails (welcome, password reset, usage warnings, billing receipts)
- Support: Diagnose technical issues when you report them
- Security: Detect and prevent abuse, unauthorized access, and fraud
- Product improvement: Aggregate, anonymized usage statistics (e.g., "most used barcode format") to guide development decisions
We do not use your data for any other purpose without your explicit consent.
6. Third-Party Services
We use the following third-party services:
- Razorpay (razorpay.com) — Payment processing. Your payment information is transmitted directly to Razorpay. See Razorpay's Privacy Policy.
- ipapi.co — Optional geolocation (only used as a fallback when Vercel geo headers are not available, such as on self-hosted deployments). Only your IP address is sent. No personal data.
We do not share your personal information with any other third party without your consent, except where required by law.
7. Data Retention
- Account data: Retained while your account is active. After account deletion, scheduled for permanent deletion within 30 days.
- Scan metadata: Retained for 12 months for usage history, then aggregated and anonymized.
- Billing records: Retained for 7 years as required by Indian tax regulations (Income Tax Act).
- Server logs: IP addresses in logs are retained for 30 days, then automatically purged.
8. Your Rights
You have the following rights regarding your personal data:
- Access: Request a copy of all data we hold about you
- Correction: Update inaccurate information from your dashboard settings
- Deletion: Delete your account and data from Dashboard → Settings → Delete Account
- Export: Download your account and usage data in JSON format
- Objection: Object to processing of your data for legitimate interests
To exercise any right, email privacy@barqscanner.com with your account email. We will respond within 5 business days.
If you are in the European Economic Area, you have additional rights under GDPR. If you are in India, your rights are governed by the Digital Personal Data Protection Act (DPDPA) 2023.
9. Security
We implement industry-standard security measures:
- All data in transit is encrypted with TLS 1.3
- Passwords are hashed with bcrypt (never stored in plaintext)
- API keys are hashed — the raw key is only shown once at creation
- Webhook payloads are signed with HMAC-SHA256 so you can verify authenticity
- Production database backups are encrypted and retained for 7 days
To report a security vulnerability, email security@barqscanner.com. We take all reports seriously and respond within 24 hours.
10. Contact
The data controller for BarqScanner is:
BarqScanner Technologies
Tamil Nadu, India
Email: privacy@barqscanner.com
For general inquiries: hello@barqscanner.com
For security issues: security@barqscanner.com
For legal matters: legal@barqscanner.com
Questions about your privacy?
If you have questions or concerns, email us at privacy@barqscanner.com. We respond within 2 business days.