ReviewQR

Legal

Privacy Policy

Last updated:

In short
  • Business owners: we keep your email, name and profile picture from Google, your plan and billing status, and the business details you type in.
  • Customers who scan a QR code are not asked for personal details. Our database stores only anonymous records that a scan, draft or tap happened, with the time. It holds no IP address or device ID.
  • We do not store the draft reviews.
  • We use only the cookies that sign-in needs. We do not use advertising or analytics cookies, and we do not sell personal data.
  • You can ask us to correct or delete your data at any time.

About this policy

This policy explains what personal data ReviewQR collects, why we collect it, who else handles it, how long we keep it and what rights you have. It is written to follow India’s Digital Personal Data Protection Act, 2023 (the DPDP Act) and the Information Technology Act, 2000, and the rules made under them.

ReviewQR is run by Divyansh Shukla, an individual (sole proprietor) based in India. For the DPDP Act, we are the “data fiduciary” for the data described here. You can reach us on the Contact page.

What we collect and why

Business owners (when you sign in)

  • From Google: your email address, name and profile picture link. We use them to create your account and sign you in.
  • Account and billing details: your plan, your Razorpay subscription ID and status, the end date of the current period, whether you have asked to cancel, the end date of any Pro period we grant you directly, and the date your account was created. We use them to give you the right plan and manage billing.
  • Business details: for each location, its name, Google Place ID, category, description, highlights, language and page address. We use them to run your QR page and write drafts.
  • Activity records: for each location we record when someone opens its page (a scan), asks for a draft, or taps the button to open Google, with the time. We show these to you as statistics. They are not linked to who the visitor is.

Customers (when you scan a QR code)

  • We do not ask for your name, email or any account. Our database does not store your IP address, your device ID or the draft review.
  • To stop abuse we keep short-lived counters linked to your IP address. They expire within minutes.
  • Our server and Cloudflare can keep ordinary technical logs, which may include your IP address, browser type and the pages requested. We use them to keep the service running, fix faults and stop abuse.
  • The draft is written when you open the page and is shown in your browser. If you edit it, your edits stay in your browser. When you tap the button, the text is copied to your clipboard and Google’s review screen opens. What you do on Google is between you and Google. We never post for you, and we do not see your Google identity.

Payments

When you subscribe to Pro, you pay in a window run by Razorpay. We never see or store your card, UPI or bank details. Razorpay tells us the status of your subscription and gives us its IDs. Razorpay’s own privacy policy covers the data it collects.

What the AI model sees

To write a draft we send the business name, category, description, highlight keywords and language to OpenRouter and the AI model providers behind it. We do not send customers’ personal data, and we do not send your email address or name. These providers handle that text under their own policies, so please do not put personal or confidential information in those fields.

Why we may use your data

Under the DPDP Act we can use personal data only with your consent or for a purpose the Act allows.

  • Consent. When you sign in with Google and accept our Terms and this policy, you agree to us using the data above to provide ReviewQR to you. You can withdraw your consent at any time (see Your rights).
  • Uses the Act allows. For example, using data you voluntarily gave us only for the purpose you gave it (such as the business details you type in), and complying with a law or a lawful order.
  • Customers. A customer who opens the page voluntarily asks for a draft. The technical data described above is used only to show the page, keep it secure and stop abuse.

Who else handles your data

  • Google handles sign-in. Customers are sent to Google’s own review page, where Google’s privacy policy applies.
  • Razorpay handles payments and subscriptions.
  • OpenRouter and the AI model providers behind it write the drafts (see above).
  • Cloudflare provides DNS, proxy and content delivery. Traffic to the site passes through it.
  • Our hosting is a virtual private server (VPS) that we manage ourselves. The app, the database and the cache run there.

We do not sell personal data, and we do not share it for advertising. We may disclose data when a law, court or authority requires it, or to protect our rights or the safety of others.

Transfers outside India

Some of these services, including OpenRouter, the AI model providers behind it and Cloudflare, may process data outside India. The DPDP Act allows such transfers except to countries that the Government of India restricts.

Cookies

We use only the cookies that sign-in needs to work: a session cookie that keeps you signed in, and security cookies that protect the sign-in process. We do not use advertising, analytics or tracking cookies, so there is no cookie banner. Razorpay’s payment window and Google’s pages may set their own cookies under their own policies.

How long we keep data

  • Account data: until your account is deleted.
  • Business details and activity records: until you delete the location (its activity records are deleted with it) or your account.
  • Draft reviews: not stored.
  • IP-based abuse counters: a few minutes.
  • Cached public page details (such as a location’s name): short-lived.
  • Server and proxy logs: only as long as needed for the purposes above.
  • Billing records: we may keep payment and subscription references for as long as the law requires for accounting and tax, even after you delete your account.

When you ask us to delete your account, we delete your data within 30 days, except what the law requires us to keep. Backup copies, if we keep any, are overwritten in the normal course.

Security

We take reasonable steps to protect your data:

  • We never see or store your Google password or your card, UPI or bank details.
  • We collect little data to begin with, and our database holds no visitor identifiers.
  • The site is served over HTTPS.
  • Access to our server and database is limited to what is needed to run the service.

No online service is completely secure. If a personal data breach affects you, we will tell you and the authorities as the law requires.

Your rights

Under the DPDP Act you can:

  • ask for a summary of the personal data we hold about you and who we have shared it with;
  • ask us to correct, complete or update it;
  • ask us to erase it;
  • withdraw your consent at any time. We will then stop using your data, and you will no longer be able to use your account. This does not affect what we did before you withdrew;
  • nominate someone to exercise these rights for you if you die or cannot act for yourself; and
  • make a complaint to us (see Grievance Officer below) and, if we do not resolve it, to the Data Protection Board of India.

To use any of these rights, email [email protected] from the email address of your account and tell us what you want. We may ask you to confirm that it is you. We reply within 2 business days and act on your request within 30 days.

The public QR page does not store visitor identifiers, so we usually cannot find or delete data about a particular customer. Their IP-based counters expire within minutes anyway.

Children

ReviewQR accounts are for people aged 18 and over, and we do not knowingly collect personal data from anyone under 18. The public review page does not ask for personal details and shows no ads. If you think a child has given us personal data, email us and we will delete it.

Changes to this policy

We may update this policy. If a change is material, we will tell you by email or in your dashboard before it takes effect, and we will ask for your consent again where the law requires. The date at the top shows the latest version.

Grievance Officer

If you have a question or complaint about your personal data, contact our Grievance Officer:

We acknowledge complaints within 48 hours and resolve them within 30 days. More ways to reach us are on the Contact page.

ReviewQR is run by Divyansh Shukla, India.