QRCodeKey
Privacy Policy

QRCodeKey Privacy Policy

Last Updated: May 2, 2026 | Effective Date: April 21, 2026

Introduction

QRCodeKey ("we," "us," "our," or the "Company") is operated by Jal Technology LLC, located at 2501 Chatham Rd Suite N, Springfield, IL 62704, USA. Jal Technology LLC is the data controller responsible for your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

Current Service Scope

QRCodeKey is currently offered to users located in the United States of America (all 50 states, Washington D.C., Puerto Rico, and US Territories). We are progressively expanding to additional countries — including India, the European Economic Area, the United Kingdom, Canada, Australia, Brazil and others — once we obtain the necessary regulatory registrations and local representatives.

Forward-looking jurisdiction sections: This Privacy Policy includes detailed sections describing how we will handle data under non-US laws (GDPR, UK GDPR, India DPDP Act 2023, Canada PIPEDA, Brazil LGPD, Australia Privacy Act 1988, South Africa POPIA, Japan APPI, South Korea PIPA, Singapore PDPA, China PIPL, Thailand PDPA, Philippines DPA, Indonesia PDP, Malaysia PDPA, New Zealand Privacy Act 2020, Switzerland nFADP, UAE PDPL, Saudi PDPL, Israel Protection of Privacy Law, Turkey KVKK, Qatar DPL, Bahrain PDPL, Nigeria DPA 2023, Kenya DPA 2019, Egypt DPL, Mexico LFPDPPP, Argentina PDPL, Colombia Law 1581, Chile Law 19.628, Russia Federal Law 152-FZ, and others). Those provisions reflect our intended compliance posture and become effective in each jurisdiction only after we have officially launched the service there. Until launch, US-based privacy law (CCPA/CPRA, state privacy laws, COPPA, TCPA, CAN-SPAM, FTC Act) governs.

Information We Collect

1. Personal Information

  • Name: Your full name
  • Email: Your email address for account creation and communication
  • Phone: Your phone number (optional)

2. Location Information

  • GPS Data: Your precise location when scanning QR codes (with your consent)
  • IP Address: Automatically collected to determine approximate location

3. Device Information

  • • Device type, OS version, browser type
  • • Device ID and unique identifiers
  • • App version and usage statistics

4. QR Code Data

  • • QR codes you create
  • • Scan history, timestamp, and frequency
  • • Scanned device information

How We Use Your Information

We collect and process your information for the following purposes:

  • QR Code Tracking: To create, manage, and track QR codes and their scans
  • Attendance Management: To record attendance and generate attendance reports
  • Notifications: To send you push notifications, emails, and SMS about QR activities
  • AI Chatbot (AG): To power our AI virtual assistant that helps you manage QR codes, groups, plans, and account actions
  • Account Management: To maintain your account and provide customer support
  • Analytics: To understand usage patterns and improve our service
  • Payments: To process payments through Stripe
  • Legal Compliance: To comply with laws and regulations

Third-Party Service Providers

We share your information with trusted third-party services. A complete and current list of all sub-processors, including the data they process and their location, is available on our Sub-Processors page. The most commonly used providers are listed here:

MongoDB Atlas

Cloud database service for storing user data, QR codes, and scan logs. Data is encrypted at rest and in transit.

Stripe

Payment processor for subscription payments. We do not store payment card information. Stripe handles all payment processing securely.

Google Maps

Used to display location data on maps and to convert GPS coordinates into a human-readable address (reverse geocoding). Your location is processed according to Google's privacy policy at https://policies.google.com/privacy. Accuracy disclaimer: automatic address detection depends on Google's address database, GPS signal strength, indoor/outdoor conditions, and your device. The detected house number, street name, or building can sometimes be off by a few houses or show the nearest registered address (for example, "123 Main St" when the actual location is "125 Main St") if your specific address has not yet been indexed by Google. Both the QR-scan flow and the group-creation flow include a draggable map pin and a manual house-number adjuster (the yellow editor) so you can correct any detected address before saving. We also fall back to OpenStreetMap (Nominatim) if Google does not return a match.

OpenStreetMap (Nominatim)

Free, community-maintained mapping service used as a backup reverse-geocoding source when Google Maps is unavailable or returns no result. Your latitude/longitude is sent to OpenStreetMap's Nominatim service to retrieve a street address. OpenStreetMap is operated by the OpenStreetMap Foundation, UK; usage is governed by https://osmfoundation.org/wiki/Privacy_Policy.

Telnyx

Third-party SMS messaging provider used to deliver text-message OTPs (one-time passwords) and account notifications. Telnyx receives your phone number and message content to deliver SMS to your device. Telnyx processes this data per its privacy policy at https://telnyx.com/legal/privacy-policy.

Resend

Transactional email delivery service used as our primary email channel for password-reset OTPs, account notifications, and system alerts. Resend receives your email address and the message content. Resend processes this data per its privacy policy at https://resend.com/legal/privacy-policy.

Brevo (Sendinblue)

Backup transactional email provider used when our primary email channel is unavailable. Brevo (operated by Sendinblue SAS, France) receives your email address and the message content. Brevo processes data within the European Union per its privacy policy at https://www.brevo.com/legal/privacypolicy/.

Render

Cloud hosting platform used to host QRCodeKey's web application and backend services. Render may process server logs containing IP addresses and request data as part of standard web hosting operations.

OpenAI

AI language model provider used to power our AI chatbot assistant "AG." When you interact with AG, your messages and recent conversation history (last 10 messages) are sent to OpenAI's API for processing. OpenAI processes this data to generate responses and does not use API-submitted data to train their models. Your conversation data is subject to OpenAI's API data usage policy. We do not permanently store your chat conversations on our servers — they exist only during your active session.

AI Chatbot (AG) — Data Processing

QRCodeKey's AI-powered virtual assistant "AG" processes the following data to provide its services:

Data Collected During Chat

  • Messages: Text messages you send to AG during your conversation
  • Conversation Context: Up to 10 recent messages are retained in your session for context
  • Account Info: If logged in, AG may access your name, email, subscription plan, QR code list, and group memberships to assist you
  • Actions Taken: Records of actions AG performs on your behalf (QR creation, plan changes, etc.)

Data Retention

  • • Chat conversations are not permanently stored on our servers
  • • Session-based conversation history is cleared when you close the chat or refresh the page
  • • Actions performed by AG (e.g., QR code creation) are logged as regular platform activity

Data Sharing with OpenAI

Your messages are sent to OpenAI's API (GPT-4o-mini model) for response generation. OpenAI's API data policy states that API inputs and outputs are not used to train their models. Data may be retained by OpenAI for up to 30 days for abuse monitoring, after which it is deleted. For more information, see OpenAI's API Data Usage Policy.

Your Rights Regarding AI Data

You have the right to: choose not to use the AG chatbot (it is an optional feature), request information about what data AG has access to, opt out of AI-powered features by simply not using the chat widget. All other data protection rights outlined in this Privacy Policy (access, correction, deletion, etc.) apply equally to any data processed through AG.

Billing Information

When you purchase a subscription, we store billing metadata including your billing address, payment method type (e.g., Visa, Mastercard), last four digits of your card, transaction amounts, and transaction history. We do NOT store your full credit card number, CVV, or full payment credentials — these are handled exclusively by Stripe's PCI-compliant payment infrastructure.

Data Retention

We retain your personal data as long as your account is active. When you delete your account, we will permanently delete all associated data within 30 days, including:

  • • Your profile information
  • • All QR codes you created
  • • All scan logs and attendance records
  • • Team and organization data
  • • Payment history

Your Privacy Rights

You have the following rights regarding your data:

Right to Access

You can request a complete export of all your data in JSON format at any time.

Right to Delete

You can delete your account and all associated data at any time from your Profile settings.

Right to Data Portability

You can export your data in a machine-readable format for use with other services.

Right to Rectification

You can correct or update inaccurate or incomplete personal data at any time from your account settings.

Right to Restriction of Processing

You can request that we restrict the processing of your personal data under certain conditions by contacting us.

Right to Object

You can object to the processing of your personal data for direct marketing or other purposes based on our legitimate interests.

Right to Withdraw Consent

You can withdraw consent for location tracking, marketing communications, and other consent-based processing at any time in your account settings.

Data Security

We implement industry-standard security measures to protect your data:

  • • Data encryption in transit (TLS/SSL)
  • • Data encryption at rest in MongoDB Atlas
  • • Password hashing with bcrypt (12-round salting)
  • • JWT token authentication
  • • Rate limiting to prevent unauthorized access
  • • Regular security audits

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting the new policy on our website with an updated "Last Updated" date.

Your California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with specific rights regarding your personal information.

Right to Know

You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which your personal information was collected, the business or commercial purpose for collecting your personal information, and the categories of third parties with whom we share your personal information.

Right to Delete

You have the right to request that we delete any personal information we have collected from you, subject to certain exceptions provided by law.

Right to Correct

You have the right to request that we correct inaccurate personal information that we maintain about you.

Right to Opt-Out of Sale

QRCodeKey does NOT sell your personal information to third parties. We do not sell, rent, or trade your personal data for monetary or other valuable consideration. Because we do not sell personal information, there is no need to opt out; however, if our practices change, we will update this policy and provide an opt-out mechanism.

Do Not Sell My Personal Information

As stated above, we do not sell your personal information. We do not share your personal information for cross-context behavioral advertising purposes.

Right to Non-Discrimination

We will not discriminate against you for exercising any of your CCPA/CPRA rights. We will not deny you goods or services, charge you different prices, provide a different quality of service, or suggest that you may receive a different price or quality of service for exercising your rights.

Verification Process

When you submit a request to know or delete, we will verify your identity by matching information you provide with information we already have on file. We may ask you to confirm your email address, account details, or other identifying information.

Authorized Agent

You may designate an authorized agent to submit a request on your behalf. The authorized agent must provide proof of written permission from you and we may still require you to verify your identity directly with us.

Annual Metrics Disclosure

In compliance with CCPA/CPRA requirements, we will publish annual metrics on consumer requests received, including the number of requests to know, requests to delete, and requests to opt-out, along with the median response time and compliance rate. These metrics will be available upon request by contacting us at info@qrcodekey.com.

To exercise any of these rights, use the self-service form at qrcodekey.com/privacy/delete-my-data (no QRCodeKey account required), email info@qrcodekey.com, or call (708) 690-0550. We will respond to your request within 45 calendar days. If we need additional time due to the complexity of the request, we may extend this period by up to 45 additional calendar days (90 calendar days total), and will notify you of the extension.

Additional State Privacy Rights

In addition to California rights described above, residents of certain other states have privacy rights under their respective laws:

Virginia (VCDPA)

Virginia residents have the right to access, correct, delete, and obtain a copy of their personal data, as well as the right to opt out of the processing of personal data for targeted advertising, sale of personal data, or profiling.

Colorado (CPA)

Colorado residents have the right to opt out of targeted advertising, sale of personal data, and certain profiling. You also have the right to access, correct, delete, and obtain a portable copy of your personal data.

Connecticut (CTDPA)

Connecticut residents have the right to access, correct, delete, and obtain a copy of their personal data, and the right to opt out of the sale of personal data, targeted advertising, and profiling.

To exercise any of these rights, please contact us at info@qrcodekey.com. If your request is denied, you have the right to appeal by contacting us at the same address.

Do Not Track Signals

Some web browsers transmit "Do Not Track" (DNT) signals to websites. Because there is no universally accepted standard for how to respond to DNT signals, QRCodeKey does not currently respond to DNT browser signals or headers. However, you can manage your privacy preferences through your account settings and the cookie management options described below. We will update this policy if a uniform DNT standard is adopted.

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to collect and track information about your use of our service. Cookies are small data files placed on your device.

Essential Cookies

These cookies are necessary for the website to function properly. They enable core features such as authentication, session management, and security. You cannot opt out of essential cookies as the service will not function without them.

Analytics Cookies

These cookies help us understand how visitors interact with our website by collecting and reporting information anonymously. Analytics data helps us improve our service and user experience.

Managing Cookies: You can control and manage cookies through your browser settings. Most browsers allow you to refuse cookies, delete existing cookies, or be notified before a cookie is set. Please note that disabling cookies may affect the functionality of our service.

For more details, please see our Cookie Policy.

SMS Communications and TCPA Compliance

QRCodeKey may send SMS text message notifications related to QR code activity, OTP verification, attendance alerts, and account updates via our third-party messaging provider, Telnyx.

  • Consent: By providing your phone number and enabling SMS notifications, you expressly consent to receive automated text messages from QRCodeKey. Consent is not a condition of purchase or use of our service.
  • Message Frequency: Message frequency varies based on your account activity and notification settings. You may receive messages related to QR code scans, attendance events, and account alerts.
  • Message and Data Rates: Message and data rates may apply depending on your mobile carrier and plan. QRCodeKey is not responsible for any charges from your mobile carrier.
  • Opt-Out: You can opt out of SMS notifications at any time by replying STOP to any message you receive from us, or by disabling SMS notifications in your account settings. After opting out, you will receive a final confirmation message.
  • Help: Reply HELP to any message for assistance, or contact us at info@qrcodekey.com.

QRCodeKey complies with the Telephone Consumer Protection Act (TCPA) and all applicable federal and state regulations governing automated text messaging. We will not send SMS messages to any number that has not opted in to receive communications from us.

CAN-SPAM Compliance

QRCodeKey complies with the CAN-SPAM Act for all commercial email communications. In accordance with CAN-SPAM, we agree to the following:

  • • We will not use false or misleading subjects or email addresses.
  • • We will identify the message as an advertisement when applicable.
  • • We will include our physical mailing address in every email: 2501 Chatham Rd Suite N, Springfield, IL 62704, USA.
  • • We will honor opt-out and unsubscribe requests promptly, within 10 business days.
  • • We will provide a clear unsubscribe mechanism in every commercial email.

To unsubscribe from our emails, click the "Unsubscribe" link at the bottom of any email, or contact us at info@qrcodekey.com.

Data Breach Notification

In the event of a data breach that compromises your personal information, QRCodeKey will:

  • • Investigate and contain the breach as quickly as possible.
  • • Notify affected users via email and/or SMS without unreasonable delay.
  • • Notify the appropriate regulatory bodies as required by applicable laws.
  • • Provide a description of the breach, the types of information involved, steps we have taken in response, and recommendations for affected users to protect themselves.
  • • Offer identity theft protection services if sensitive personal information is compromised.

Jurisdiction-Specific Timelines:

  • EU/EEA (GDPR): Notify supervisory authority within 72 hours of becoming aware (Article 33); notify affected individuals without undue delay where there is a high risk (Article 34).
  • United Kingdom: Notify the ICO within 72 hours; notify affected individuals without undue delay where high risk exists.
  • United States (Illinois): Within 30 days under the Illinois Personal Information Protection Act; other states as required by their respective breach notification laws.
  • Canada (PIPEDA): Notify affected individuals and the Privacy Commissioner of Canada as soon as feasible.
  • Australia: Notify the OAIC and affected individuals as soon as practicable under the Notifiable Data Breaches scheme (Privacy Act 1988, Part IIIC).
  • Brazil (LGPD): Notify the ANPD and affected individuals within a reasonable timeframe as defined by the ANPD.
  • India (DPDP): Notify the Data Protection Board of India without delay.
  • South Africa (POPIA): Notify the Information Regulator and affected individuals as soon as reasonably possible.
  • All other jurisdictions: In accordance with the breach notification requirements of your local data protection law.

International Data Transfers

QRCodeKey is operated from the United States, and your personal data is stored and processed on servers located in the United States. If you access our service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country of residence. By using QRCodeKey, you consent to the transfer of your information to the United States and the processing of your data in accordance with this Privacy Policy and applicable US laws.

Third-Party Links

Our service may contain links to third-party websites, services, or applications that are not operated by QRCodeKey. If you click on a third-party link, you will be directed to that third party's website. We strongly advise you to review the privacy policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services. QRCodeKey is not liable for any damages or losses arising from your use of third-party websites or services.

No Biometric Identifiers

QRCodeKey does not collect, store, process, sell, lease, trade, profit from, or otherwise handle biometric identifiers or biometric information of any kind. We do not use facial geometry, fingerprints, voiceprints, retina or iris scans, hand geometry, gait, or any analogous identifier in any product or service. The previously available face-verification attendance feature has been removed from QRCodeKey, all associated APIs are decommissioned, and all biometric records collected under the prior policy have been permanently destroyed.

Accordingly, the following biometric-privacy regimes are not engagedby our current product: the Illinois Biometric Information Privacy Act (BIPA, 740 ILCS 14), Texas Capture or Use of Biometric Identifier Act (CUBI), Washington H.B. 1493, New York City Biometric Identifier Information Law, GDPR Article 9 (special-category biometric data), UK GDPR Article 9, India DPDP Act 2023 / SPDI Rule 8 (biometric sensitive personal data), Brazil LGPD Article 11 (sensitive personal data), Canada PIPEDA, China PIPL Article 28 (sensitive personal information), and analogous regimes. Anti-proxy attendance is implemented entirely through GPS geofence verification, device / IP signals, and the Group Admin's own at-the-entry identity check (e.g., photo-ID review).

Reintroduction policy.If we ever reintroduce a biometric feature in the future, we will publish a separate Biometric Privacy Policy with a written retention & destruction schedule, run a new BIPA-compliant written-informed-consent flow (collecting only the data of users who explicitly opt in after the new policy is published), execute a separate biometric Data Processing Agreement with each customer that enables it, and notify users in advance through the email associated with their account.

Legacy biometric URLs (/biometric-policy and /face-verification) display a feature-removal notice and redirect, but no longer represent live functionality.

European Economic Area (EEA) Privacy Rights — GDPR

If you are located in the European Economic Area (EEA), you are protected by the General Data Protection Regulation (GDPR). QRCodeKey processes your personal data based on the following legal bases:

Legal Basis for Processing

  • Consent: You have given consent for processing your personal data for one or more specific purposes (e.g., location tracking, marketing emails).
  • Contract Performance: Processing is necessary for the performance of a contract with you (e.g., providing QR code services, processing payments).
  • Legitimate Interests: Processing is necessary for our legitimate interests (e.g., improving our service, preventing fraud), provided these interests do not override your fundamental rights and freedoms.
  • Legal Obligation: Processing is necessary for compliance with a legal obligation to which we are subject.

Your GDPR Rights

  • Right of Access (Art. 15): You have the right to obtain confirmation as to whether your personal data is being processed, and to access a copy of your personal data.
  • Right to Rectification (Art. 16): You have the right to request correction of inaccurate personal data without undue delay.
  • Right to Erasure / Right to be Forgotten (Art. 17): You have the right to request the deletion of your personal data when it is no longer necessary for the purpose it was collected, or you withdraw consent.
  • Right to Restriction of Processing (Art. 18): You have the right to request restriction of processing of your personal data under certain conditions.
  • Right to Data Portability (Art. 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
  • Right to Object (Art. 21): You have the right to object to processing of your personal data based on legitimate interests or direct marketing.
  • Right Not to be Subject to Automated Decision-Making (Art. 22): You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you. QRCodeKey does not engage in automated decision-making.

Data Transfers Outside the EEA

Your personal data is transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the legal mechanism for such transfers. We ensure that adequate safeguards are in place to protect your data in accordance with GDPR requirements.

Data Protection Contact

For GDPR-related inquiries, contact our data protection contact at Jal Technology LLC, 2501 Chatham Rd Suite N, Springfield, IL 62704, USA. Email: info@qrcodekey.com. Phone: (708) 690-0550.

Right to Lodge a Complaint

If you believe that your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.

To exercise any of these rights, use the self-service form at qrcodekey.com/privacy/delete-my-data or email info@qrcodekey.com. We will respond to your request without undue delay and in any event within one month as required by GDPR Article 12(3). If your request is complex or we receive a high volume of requests, we may extend this period by up to two additional months, and will notify you of the extension within the initial one-month period.

United Kingdom Privacy Rights — UK GDPR

If you are located in the United Kingdom, you are protected by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. You have the same rights as EEA residents described above, including the rights of access, rectification, erasure, restriction, data portability, objection, and protection against automated decision-making. Your data is transferred to the United States using appropriate safeguards including the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU Standard Contractual Clauses. You may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

Canadian Privacy Rights — PIPEDA

If you are a Canadian resident, the Personal Information Protection and Electronic Documents Act (PIPEDA) protects your personal information. Under PIPEDA, you have the following rights:

Consent

We collect, use, and disclose your personal information only with your knowledge and consent, except where permitted or required by law. You may withdraw your consent at any time, subject to legal or contractual restrictions.

Right of Access

You have the right to access the personal information we hold about you and to be informed of how it has been used and disclosed.

Right to Correction

You have the right to challenge the accuracy and completeness of your personal information and have it amended as appropriate.

Accountability

QRCodeKey is responsible for personal information in its possession or custody, including information transferred to third parties for processing.

Complaint Process

If you are not satisfied with our response to your privacy concern, you may file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca.

For residents of Quebec, the Act Respecting the Protection of Personal Information in the Private Sector (Quebec Law 25) provides additional protections, including the requirement for express consent for the collection and use of sensitive personal information.

Brazilian Privacy Rights — LGPD

If you are located in Brazil, the Lei Geral de Proteção de Dados (LGPD) provides you with specific rights regarding your personal data. Under the LGPD, you have the right to:

  • • Confirm the existence of processing of your personal data
  • • Access your personal data
  • • Correct incomplete, inaccurate, or outdated personal data
  • • Anonymize, block, or delete unnecessary or excessive personal data
  • • Request data portability to another service or product provider
  • • Delete personal data processed with your consent
  • • Obtain information about public and private entities with which we have shared your data
  • • Be informed about the possibility of denying consent and the consequences thereof
  • • Revoke your consent at any time

To exercise your LGPD rights, contact us at info@qrcodekey.com. You may also lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD).

Indian Privacy Rights — DPDP Act 2023

Status: India is a planned market. Service is not yet officially launched in India. This section becomes fully operative on the date of our official India launch. Until that date, the provisions below describe our committed approach for Indian users.

If you are located in India, the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act 2000, the Sensitive Personal Data or Information Rules 2011 ("SPDI Rules"), and the Consumer Protection (E-Commerce) Rules 2020 govern our handling of your personal data. We act as a "Data Fiduciary" under the DPDP Act with respect to Indian users.

Your DPDP rights as a Data Principal

  • Right to Information (Section 11): You may obtain a summary of personal data being processed and the activities undertaken with that data.
  • Right to Correction and Erasure (Section 12): You may have inaccurate or misleading personal data corrected, completed, or erased when it is no longer necessary for the original purpose.
  • Right to Grievance Redressal (Section 13): You may seek grievance redressal through the contact below; we will respond within the period prescribed by the DPDP Rules (and in any case within 30 days).
  • Right to Nominate (Section 14): You may nominate another individual to exercise your rights in the event of your death or incapacity.
  • Right to Withdraw Consent (Section 6(4)): You may withdraw consent at any time; processing prior to withdrawal remains lawful.
  • Right against unlawful processing: You may complain to the Data Protection Board of India ("DPB") if you believe your rights have been infringed.

Lawful basis for processing

We rely on your free, specific, informed, unconditional and unambiguous consent for processing personal data, in accordance with Section 6 of the DPDP Act. For certain limited "legitimate uses" (Section 7) — such as verifying identity, ensuring information security, or complying with judgments — we may rely on those bases.

Children and minors (Section 9)

The DPDP Act defines a "child" as any individual under 18 years of age. We do not knowingly process the personal data of any minor without verifiable parental or lawful guardian consent. We do not engage in tracking, behavioural monitoring, targeted advertising, or any processing likely to cause detriment to children. Educational institutions, coaching centres and similar organizations using QRCodeKey for student attendance are themselves responsible, as the Data Fiduciary for their students, for obtaining valid parental consent under Section 9.

Personal Data Breach

In the event of a personal data breach affecting Indian users, we will notify the Data Protection Board of India and affected Data Principals without undue delay, and in any case within 72 hours of becoming aware of the breach (or such other timeline as may be prescribed under the DPDP Rules), in accordance with Section 8(6).

Cross-border data transfer

Your personal data is transferred to and stored on servers in the United States. The Central Government may, by notification, restrict transfers to certain countries; we will comply with any such notifications. By providing your consent, you acknowledge and agree to this cross-border transfer.

Sensitive Personal Data — SPDI Rules 2011

Where we process Sensitive Personal Data or Information ("SPDI") — such as passwords, financial information, or health data — we comply with the reasonable security practices required by Rule 8 of the SPDI Rules. We do notprocess biometric information (face geometry, fingerprints, retina, iris, voice, or hand) — see the "No Biometric Identifiers" section above.

Grievance Officer (Section 8(10) DPDP Act)

Name: AG

Designation: Grievance Officer / Data Protection Contact

Email: info@qrcodekey.com

Phone (international): +1 (708) 690-0550

Postal address: Jal Technology LLC, 2501 Chatham Rd Suite N, Springfield, IL 62704, USA

Response timeline: Acknowledged within 48 hours; resolved within 30 days from the date of receipt of the grievance, in accordance with the DPDP Act and Rule 5(9) of the IT Intermediary Guidelines, 2021 (where applicable).

Consumer Protection (E-Commerce Rules) 2020

Once the service is officially launched in India, we will also comply with the disclosure obligations of the Consumer Protection (E-Commerce) Rules, 2020, including the display of seller details, refund policy, grievance redressal, country of origin where applicable, and a Nodal Officer / Grievance Officer for consumer complaints (combined with the Grievance Officer above).

SMS / TRAI compliance

All SMS messages sent to Indian mobile numbers will be delivered through DLT-registered headers and templates as required by the Telecom Commercial Communications Customer Preference Regulations, 2018 ("TCCCPR-2018") issued by the Telecom Regulatory Authority of India (TRAI). Promotional SMS will be sent only with your explicit opt-in. Transactional SMS (such as login OTPs and attendance confirmations) is exempt from DND scrubbing under TRAI rules.

Tax (GST)

Subscription fees charged to Indian customers will be inclusive of applicable Goods and Services Tax (presently 18%, HSN/SAC 998313 or 9985 as applicable). Our GSTIN, once registered, will be displayed on the Terms of Service and on each tax invoice issued to Indian customers.

To exercise any DPDP right or to file a complaint, please contact the Grievance Officer named above. You may also lodge a complaint with the Data Protection Board of India once it is established and operational.

Australian Privacy Rights — Privacy Act 1988

If you are located in Australia, the Privacy Act 1988 and the Australian Privacy Principles (APPs) protect your personal information. Under the APPs, you have the right to:

  • • Access your personal information held by us
  • • Request correction of inaccurate, out-of-date, incomplete, irrelevant, or misleading personal information
  • • Opt out of receiving direct marketing communications
  • • Make a complaint about a breach of the Australian Privacy Principles

We will respond to your request within a reasonable period. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

South African Privacy Rights — POPIA

If you are located in South Africa, the Protection of Personal Information Act (POPIA) provides you with the following rights:

  • • The right to be notified that personal information is being collected or that your personal information has been accessed or acquired by an unauthorized person
  • • The right to request access to your personal information
  • • The right to request correction or deletion of your personal information
  • • The right to object to the processing of your personal information
  • • The right not to have your personal information processed for purposes of direct marketing by means of unsolicited electronic communications
  • • The right to submit a complaint to the Information Regulator

To exercise your POPIA rights, contact us at info@qrcodekey.com. You may also lodge a complaint with the Information Regulator of South Africa at inforegulator.org.za.

Japanese Privacy Rights — APPI

If you are located in Japan, the Act on the Protection of Personal Information (APPI) provides you with the right to request disclosure, correction, suspension of use, or deletion of your personal information. When we transfer your personal data outside Japan, we ensure compliance with APPI cross-border transfer requirements. To exercise your rights, contact us at info@qrcodekey.com. You may also file a complaint with the Personal Information Protection Commission of Japan (PPC).

South Korean Privacy Rights — PIPA

If you are located in South Korea, the Personal Information Protection Act (PIPA) provides you with the right to access, correct, delete, and suspend processing of your personal information. We collect and process your personal data only with your consent or as permitted by PIPA. You have the right to withdraw consent at any time. To exercise your rights or file a complaint, contact us at info@qrcodekey.com. You may also contact the Personal Information Protection Commission (PIPC) of South Korea.

Singapore Privacy Rights — PDPA

If you are located in Singapore, the Personal Data Protection Act (PDPA) provides you with the right to access and correct your personal data, and to withdraw your consent for the collection, use, or disclosure of your personal data. We obtain your consent before collecting, using, or disclosing your personal data, and you may withdraw consent at any time with reasonable notice. To exercise your rights, contact us at info@qrcodekey.com. You may also lodge a complaint with the Personal Data Protection Commission (PDPC) of Singapore.

Chinese Privacy Rights — PIPL

If you are located in the People's Republic of China, the Personal Information Protection Law (PIPL) provides you with the right to know about and make decisions regarding the processing of your personal information. You have the right to access, copy, correct, and delete your personal information, and to withdraw your consent. You have the right to request an explanation of the processing rules. We process your personal information based on your consent or other lawful bases under PIPL. Cross-border transfer of your data is conducted in compliance with PIPL requirements. To exercise your rights, contact us at info@qrcodekey.com.

Thai Privacy Rights — PDPA

If you are located in Thailand, the Personal Data Protection Act B.E. 2562 (PDPA) provides you with the right to access, correct, delete, restrict, and port your personal data. You have the right to withdraw consent and to object to processing. We collect and process your personal data with your consent or on other lawful bases recognized by the PDPA. To exercise your rights, contact us at info@qrcodekey.com. You may also lodge a complaint with the Personal Data Protection Committee (PDPC) of Thailand.

Philippine Privacy Rights — Data Privacy Act

If you are located in the Philippines, Republic Act No. 10173 (Data Privacy Act of 2012) provides you with the right to be informed, the right to access, the right to object, the right to erasure and blocking, the right to rectification, the right to data portability, and the right to file a complaint. To exercise your rights, contact us at info@qrcodekey.com. You may also lodge a complaint with the National Privacy Commission (NPC) of the Philippines.

Indonesian Privacy Rights — PDP Law

If you are located in Indonesia, Law No. 27 of 2022 on Personal Data Protection (PDP Law) provides you with the right to obtain information about the processing of your personal data, the right to access, correct, update, and delete your personal data, the right to withdraw consent, the right to object to automated decision-making, and the right to data portability. To exercise your rights, contact us at info@qrcodekey.com.

Malaysian Privacy Rights — PDPA 2010

If you are located in Malaysia, the Personal Data Protection Act 2010 (PDPA) requires us to process your personal data with your consent and for a lawful purpose. You have the right to access, correct, and withdraw consent for the processing of your personal data. To exercise your rights, contact us at info@qrcodekey.com.

New Zealand Privacy Rights — Privacy Act 2020

If you are located in New Zealand, the Privacy Act 2020 and the Information Privacy Principles (IPPs) protect your personal information. You have the right to access and request correction of your personal information. We collect personal information only for lawful purposes directly related to our service. To exercise your rights, contact us at info@qrcodekey.com. You may also lodge a complaint with the Office of the Privacy Commissioner of New Zealand.

Swiss Privacy Rights — nFADP

If you are located in Switzerland, the new Federal Act on Data Protection (nFADP/revDSG) provides you with the right to access, rectify, and delete your personal data, and the right to data portability. Your data is transferred to the US using appropriate safeguards. You may lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC). To exercise your rights, contact us at info@qrcodekey.com.

Middle East Privacy Rights

United Arab Emirates — PDPL (Federal Decree-Law No. 45 of 2021)

If you are located in the UAE, you have the right to access, correct, and delete your personal data, and to restrict or object to processing. We process your data with your consent or on other lawful bases. You may lodge a complaint with the UAE Data Office.

Saudi Arabia — PDPL

If you are located in Saudi Arabia, the Personal Data Protection Law (PDPL) provides you with the right to be informed, access, correct, and request destruction of your personal data. We process your data with your consent. You may lodge a complaint with the Saudi Data and AI Authority (SDAIA).

Israel — Protection of Privacy Law

If you are located in Israel, the Protection of Privacy Law, 5741-1981 provides you with the right to access and correct your personal data held in databases. We process your data with your consent and in compliance with Israeli privacy regulations.

Turkey — KVKK (Law No. 6698)

If you are located in Turkey, the Law on Protection of Personal Data (KVKK) provides you with the right to learn whether your data is processed, request information, know the purpose of processing, request correction, request deletion, and object to processing. You may lodge a complaint with the Personal Data Protection Authority (KVKK).

Qatar — Data Protection Law (Law No. 13 of 2016)

If you are located in Qatar, you have the right to access, correct, and request deletion of your personal data. We process your data in compliance with Qatar's data protection regulations.

Bahrain — PDPL (Law No. 30 of 2018)

If you are located in Bahrain, the Personal Data Protection Law provides you with rights to access, correct, and delete your personal data. You may lodge a complaint with the Personal Data Protection Authority of Bahrain.

To exercise any rights under Middle East privacy laws, contact us at info@qrcodekey.com.

African Privacy Rights (Additional)

Nigeria — NDPR / Nigeria Data Protection Act 2023

If you are located in Nigeria, the Nigeria Data Protection Act 2023 provides you with the right to be informed about data processing, access your personal data, rectify inaccurate data, and request deletion. You may lodge a complaint with the Nigeria Data Protection Commission (NDPC).

Kenya — Data Protection Act 2019

If you are located in Kenya, the Data Protection Act 2019 provides you with the right to be informed, access, correct, delete, and object to the processing of your personal data. You may lodge a complaint with the Office of the Data Protection Commissioner of Kenya.

Egypt — Data Protection Law No. 151 of 2020

If you are located in Egypt, you have the right to access, correct, and delete your personal data, and to withdraw consent. You may lodge a complaint with the Data Protection Center of Egypt.

To exercise any rights under African privacy laws, contact us at info@qrcodekey.com.

Latin American Privacy Rights (Additional)

Mexico — LFPDPPP

If you are located in Mexico, the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) provides you with ARCO rights: Access, Rectification, Cancellation, and Opposition. We process your data with your consent and provide a privacy notice as required. You may lodge a complaint with the Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI).

Argentina — PDPL (Law No. 25.326)

If you are located in Argentina, you have the right to access, update, rectify, and suppress your personal data. You may lodge a complaint with the Agencia de Acceso a la Información Pública (AAIP).

Colombia — Law 1581 of 2012

If you are located in Colombia, you have the right to know, update, rectify, and delete your personal data, and to revoke your consent. You may lodge a complaint with the Superintendencia de Industria y Comercio (SIC).

Chile — Law No. 19.628

If you are located in Chile, you have the right to access, rectify, cancel, and object to the processing of your personal data. You may lodge a complaint with the relevant Chilean authorities.

To exercise any rights under Latin American privacy laws, contact us at info@qrcodekey.com.

Russian Privacy Rights — Federal Law No. 152-FZ

If you are located in Russia, Federal Law No. 152-FZ on Personal Data provides you with the right to access, correct, block, and destroy your personal data. We process your personal data with your consent. You have the right to withdraw consent at any time. To exercise your rights, contact us at info@qrcodekey.com. You may also lodge a complaint with Roskomnadzor (Federal Service for Supervision of Communications).

Additional US State Privacy Laws

In addition to California, Virginia, Colorado, and Connecticut privacy laws described above, residents of the following states have specific privacy rights under their respective state laws:

Texas (TDPSA)

Texas residents have the right to access, correct, delete, and obtain a copy of their personal data, and to opt out of targeted advertising, sale of personal data, and profiling.

Oregon (OCPA)

Oregon residents have the right to access, correct, delete, and obtain a copy of their personal data, and to opt out of targeted advertising, sale, and profiling.

Montana (MCDPA)

Montana residents have the right to access, correct, delete, and port their personal data, and to opt out of targeted advertising and sale of personal data.

Tennessee (TIPA), Iowa, Delaware, Nebraska, New Hampshire, Maryland

Residents of these states have consumer privacy rights including the right to access, correct, and delete personal data, and to opt out of targeted advertising and sale of personal data, under their respective state privacy laws.

To exercise any US state privacy rights, please contact us at info@qrcodekey.com or call (708) 690-0550.

Other Jurisdictions

If you are located in a jurisdiction not specifically mentioned above that has data protection or privacy laws, QRCodeKey is committed to respecting your privacy rights under your local laws. We will process your personal data in accordance with applicable data protection laws and provide you with the rights available to you under your local legislation. To exercise any privacy rights or for any privacy-related inquiries, please contact us at info@qrcodekey.com. We will respond to your request within the timeframe required by your local law, or within 30 days if no specific timeframe is prescribed.

Children's Privacy — 18+ Only

QRCodeKey is intended for adults only. The minimum registration age is 18 years globally. We do not knowingly create accounts for, or collect personal data from, anyone under the age of 18 — even where local law would technically permit a younger age (e.g. 13 under US COPPA or 13–16 under EU GDPR).

Why 18+: QRCodeKey processes location data, device fingerprints, and other sensitive personal information. We have chosen a single, strict 18+ minimum to align with the most protective standard worldwide and to comply by default with:

  • India — Digital Personal Data Protection Act 2023 (DPDP): Treats anyone under 18 as a "child" and prohibits behavioural monitoring or tracking-based advertising of children. A single 18+ policy avoids the need for verifiable parental consent under section 9 of the DPDP Act.
  • USA — COPPA (15 U.S.C. §§ 6501-6506): Restricts collection of personal information from children under 13 without verifiable parental consent.
  • EU/EEA — GDPR Article 8: Member-State digital-consent age (13–16); 18+ exceeds all of these.
  • United Kingdom — UK GDPR & the ICO's Age Appropriate Design Code: 13+ for online services; 18+ exceeds.
  • Brazil — LGPD & ECA: Child = under 12; minors under 18 require parental consent. 18+ avoids this.
  • South Korea (PIPA), China (PIPL), Thailand (PDPA): Various sub-18 thresholds; 18+ is uniformly above.
  • Australia — Privacy Act 1988 APP 3: Recommends 15+ minimum; 18+ exceeds.
  • All other jurisdictions: 18+ meets or exceeds the local minimum.

Verification: A valid date of birth is required at registration and is verified server-side. Accounts created with a date of birth indicating an age below 18 are rejected at the API layer. We do not rely on self-declared adulthood without a date of birth.

Use of QRCodeKey by minors (under 18):A parent or legal guardian may register their own adult account and add their minor child as a tracked member of a family or school group on the parent's account. In that scenario, the parent/guardian is the data controller for the child's information and is responsible for obtaining any consent required by their local law. Minors may not create their own accounts or log in independently. (QRCodeKey does not offer any biometric feature.)

If a minor account is discovered: If we learn that an account was created by, or contains data primarily about, a person under 18 without the involvement of a parent or legal guardian, we will (i) suspend the account immediately, (ii) delete the personal data we hold about that person, and (iii) refund any unused subscription period at our discretion. We will use commercially reasonable efforts to do this within thirty (30) days of becoming aware.

Reporting: If you are a parent, legal guardian, or any other person who believes a minor has registered or that we hold a child's personal data without parental consent, please contact us at info@qrcodekey.com with the username/email of the account in question and we will investigate promptly. You may also report concerns to the relevant data-protection authority in your country (for example, the FTC in the United States or the Data Protection Board of India).

QR Code Distribution & Owner Responsibility

When you create a QR code on QRCodeKey, you may print, sticker, or otherwise deploy that QR at one or many physical locations or on multiple items. QRCodeKey does not limit how many copies of a single QR you deploy and does not, by default, distinguish "originals" from copies. As a result, multiple scans of the same QR can occur simultaneously or near-simultaneously from different geographic locations, and each will be captured and notified to you independently. QRCodeKey treats every scan as legitimate and does not arbitrate which scan is "real" or which physical item it corresponds to. Interpreting multi-location or simultaneous scans, mapping each scan back to a specific physical instance, and resolving any related disputes (with finders, customers, employees, partners, or third parties) is the sole responsibility of the QR Owner. We collect, store, and surface scan data on a per-event basis; we do not perform anti-counterfeit, anti-duplication, or fraud detection on QR scans. If a QR Owner suspects unauthorized multi-location scanning, the QR Owner may delete the QR code at any time from their dashboard or via the AI assistant; deletion is permanent and irreversible and removes the QR identifier together with its full scan history, finder submissions, registered name / phone / email / address, photos, and any attached attendance or visitor records. The QR Owner accepts sole responsibility for the consequences of this irreversible deletion (loss of evidence, loss of recovery channel, broken attendance flow). See Sections 9B.7 (Deletion) and 9B (overall) of the Terms of Service for the full responsibility, indemnification, and best-practices framework.

Group invitations & member-provided QR codes. When a Group Admin invites participants to a Group on QRCodeKey, members typically join by sharing their own personal QR code with the Admin. Each member who shares a personal QR is responsible for the information attached to it and for the consequences of being scanned at the Group's pinned location for attendance / sign-in / visitor flows. For minors (under 18, or below the applicable local age — for example under 13 in the United States under COPPA, or below the applicable threshold under India's DPDP Act 2023 Section 9), the QR must be supplied with verifiable prior consent of the minor's parent or legal guardian. The parent / legal guardian — not the Admin, not the school, not the employer — is the data controller for that minor's data on QRCodeKey. Any Admin who adds a Member (especially a minor) without proper consent is solely responsible and indemnifies QRCodeKey for any resulting claim. See Terms Section 9C (Group Membership & Member-Provided QR Codes) for the full framework. Attendance disputes & proxy scans: if a Member QR is scanned at the Group's pinned location while the Member is actually elsewhere (or vice versa), or any other discrepancy arises between the scan log and the parties' account of what happened, QRCodeKey records the event factually but does not verify physical presence and is not the arbiter of the dispute. Resolution is between the Admin and the Member (or, for a minor, the parent / legal guardian); the Admin may also pursue any lawful remedy (internal action, payroll adjustment, civil claim, or referral to authorities). See Terms Section 9C.6 for the full attendance-dispute framework. Group data visibility & access routing: only the Group Admin can view, search, export, edit, or delete the Group's combined dataset (Member roster, scan and attendance logs, geofence, visitor sign-ins, shift / leave / holiday records, reports). The Admin is the data controller for the Group's combined dataset; QRCodeKey acts as a processor on the Admin's instructions. A Member who wants to access, correct, port, restrict, or delete their own Group data must first ask the Group Admin in writing; if the Admin does not respond within the legal deadline, the Member may escalate to QRCodeKey (info@qrcodekey.com) and ultimately to the relevant data-protection authority. Members always retain the absolute right to delete their personal QR under Terms Section 9B.7 at any time, which retroactively invalidates the QR within every Group. See Terms Section 9C.7 for the full data-visibility & access-routing framework. Group deletion by the Admin: a Group Admin may delete an entire Group at any time. Deletion is permanent and irreversible: the Group, its pinned location, the entire combined attendance / clock-in / clock-out / shift / leave / holiday / report log, the audit trail, and all visitor data inside the Group (visitor names, phones, emails, photos, signatures, purposes, sign-ins, sign-outs, host notifications) are wiped from our active datastore and cannot be recovered, restored, or re-issued — not even by QRCodeKey support and not even on receipt of a court order. The Admin accepts sole responsibility for downstream consequences (loss of evidence in pending disputes, loss of statutorily-retainable records, broken visitor sign-in at the physical premises, etc.). Members' personal QR codes are NOT deleted by a Group deletion — only their membership link to that particular Group is removed; the personal QRs continue to exist in each Member's own account. See Terms Section 9C.8 for the full Group-deletion framework. Visitor self-reported data & Admin verification: in the Visitor Management flow, the visitor enters their own name, phone, email, purpose, photo, and signature into the sign-in form. QRCodeKey does NOT verify this self-reported data. The visitor is responsible for the truthfulness of what they submit; the Group Admin is responsible for verifying the visitor's identity at the point of entry (ID check, photo comparison, callback, or whatever procedure their organization requires). QRCodeKey acts as a processor of the data the Admin chose to collect and the visitor chose to submit; we do not warrant truthfulness or fitness for purpose. See Terms Section 9C.9 for the full visitor-data framework and indemnification. Reports, export & Admin's data-retention responsibility:QRCodeKey gives the Group Admin built-in attendance and visitor reports in Daily, Weekly, and Monthly views, downloadable as printable PDF or spreadsheet (Excel / CSV) and printable from the dashboard. The Admin is solely responsible for downloading, printing, archiving, and securely storing — outside QRCodeKey — any records they (or their institution) are required to retain by law, regulation, contract, sector practice, or internal policy (labor / wage-hour, tax, payroll, education attendance registers, healthcare visitor logs, building-access logs, litigation-hold records, etc.). QRCodeKey does not guarantee perpetual storage: Group data can be deleted by the Admin under Section 9C.8, individual entries can be wiped by Members under Section 9B.7, and retention windows / archival / feature changes may affect long-term availability. Once an Admin downloads a report, the resulting file is entirely in the Admin's custody — the Admin is responsible for securing it, sharing it lawfully, redacting personal data where required (minor data under COPPA / DPDP Section 9, biometrics under BIPA, special-category data under GDPR Article 9), and deleting it at the end of its retention period. QRCodeKey has no control over downloaded copies and accepts no liability for their downstream handling, loss, theft, or misuse. See Terms Section 9C.10 for the full retention-and-export framework.

International Data Transfer Mechanisms

QRCodeKey is based in the United States. When we transfer personal data from outside the US to our servers, we use the following legal mechanisms to ensure the protection of your data:

  • EU-US Data Privacy Framework (DPF): Where applicable, we may rely on the EU-US Data Privacy Framework for transfers from the EEA to the US.
  • Standard Contractual Clauses (SCCs): For transfers from the EEA, we rely on SCCs approved by the European Commission as adopted under Commission Implementing Decision (EU) 2021/914.
  • UK International Data Transfer Agreement (IDTA): For transfers from the United Kingdom, we use the UK IDTA or the UK Addendum to the EU SCCs.
  • Swiss nFADP: For transfers from Switzerland, we use SCCs recognized by the Federal Data Protection and Information Commissioner (FDPIC).
  • Consent: Where required, we obtain your explicit consent for the transfer of your data outside your jurisdiction.
  • Adequacy Decisions: Where an adequacy decision exists between your country and the US, we rely on that decision.

Important notes for certain jurisdictions: Russia's Federal Law 152-FZ requires that personal data of Russian citizens be stored on servers within the Russian Federation (data localization). QRCodeKey's servers are located in the United States; therefore, Russian users should be aware that their data is processed and stored outside Russia. China's PIPL requires specific cross-border data transfer mechanisms (security assessment, certification, or standard contracts); QRCodeKey takes reasonable steps to comply with these requirements for Chinese users.

Regardless of the transfer mechanism, we ensure that your personal data receives an adequate level of protection in accordance with applicable data protection laws.

Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us at:

Company: QRCodeKey by Jal Technology LLC

Address: 2501 Chatham Rd Suite N, Springfield, IL 62704, USA

Contact Person: AG (Data Protection Contact)

Email: info@qrcodekey.com

Phone: (708) 690-0550

We will respond to your inquiry within 7 business days.

🤵
AG
AI Support — Online