Privacy Policy
Effective date: July 29, 2026. This Privacy Policy explains what information OriginQR collects, how we use it, and the choices you have.
1. Information We Collect
- Account information: your name, email address, and password (handled via Firebase Authentication) when you sign up.
- Business/brand information: your brand name and related business details you provide during onboarding.
- Product data: GTINs, lot/batch codes, expiration dates, destination URLs, and recall-status flags you enter (“Customer Data”) — see our Terms of Service for how this is used to provide the Service.
- Payment information: subscription payments are processed by Stripe; OriginQR does not receive or store your full card number.
- Usage data: log data such as IP address, browser type, pages visited, and timestamps, collected automatically to operate and improve the Service.
- Support/communications data: information you share with us via email or the in-app chat widget when requesting support.
2. How We Use Information
We use the information above to provide, maintain, and secure the Service; process payments and manage subscriptions; respond to support requests; send you Service-related notices (such as billing or security notices); and improve and develop the Service. We do not sell your personal information.
3. How We Share Information
We share information with the service providers (“sub-processors”) that help us operate OriginQR, including:
- Google Firebase / Google Cloud Platform — hosting, database, authentication, and serverless backend functions
- Stripe — payment processing and subscription billing
- Netlify — website hosting and content delivery
- need2.chat — an in-app chat widget on some pages, which may process messages you send through it
We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets (with notice to you where required).
4. Data Retention
We retain Customer Data and account information for as long as your account is active, and for a reasonable period after cancellation in case you wish to reactivate or export data, after which we delete or anonymize it, unless a longer retention period is required by law.
5. Data Security
We use reasonable administrative, technical, and physical safeguards to protect information, including relying on our infrastructure providers’ security practices (e.g., Google Cloud, Stripe). No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
6. Your Choices and Rights
You can access, correct, or delete most account and Customer Data directly from your dashboard. To request a full export or deletion of your account and associated data, contact originqr.app@gmail.com. Depending on where you live, you may have additional rights under laws such as the California Consumer Privacy Act (CCPA) or the EU/UK GDPR; contact us to exercise them.
7. Cookies and Similar Technologies
The Service uses a minimal set of cookies and similar technologies necessary for authentication and checkout (including cookies set by Stripe during payment) and, on pages with our chat widget, cookies set by that provider. We do not use third-party advertising trackers.
8. Children’s Privacy
The Service is intended for business use and is not directed to children. We do not knowingly collect personal information from children.
9. International Users
Our infrastructure providers operate data centers in the United States and elsewhere. By using the Service, you consent to your information being processed in the United States and other countries where our sub-processors operate.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version here with a new effective date, and, for material changes, provide reasonable additional notice.
11. Contact
Questions about this Privacy Policy? Contact us at originqr.app@gmail.com.
See also our Terms of Service.