QRCODEAPI

Last Updated: 15-08-2026 5:30:00 PM

Privacy Policy

Last updated: 15 August 2026

This Privacy Policy explains how QRCODEAPI ("QRCodeAPI", "we", "us") collects, uses, stores, and protects information when you use qrcodeapi.in and our related APIs, SDKs, dashboards, and services. Registered address: Haryana, India.

1. Our role

QRCodeAPI operates software infrastructure for dynamic QR generation, merchant integrations, APIs, SDKs, callbacks, and merchant-side order/status workflows. We are not a payment gateway, payment processor, bank, PSP, payment aggregator, or settlement provider, and we do not receive or hold customer funds.

We do not request or intentionally process end-customer payment credentials such as UPI PINs, card CVVs, banking passwords, or banking-app OTPs through our Service.

2. Information we collect

2.1 Account and profile information

  • Name, email address, phone number, password or password hash, business information, and other information you provide when creating or managing an account.
  • Subscription, plan, billing, usage, and account administration records.

2.2 Cookies, device, and technical logs

  • Essential session and security cookies used for authentication and account security.
  • IP address, user agent, timestamps, request information, device or browser information where available, and diagnostic logs used for security, abuse prevention, troubleshooting, and service reliability.

2.3 Merchant QR and payment-provider configuration information

  • Merchant-provided configuration such as QR information, VPA/UPI ID, MID, merchant/store identifiers, provider name, and other configuration values required to provide the requested QR/API functionality.
  • Where technically required for a connected merchant workflow, provider-specific authentication or session information, including tokens or credentials supplied by the merchant, may be stored or processed. Such information is used only for the configured Service functionality and should not include end-customer payment credentials.
  • Where we require explicit authorization before accepting a third-party QR or merchant configuration, we may record the consent version, acceptance timestamp, account or merchant identifier, provider, and related audit information.
  • Optional messaging or notification identifiers that you explicitly connect, such as WhatsApp or Telegram identifiers, may be processed to provide the notification features you enable.

2.4 QR, order, callback, and status information

  • QR identifiers, order identifiers, amounts or order values supplied by you, merchant-side status fields such as pending/success/failed where applicable, callback or redirect configuration, reference information, timestamps, and related technical metadata.
  • We use this information to provide the QR, API, callback, reporting, and merchant-side status functionality you configure.

2.5 Information we do not intentionally collect

  • End-customer UPI PINs, card numbers, CVV/security codes, banking passwords, or banking-app OTPs.
  • We do not intentionally collect or request credentials that are intended exclusively for end-customer payment authorization.
  • We do not custody customer funds or settle customer payments to merchants on behalf of a payment provider.

3. How we use information

  • To provide APIs, SDKs, dashboards, QR generation, merchant integrations, callbacks, and merchant-side order/status functionality.
  • To authenticate users and maintain account security.
  • To record and enforce required consent and authorization controls.
  • To prevent fraud, unauthorized use, abuse, security incidents, and violations of our Acceptable Use Policy.
  • To provide technical support, troubleshoot issues, monitor reliability, and improve the Service.
  • To administer subscriptions, API usage, billing, and service communications.
  • To comply with applicable law, lawful requests, and legal obligations.

4. Sharing and service providers

We may share or disclose information with infrastructure, hosting, database, analytics, security, communications, and other service providers that process information on our behalf and as necessary to provide the Service. We may also process or transmit merchant configuration information to or through connected third-party merchant/payment-provider systems when required to perform functionality that you explicitly configure or request.

We may disclose information where required by applicable law, valid legal process, or to protect the security, rights, property, or users of the Service. We do not sell personal data.

5. Data retention

We retain information for as long as reasonably necessary to provide the Service, maintain security, administer accounts, resolve disputes, maintain required business records, enforce agreements, and comply with applicable legal obligations.

Different categories of information may be retained for different periods. In particular, consent and authorization records may be retained for audit, security, dispute-resolution, compliance, and legal purposes even after a particular QR configuration or account is no longer active, where permitted or required by applicable law.

6. Security

We use reasonable technical and organisational measures appropriate to the nature of the information we process, including encryption in transit where supported, access controls, authentication controls, logging, and security monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Your choices and requests

You may update available account information through the dashboard or contact us at [email protected] for privacy-related requests or assistance. Requests may be subject to identity verification and lawful retention requirements.

You may also use our account deletion flow where available. Deletion of an account does not necessarily require immediate deletion of information that we are legally required or reasonably entitled to retain for security, fraud prevention, dispute resolution, accounting, or compliance purposes.

8. Children

The Service is not directed to children under 18, and we do not knowingly provide accounts to children where prohibited by applicable law.

9. Changes

We may update this Privacy Policy by posting a revised version and updating the "Last updated" date. Where required by applicable law, we may provide additional notice.

10. Contact

Privacy questions and requests can be sent to [email protected] or through our Contact page.

See also our Terms & Conditions, Refund Policy, and Acceptable Use Policy.