EliteQR

Privacy Policy

Last updated 22 August 2026 · Effective 22 August 2026 · Operated by Agam Sharma, sole proprietor, trading as Elite QR, Mehsana, Gujarat, India

The short version. If you create an account we store your Google profile basics and the QR codes you make. When someone scans one of your codes we record the scan — including the scanner's IP address, which we use to show an approximate city and a device count. Opening a restaurant menu records less: a city, a table number and a time, with no IP address, deleted after 90 days. Opening an ID card records nothing at all — but the card itself holds somebody's details, and whoever uploaded it decided what goes on it. We do not sell anything to anyone. You can delete it all yourself — codes from Settings, card batches from Bulk Studio — or by emailing us.

1. Who we are

Elite QR ("we", "us") is a QR code platform operated by Agam Sharma, a sole proprietor based in India, at Swastik Homes, Mehsana, Gujarat 384002, India. Agam Sharma is the data fiduciary for the purposes of India's Digital Personal Data Protection Act, 2023.

For any privacy question, or to exercise the rights in section 8, contact customer@eliteqr.in.

2. What we collect from account holders

You sign in with Google. We never see or store your Google password.

DataWhy
Email address, display name, profile photo URLTo identify your account and show who is signed in.
The QR codes you create — title, destination, design, and any routing rules such as a geo-fence location or a time cutoffThey are the product. Without them there is nothing to route.
Files you upload (PDFs, images, 3D models)So a hosted-file code has something to serve.
Your plan, its expiry, and how many codes you have made this monthTo apply the free-tier allowance and to know whether you are a subscriber.
Card batches — the rows of a spreadsheet you upload to make ID or member cards, which usually contain other people's names, ID numbers and photographsTo render the page each card opens. See section 3 for what a cardholder sees and section 9 if any of them are under 18.

If you upload a card batch you are responsible for the people in it. You decide what goes on the card and you must have a lawful basis for putting it there — consent, employment, or whatever applies to your organisation. We do not check that you do, and we have no relationship with the people named. Only upload details you are entitled to publish to anyone holding the card.

Our lawful basis is the performance of our contract with you — these terms — except for the analytics described in section 4, which rests on consent you can withdraw by blocking those cookies.

Vault PINs are stored separately from the code they protect and are never returned to a browser. They are not hashed — we need the original value to check a PIN — so treat a Vault PIN as a convenience lock, not as encryption, and do not reuse a PIN from anywhere else.

3. What we collect from people who scan a code

This section is about visitors, who usually have no account and no relationship with us. When a dynamic QR code or a hub page is opened we record:

We do not use cookies to track scanners across sites, and we do not build advertising profiles.

What the code's owner sees: the city, country, device, browser, time, and a count of unique devices. They do not see IP addresses. The IP is used to compute that count on our server and is never sent to the owner's browser or included in any export.

If a code has a geo-fence, your browser will ask permission for your precise location. That check happens entirely in your browser; the result is not sent to us or stored. Declining means the code will not open.

Scanning a restaurant's table code

Some venues use Elite QR to publish a menu, with a separate code printed for each table. Opening one of those records a menu view, which is a smaller record than a scan:

We do not store your IP address for a menu view. A menu view says that somebody was in a particular restaurant at a particular time, which is more revealing than a link being opened, so we keep less rather than more. It is used to tell the venue how many people looked at the menu.

Menu views are deleted automatically after 90 days.

The venue writes its own menu, prices and descriptions. Elite QR hosts that content and does not sell food, take payment for it, or check that it is accurate — ordering, where a venue has it switched on, is passed to the venue's own staff.

Scanning an ID card or member card

An organisation — a school, an employer, an event — can print a card for each person, where scanning the code opens a page showing that person's details. If your name is on one of those cards, this section is about you, and you have rights here even though you have no account with us.

The organisation decides what goes on the card, not us. They upload a spreadsheet and choose which columns to show. Typically that is a name, a class or department, an ID number, and sometimes a photograph. We do not choose those fields, we do not verify them, and we cannot correct them — the organisation can. In the language of the Digital Personal Data Protection Act, they are the data fiduciary for the contents of the card and we process it on their instructions.

What the link protects. Each card's address contains a long random code. It is not a number you can count up from, and holding one card tells you nothing about anybody else's — you cannot get from one person's card to another's by editing the address. The pages are excluded from search engines and produce no preview image in chat apps, so a card cannot be found by searching for somebody's name and does not display their face when the link is pasted into a group.

But a card link is a key, and anyone holding it can open the page. There is no password. If you photograph, forward or post the code, whoever receives it can see those details. That is the trade a printed card makes: it has to work for anyone the cardholder shows it to.

Opening a card records nothing. No IP address, no city, no device, no count, no timestamp. Unlike a scan or a menu view, we store nothing at all when a card page is opened — a record of when a named person's card was scanned, and by how many people, is not something we want to be holding.

4. Analytics and payments

Google Analytics runs on our website and sets its own cookies. Note that it also runs on the scan and hub pages — so it loads for people who merely scanned someone's code and never created an account. See Google's privacy policy. You can prevent it by blocking third-party scripts or cookies in your browser; the codes will still resolve normally.

Razorpay processes all payments. Card numbers, UPI IDs and bank details are entered on Razorpay's own checkout and never reach our servers. We store only the order id, the amount, the plan bought, and whether it succeeded. See Razorpay's privacy policy.

5. Who else your data reaches

We do not sell personal data, and we do not share it for anyone else's advertising. We share it only with the services that make the product work:

We will also disclose data where the law requires it.

6. Where it is stored

Our infrastructure providers operate globally and your data may be processed outside India, including in the United States and the European Union, under those providers' own safeguards.

7. How long we keep it

8. Your rights

Under India's Digital Personal Data Protection Act, 2023 — and comparable rights elsewhere — you may ask us to show you what we hold, correct it, delete it, or withdraw consent. Write to customer@eliteqr.in and we will respond within 30 days.

Most of it you can do yourself: your codes and their entire scan history are deleted from the Settings panel, immediately and permanently, and your card batches from Bulk Studio. Clearing everything covers both.

If you scanned someone's code and want the record removed, email us with roughly when and where it happened. We will find it and delete it; you do not need an account to ask.

If your details are on somebody's card — a student ID, a staff badge, an event pass — you can write to us at customer@eliteqr.in and we will take that card offline. Send the link or a photograph of the card so we can find it. You do not need an account and you do not need the organisation's permission to ask us. We will tell them the card was removed, because their cards will stop working and they need to know why, but we will not wait for their agreement first. To have the details corrected rather than removed, ask the organisation — they wrote them and only they can change them.

If you are not satisfied with our response, escalate to our Grievance Officer (section 12). If you are still not satisfied you may complain to the Data Protection Board of India.

9. Children

Elite QR is not intended to be used by anyone under 18. We do not knowingly let a child create an account, and if you believe a child has given us data directly, tell us and we will remove it.

Card batches are the exception, and we would rather say so plainly than leave it implied. A school that makes student ID cards is uploading children's personal data to us. We do not collect it from the child and we have no relationship with them; the school does, and the school decides what goes on the card. But the data is here, on our servers, and pretending otherwise would be dishonest.

If you are a school, a coaching centre, or anyone else making cards for people under 18: India's Digital Personal Data Protection Act, 2023 requires verifiable parental consent before a child's personal data is processed, and forbids tracking or behavioural advertising directed at children. Obtaining that consent is your responsibility, not ours — we have no way to ask a parent and no way to check that you did. It also forbids processing that is likely to cause a detrimental effect on a child, which is worth weighing before you put a photograph and a full name on something a stranger can scan.

A parent or guardian can ask us directly. Write to customer@eliteqr.in with the card link or a photograph of the card. You do not need an account, you do not need to go through the school, and we will remove the card without asking them first.

10. Security, stated plainly

Payment details never touch our servers. Vault PINs and their destinations are held where no other visitor can read them, and PIN attempts are rate-limited. Access to your own codes requires your Google sign-in.

No system is perfectly secure, and we will not pretend otherwise. If we discover a breach affecting your data we will notify you and the Data Protection Board without undue delay.

11. Changes

If we change this policy we will update the date above. Material changes will be announced in the app before they take effect.

12. Contact

Agam Sharma (sole proprietor), trading as Elite QR
Swastik Homes, Mehsana, Gujarat 384002, India
Email customer@eliteqr.in

Grievance Officer: Agam Sharma — customer@eliteqr.in. Response within 30 days of receipt.