01 Introduction & Business Status
Welcome to One QR ("we", "us", "our", or "Platform"), accessible online at oneqrscan.in. This Privacy Policy details our practices regarding the collection, processing, storage, and safeguarding of information when merchants register accounts and customers interact with our dynamic QR code services, digital business profiles, catalogues, and payment routing features.
Business Status Notice
The One QR platform is currently operated as an Indian proprietary commercial enterprise based in GTB Nagar, Mumbai – 400037, Maharashtra, India. The business is currently not formally incorporated as a Private Limited Company, Limited Liability Partnership (LLP), or public corporation. Whenever the business completes formal corporate incorporation, all applicable legal corporate identifiers will be updated transparently on this page.
By accessing our website, creating a merchant profile, or scanning a One QR code at any affiliated physical storefront, you acknowledge the terms of this Privacy Policy.
02 Merchant Information We Collect
When an entrepreneur, business owner, or enterprise manager registers on One QR to configure a dynamic QR code or subscription plan, we collect:
- Contact & Identity Details: Full name, authorized representative name, mobile phone number, and official email address.
- Business Profile Information: Registered trading name, brand name, store category (e.g., café, restaurant, salon, boutique, clinic), street address, city, state, pin code, and operating business hours.
- Billing & Payout Information: Billing address, plan selection, and payout UPI Virtual Payment Address (VPA) or bank account details required for routing verified customer settlement payouts.
- Account Credentials: Secure administrative login identifiers and authenticated session tokens.
03 Customer & End-User Information
One QR is engineered with a strict privacy-first principle for retail and dining guests. End customers who scan a physical One QR standee can browse menus, business profiles, and operational links completely anonymously without creating an account or downloading an app.
We only collect personal information from end customers when they intentionally choose to submit it through an interactive feature:
- Customer Inquiries & Feedback: Name, phone number, and message content when submitting a contact request or private store feedback.
- Loyalty & Rewards Program: Mobile phone number submitted with customer consent to record stamps, reward points, or visit counts.
- Table Bookings & Appointments: Guest name, phone number, party size, appointment date, time, and special requests routed directly to the merchant.
- Direct Orders & WhatsApp Routing: Selected items, customer preferences, and delivery notes passed to the merchant's official communication channel.
04 QR Scan & Interaction Information
When a smartphone camera scans a physical One QR code or clicks a branded short link, our application servers log operational diagnostic data:
- Timestamp of scan (date and time).
- Unique QR code identifier and assigned merchant outlet token.
- Feature modules accessed (e.g., Digital Menu, Split Payment, Google Maps redirect, Instagram, AI concierge).
- Aggregated scan velocity metrics used to calculate real-time daily scan limits per subscription tier.
This scanning data is processed in aggregate and is not linked to personal identifiable information unless the customer explicitly submits their details during the interaction.
05 Technical, Device & IP Data
To ensure optimal mobile rendering, load speed under 1.2 seconds, and platform integrity, our servers record standard web telemetry:
- Device & Browser Properties: Browser type, operating system version (iOS, Android, Windows, macOS), viewport dimensions, device model, and preferred interface language.
- Internet Protocol (IP) Address: Collected in server security logs to prevent DDoS attacks, mitigate automated bot abuse, enforce rate limits, and calculate general regional traffic distribution.
- Referral Uniform Resource Locators (URLs): The referring link or application that routed the user to the landing page.
06 Cookies & Local Storage
One QR avoids intrusive third-party behavioral tracking cookies, cross-site trackers, or commercial advertising pixels. We utilize minimal first-party browser storage strictly for essential operational functionality:
- Visual Theme Preference: A lightweight key in
localStorageorsessionStoragestoring the user's Day Mode or Night Mode preference. - Temporary Session State: Ephemeral session tokens allowing merchants to remain authenticated inside their control panel.
- Cart & Table Selections: Temporary client-side memory retaining active menu item selections or split bill breakdowns during a visit.
Users can clear or block cookies and local storage keys via standard browser settings without impacting their ability to view static menus or business hours.
07 Operational Feature Data
Our platform includes diverse modular micro-services configured by merchants. Data handling for each module is outlined below:
- Catalogue & Digital Menu: Category preferences, item search queries, and dietary filters applied during the browsing session.
- Customer Reviews & Testimonials: Star ratings, written feedback, and submission timestamps. If the merchant enables a Google Reviews link, the user is redirected to Google Maps where Google's independent privacy policy applies.
- Loyalty & Rewards Accrual: Visit tallies, stamp history, and redemption events linked to the customer's phone number.
- Merchant CRM (Customer Relationship Management): Contact directories curated by the merchant for their own recurring customers. Merchants are solely responsible for ensuring they have lawful customer consent to store customer notes in their dashboard.
- WhatsApp & Communication Integrations: When a customer clicks a WhatsApp button, One QR generates a standard
https://wa.me/direct URI. All messages exchanged in WhatsApp are end-to-end encrypted by WhatsApp; One QR does not intercept, read, or store customer chat messages. - Marketing & Announcements: Promotional broadcast banners or coupon notices configured by merchants.
08 Payment & Transaction Processing via Cashfree
Zero Storage of Sensitive Payment Credentials
One QR does NOT collect, capture, store, or process sensitive payment credentials such as credit card numbers, debit card numbers, Card Verification Values (CVV), net banking passwords, or UPI Mobile Personal Identification Numbers (MPIN).
All online payment processing for merchant subscriptions and split payment transactions is handled exclusively by Cashfree (Cashfree Payments India Private Limited), an authorized payment aggregator regulated by the Reserve Bank of India (RBI).
When a transaction occurs:
- The payment workflow operates directly on Cashfree's secure payment gateway or is handed off to the customer's installed UPI app (e.g., PhonePe, Google Pay, Paytm, BHIM, CRED).
- One QR only receives non-sensitive transaction confirmation metadata from Cashfree webhooks, including: Cashfree order ID, transaction reference number, payment status (SUCCESS / PENDING / FAILED), amount paid, currency (INR), payment method category (UPI, Netbanking, Card), and settlement timestamp.
- This metadata is recorded solely for account reconciliation, subscription activation, merchant ledger display, and tax compliance.
09 How We Use Collected Data
One QR utilizes collected information strictly for legitimate commercial and operational purposes:
- Delivering responsive, high-speed digital business profile landing pages.
- Generating, updating, and monitoring physical and digital dynamic QR code standees.
- Providing merchant dashboard analytics (e.g., total scans, popular menu items, peak hours).
- Processing monthly merchant subscriptions and enforcing plan daily scan limits.
- Providing technical customer support, troubleshooting, and resolving hardware or software issues.
- Detecting, preventing, and addressing fraud, network attacks, or abusive usage.
- Complying with applicable Indian statutory, tax, accounting, and legal requirements.
We do not sell, rent, or trade merchant or customer personal information to third-party data brokers or marketing agencies.
10 Third-Party Service Providers
We collaborate with carefully selected infrastructure and service partners who process data strictly under confidentiality agreements:
- Payment Processing: Cashfree Payments India Pvt. Ltd. (payment gateway and settlement infrastructure).
- Cloud Hosting & Content Delivery: Secure cloud servers and Content Delivery Networks (CDN) providing web hosting and database redundancy.
- SMS & Notification Gateways: Telecommunication partners for merchant account OTP verification and system notifications.
- Mapping & Routing: Google Maps platform for storefront navigation links.
11 Data Security & Storage Safeguards
We implement industry-standard administrative, electronic, and physical security measures to protect merchant and user data against unauthorized access, loss, alteration, or disclosure.
- All web traffic across
oneqrscan.inis encrypted in transit using Transport Layer Security (TLS/HTTPS). - Server access is restricted via multi-factor authentication, key-based SSH permissions, and role-based operational segregation.
- Regular operational database backups and firewall configurations mitigate systemic data loss.
Security Disclaimer
While we maintain rigorous security protocols to protect your information, no electronic transmission over the internet or cloud storage architecture can be guaranteed 100% impenetrable. We do not make false claims of unverified external security accreditations or proprietary ISO/SOC certifications that have not been formally audited.
12 Data Retention & Purging
We retain merchant profile information for the duration of the merchant's active subscription and account lifecycle. When an account is terminated:
- Dynamic QR code routing is deactivated immediately.
- Merchant catalogue data, store profiles, and CRM directories are retained for a 30-day grace period to allow data export or reactivation, after which they are permanently deleted or anonymized.
- Financial transaction records, invoices, and payment logs are retained for statutory retention periods as mandated by Indian accounting and taxation laws.
- Temporary customer interaction telemetry (e.g., ephemeral scan session logs) is routinely purged or aggregated into non-personal analytical summaries.
13 User Privacy Rights & Deletion Requests
Under applicable Indian data protection principles, users and merchants possess rights regarding their personal information:
- Right of Access & Review: You may request a summary of the personal data held about you on our platform.
- Right to Rectification: You may request correction or updating of any inaccurate, outdated, or incomplete information.
- Right to Deletion: You may request the deletion of your personal contact data or merchant profile, subject to statutory retention obligations.
To exercise any of these rights, email us at officialoneqr@gmail.com with the subject line "Privacy Rights Request". We will process verified requests within 30 business days.
14 Age Requirement & Minors (18+ Policy)
One QR is strictly intended for individuals who are at least eighteen (18) years of age. We do not knowingly solicit, collect, or process personal data from children or individuals under the age of 18. If a parent or guardian becomes aware that a minor has provided us with personal information without parental consent, please contact us immediately, and we will promptly take steps to delete such records from our databases.
15 Changes to this Privacy Policy
We may revise this Privacy Policy periodically to reflect technological enhancements, operational changes, new regulatory frameworks, or changes in business structure. Whenever changes occur, the revised document will be published on this page with an updated "Last Updated" date at the top. Merchants with active subscriptions will be notified of material changes via email or dashboard alert.
16 Privacy Grievance & Contact Information
If you have any questions, concerns, complaints, or grievance requests concerning this Privacy Policy or our data protection practices, please contact our designated privacy desk:
One QR Privacy & Grievance Desk
Business Name: One QR
Website: oneqrscan.in
Address: GTB Nagar, Mumbai – 400037, Maharashtra, India
Official Email: officialoneqr@gmail.com
Helpline Phone: +91 90820 09379
Operating Hours: Monday – Saturday, 10:00 AM – 6:30 PM IST