Legal

Privacy Policy

Effective:1 January 2025  · Last Updated:1 January 2025  ·  Operated by [YOUR LEGAL ENTITY NAME]
Table of Contents
  1. Who We Are
  2. What We Collect
  3. How We Use It
  4. Your Phone Number — Special Protection
  5. Payments & PhonePe
  6. Data Sharing
  7. Data Retention
  8. Security
  9. Your Rights (DPDP Act 2023)
  10. Cookies
  11. Children's Privacy
  12. Policy Changes
  13. Contact & Grievance Officer

01Who We Are

uLinkQR ("we", "us", "our") is a QR-based lost-and-found alert service operated by [YOUR LEGAL ENTITY NAME], registered office at [FULL ADDRESS, CITY, STATE, PIN — INDIA].

Privacy contact: privacy@ulinkqr.com

02What We Collect

  • Phone number — OTP login and push delivery only. Stored encrypted. Never exposed in API responses.
  • First name — Shown to the person who scans your tag.
  • Tag details — Category, tag ID, optional description.
  • Alert data — Timestamp, message from reporter, location text (if typed).
  • Device token — FCM push token. OS type for compatibility.
  • Anonymised usage data — Feature interactions to improve the service.

📵 We do NOT collect: GPS location, contacts, photos, or anything not listed above.

03How We Use It

  • Send instant push notifications when your QR is scanned
  • Enable masked calling between owner and reporter
  • Manage your account and subscription status
  • Send service updates (not marketing unless you opt in)
  • Detect fraud, spam, and platform abuse
  • Meet legal obligations under IT Act 2000 and DPDP Act 2023

04Your Phone Number — Special Protection

Your phone number is NEVER shared with anyone who scans your QR. It is encrypted at rest (AES-256) and in transit (TLS 1.3). It never appears in any API response to a scanner. Masked calls route through our WebRTC bridge — neither party's number is revealed to the other.

Any breach of this is treated as a critical security incident subject to immediate remediation and CERT-In disclosure.

05Payments & PhonePe

Processed via PhonePe Payment Gateway (PhonePe Private Limited, RBI-regulated). When you pay:

  • You're redirected to PhonePe's secure page or UPI app
  • We receive only: transaction ID + success/failure. Never your card, UPI ID, or bank details.
  • PhonePe's privacy policy governs their data handling
  • We store: plan type, start date, transaction reference — for billing and support

06Data Sharing

We do not sell, rent, or trade your data. We share only with:

  • PhonePe — payment processing
  • Firebase/Google — push notifications (FCM) and OTP
  • Cloud host — servers in India / compliant regions
  • Law enforcement — only on valid court order under IT Act Section 69

07Data Retention

  • Active accounts — retained while account is active
  • Alert history — 90 days, then permanently deleted
  • Deleted accounts — all personal data erased within 30 days
  • Payment records — 7 years (Indian GST/tax law)

08Security

  • AES-256 encryption at rest, TLS 1.3 in transit
  • OTP-only login — no passwords stored
  • Rate limiting on all scan endpoints
  • Regular security audits and penetration testing
  • Breach disclosure within 72 hours per CERT-In mandate

09Your Rights (DPDP Act 2023)

  • Access — Request a copy of your data
  • Correction — Fix inaccurate data
  • Erasure — Delete your account and all personal data
  • Grievance — Complain to our Grievance Officer
  • Nomination — Appoint someone to act on your behalf

To exercise rights: privacy@ulinkqr.com or use Settings → Delete Account. We respond within 30 days.

🏛️ Grievance Officer (IT Act Rule 5(9) & DPDP Act):
[OFFICER FULL NAME] · [YOUR LEGAL ENTITY] · grievance@ulinkqr.com · Responds within 30 days

10Cookies

  • Session cookie — keeps you logged in (essential)
  • Analytics — anonymised usage only, no cross-site tracking, no ad networks

11Children's Privacy

uLinkQR is not for users under 18. If a minor has registered, email privacy@ulinkqr.com and we'll delete the account within 48 hours.

12Policy Changes

Material changes notified via push/email at least 14 days before taking effect. Continued use = acceptance.

13Contact & Grievance Officer