Privacy Policy
Effective Date: September 7, 2026 • Compliant with Indian DPDP Act 2023 & Global Privacy Principles
01Introduction & Core Privacy Commitment
Welcome to Alpha QR, operated by AlphaPrime (founded and operated by Santhosh Ravi). We are dedicated to respecting your privacy, minimizing data retention, and providing complete transparency regarding how information is handled across our dynamic QR code platform.
This Privacy Policy details how we collect, process, protect, and purge personal data when you visit our website, interact with dynamic landing cards, or operate creator accounts.
02Strict "Zero Data Monetization" Pledge
03Information We Collect
We apply strict data minimization principles, collecting only what is functionally essential to deliver our 9 dynamic engines:
- Account Identity Data:Name, email address, and profile picture provided securely via Google OAuth 2.0 when you register or sign in. We never access your Google password or private drive files.
- Payment & Billing Data:Subscription order references and transaction IDs processed securely via Razorpay (PCI-DSS Level 1 compliant). We do NOT capture, view, or store raw debit/credit card numbers or CVVs on our servers.
- Scan Telemetry & Geo-Resolution:When an end-user scans a dynamic code, the edge router resolves city/country-level location, device operating system (iOS, Android, Desktop), and browser user-agent. Raw IP addresses are hashed with server salts or discarded immediately after geo-lookup to prevent individual tracking.
- User-Generated Content (UGC):Custom URLs, uploaded food menu dishes, vCard contact fields, appointment booking slots, review ratings, and opinion poll entries configured by account holders.
04How We Use Your Data
- Facilitating instant dynamic edge redirections and rendering micro-app landing cards (Food menus, vCards, booking desks).
- Compiling aggregated, anonymized scan analytics (total scans, unique devices, geographic distribution) inside creator dashboards.
- Processing 1-time UPI and card upgrades through Razorpay with zero auto-debit mandates.
- Detecting malware, phishing links, and deceptive URLs via automated security validators.
- Sending essential account notifications, order receipts, emergency domain failover and migration advisories, and customer support responses to your registered Gmail address.
05Cookies & Local Storage Usage
Alpha QR uses minimal, essential functional cookies and browser storage keys:
06Account Deletion & Data Purge Rights (DPDP Act Compliance)
In full accordance with the Indian Digital Personal Data Protection (DPDP) Act, 2023, you hold absolute authority over your personal data:
- Instant Data Clear: You can purge all active QR codes, associated scan logs, and comments with a single click from your account profile settings.
- Self-Service Storage Manager & Media Purge: Account holders maintain direct real-time access to a granular Storage Manager in their dashboard. You can inspect attached binary assets (PDFs, menus, logos, event images) and permanently delete individual heavy files at will to instantly release your cloud storage allocation without deleting the underlying QR code.
- Automated Free Tier Dormancy Cleanup: In accordance with technical capacity preservation, Free Tier dynamic QR codes showing zero scan events AND zero creator modifications for fourteen (14) consecutive calendar days are automatically marked dormant and recycled. Short-lived media (e.g., 24-hour GIF assets) are automatically destroyed on a rolling 24-hour schedule. Paid accounts (Pro Monthly & Pro Yearly) are exempt from dormancy cleanup.
- Immutable Financial & Statutory Accounting Shield: In strict compliance with Indian taxation, GST laws, and corporate accounting requirements, billing logs, Razorpay payment reference IDs, and transaction histories are permanently locked and cannot be deleted through self-service storage tools.
- Complete Account Deletion: You can permanently delete your account and all associated records by utilizing the profile deletion tool or emailing our data desk. Once executed, all dynamic routing records are purged from our primary database.
- QR Code Transfer & Rights Extinguishment: Creators can securely transfer dynamic QR code ownership to another registered user account without losing scan history or reprinting. Upon acceptance, all recovery and editing rights transfer exclusively to the recipient, and the previous owner's recovery privileges are permanently extinguished.
- SafeGuard™ Disaster Recovery Vault: Every generated 2D QR and 1D Barcode payload is cryptographically fingerprinted with an HMAC-SHA256 signature and preserved in an isolated SafeGuard disaster vault bound strictly to the creator's authenticated Gmail address. This prevents physical collateral loss during accidental deletions. In case of ownership transfer, the vault atomically rebinds to the recipient's Gmail address, logging cryptographic transfer history to prevent cross-account asset hijacking.
07Security & Infrastructure Safeguards
- 100% TLS/HTTPS encryption in transit across all endpoints and web micro-apps.
- Encrypted database connections, salt-hashed IP storage, and environment variable key isolation.
- Cryptographic HMAC-SHA256 digital signatures validating origin authenticity for disaster recovery operations.
- Automated anti-brute force OTP lockouts (5 failed attempts maximum) and server rate-limiting on recovery appeals.
- Strict secret separation: server-only API keys are never bundled into client-side browser bundles.
08Law Enforcement Disclosure & Cybercrime Cooperation
While we protect lawful user privacy, Alpha QR maintains zero tolerance for criminal exploitation. We actively cooperate with statutory Law Enforcement Agencies (LEAs), Cyber Crime Police Cells, CERT-In, and judicial courts:
Pursuant to Section 69, 91 of the Code of Criminal Procedure (CrPC) / Bharatiya Nagarik Suraksha Sanhita (BNSS), and applicable international treaties, we may disclose account identity metadata, registration timestamps, associated QR destinations, and hashed IP telemetry to authorized law enforcement officers investigating:
- Financial fraud, banking phishing, or UPI extortion schemes;
- Child Sexual Abuse Material (CSAM) or sexual violence;
- Communal incitement, religious disharmony, or terroristic propaganda;
- Imminent threats to life, national sovereignty, or public order.
09Data Protection Officer & Inquiries
If you have any questions regarding this Privacy Policy, wish to exercise data rights, or submit a privacy grievance, please reach our Data Protection Desk at:
alphaprime.co.in@gmail.com • Grievance Redressal Officer, AlphaPrime, Chennai, Tamil Nadu, India