AviQR ("we", "our") is committed to protecting your privacy. This Policy explains what data we collect, how we use it, and your rights under the Digital Personal Data Protection Act 2023 (DPDP Act) and the IT Rules 2011.
Business users: Name, email, phone, business details (GSTIN, address), subscription and billing history, usage logs, device information.
End customers (via QR menu): Name and phone number (entered at checkout), order details, payment method. No card data is stored on AviQR servers.
We use your data to operate the platform, process orders, send order notifications (WhatsApp/SMS via Twilio), generate analytics, respond to support queries, and comply with legal obligations. We do not sell your data.
Razorpay — payment processing (order amount, contact details).
Twilio — SMS/WhatsApp notifications (phone number, order summary).
Google Cloud Vision — OCR menu scanning (image only).
We do not share data with advertisers or marketing platforms.
Account data: duration of account + 3 years. Order/payment records: 7 years (Income Tax Act). Customer contact data: 1 year from order. Audit logs: 90 days.
All data in transit is encrypted via TLS 1.2/1.3. Passwords are hashed with bcrypt. Databases are not publicly accessible. JWT tokens are short-lived with rotation.
We use session cookies for login state and a preference cookie (aviqr_lang) for language selection. We do not use advertising cookies or cross-site tracking.
You have the right to access, correct, erase, and port your personal data. You may withdraw consent for WhatsApp notifications at any time in Settings. Contact privacy@aviqr.com to exercise your rights.
AviQR is not directed to persons under 18. We do not knowingly collect data from minors.
Privacy queries: privacy@aviqr.com
Grievance Officer: grievance@aviqr.com (response within 30 days)
Address: [Company Registered Address], Bengaluru, Karnataka – 560001
Last updated: 25 June 2025