Legal

Privacy Policy

Last updated: 19 August 2026

1. Who We Are

ScanTapView (“we”, “our”, “the platform”) operates at scantapview.com. We provide LED backlit tabletop QR standees and a connected digital storefront platform for local businesses (“merchants”) across India. Customers (“users”) interact with merchant pages by scanning QR codes at physical store locations.

This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and your rights under India's Digital Personal Data Protection (DPDP) Act, 2023.

2. Data We Collect

2.1 From Merchants (Business Owners)

  • Business information: Business name, type, address, city, phone number, WhatsApp number, email address
  • Branding assets: Logo images and cover photos uploaded to our storage
  • Catalog data: Product or service names, photos, prices, and descriptions
  • Authentication data: Email address used to sign in via magic link
  • Google Business links: Google Maps URL and Google Review URL (provided voluntarily)

2.2 From Customers (QR Code Scanners)

  • Scan events: Timestamp, IP address, browser user-agent string, and a lightweight device fingerprint (browser + screen size hash) for repeat-visitor detection. No Canvas or WebGL fingerprinting is used.
  • WhatsApp enquiry: When a customer taps the WhatsApp button, we log the event and the items selected. The customer's phone number is not captured by us — it only becomes known to the merchant through the WhatsApp conversation.
  • Reviews: Star rating (1–5) and optional text feedback submitted via our review form.
  • Contact records: If a merchant manually adds a customer's name and phone number to their contact database after a WhatsApp conversation, that data is stored on our platform.

2.3 What We Do Not Collect

  • We do not use advertising cookies or third-party tracking pixels
  • We do not use localStorage or sessionStorage
  • We do not access WhatsApp message content — all WhatsApp interaction is via wa.me deep links only
  • We do not collect payment card information — all payments are handled directly between customer and merchant

3. How We Use Your Data

PurposeLegal Basis (DPDP)
Displaying the merchant storefront to scanning customersLegitimate interest
Recording scan analytics for merchant dashboardLegitimate interest
Sending magic link authentication emails to merchantsContract performance
Storing merchant catalog, offers, and contact dataContract performance
Detecting repeat visitors for analytics accuracyLegitimate interest (lightweight fingerprint, no ads)
Routing Google review prompts to all customersLegitimate interest + compliance with Google policy
Merchant subscription and billing managementContract performance

4. Data Sharing

We do not sell, rent, or share your personal data with third parties for advertising purposes.

We share data only with:

  • Supabase (database & storage): Our cloud infrastructure provider. Data is stored in secure, encrypted databases hosted on Supabase.
  • Vercel (hosting): Our web application hosting provider. Handles server rendering and image optimisation.
  • WhatsApp / Meta: When a customer taps the WhatsApp button, they are redirected to WhatsApp's app via a wa.me link. We do not send any data to Meta — the user initiates the WhatsApp session themselves.
  • Merchant (your business): Scan analytics, inquiry logs, customer contacts, and reviews are shared only with the merchant whose QR code generated them.

5. Data Retention

  • Active merchants: Data retained for the duration of the subscription plus 90 days after expiry.
  • Churned merchants: All merchant data (contacts, inquiries, catalog, reviews, scans) is permanently deleted 90 days after subscription lapse.
  • Scan logs: IP addresses are anonymised after 30 days. Device fingerprints are retained for repeat-visitor analytics only.
  • Review data: Internal ratings are retained as long as the merchant is active. They are never made public.

6. Data Security

  • All database access is enforced via Row Level Security (RLS) — merchants can only access their own data
  • All data is encrypted in transit (HTTPS/TLS) and at rest
  • Service role keys are never exposed to client-side code
  • Magic link tokens expire after 10 minutes
  • Sessions expire after 7 days of inactivity

7. Your Rights (DPDP Act, 2023)

Under India's Digital Personal Data Protection Act, you have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate personal data
  • Erasure: Request deletion of your personal data (subject to legal retention obligations)
  • Data portability: Merchants can export all their contacts and inquiries as CSV at any time from the dashboard
  • Grievance redressal: File a complaint with our Data Protection Officer

To exercise any of these rights, email us at info@scantapview.com with subject line “Data Request — [Your Name]”. We will respond within 30 days.

8. Cookies

ScanTapView does not use advertising cookies, analytics cookies, or any third-party tracking cookies. We use only essential session cookies required for merchant authentication (managed by Supabase Auth). These cookies expire when the session ends or after 7 days of inactivity.

9. Children's Privacy

Our platform is intended for business owners and adult customers. We do not knowingly collect personal data from children under 18 years of age. If you believe a child has submitted personal data to us, contact us immediately at info@scantapview.com.

10. Changes to This Policy

We may update this Privacy Policy periodically. When we make material changes, we will update the “Last updated” date at the top of this page. Continued use of ScanTapView after changes constitutes acceptance of the updated policy.

11. Contact Us

ScanTapView — Data Protection

Email: info@scantapview.com

Made with care in India 🇮🇳