Privacy Policy
This explains what the idzone QR studio collects, why we hold it, who else sees it, and how to get it deleted. It covers idzone.in and the QR generator that runs on it.
Last updated 24 July 2026. Questions about this page go to admin@idzone.in.
Who we are
The idzone QR studio is operated by IDZONE, No.99/100, Vinayagar Kovil Street, Sivananda Colony, Tatabad, Coimbatore, Tamil Nadu 641002, India. We are the data controller for everything described below. Reach us at admin@idzone.in or +91 90801 57234.
Designing a code without an account
You can open the studio, type a link, pick a shape and colour, and see a working QR code without telling us anything. That design lives in your browser tab and nowhere else — we do not save it, and refreshing the page clears it. An account is only needed to download, save or share a code, and to add a logo.
What we collect
- Account details. Your name, email address, phone number and a hashed password. If you sign in with Google we receive your name, email address and profile picture from Google instead — never your Google password.
- The codes you save. The content you encode (a URL, text, Wi-Fi details, contact details), the destination of a dynamic code, its design, and any logo you upload.
- Scan data, for dynamic codes only. When someone scans a dynamic code we log the time, the IP address, the browser user-agent string, and the country and device type derived from them. This is what powers your analytics. Static codes point straight at your destination and are never routed through us, so they generate no scan data at all.
- Payment records. The plan you bought, the amount, the currency, any promo code applied, and the Razorpay order and payment identifiers. If you claim the IDZONE member plan we also store the mobile number you entered, so the claim can be limited to one per number.
- Sign-in records. The time, IP address and device description of each login, so you can spot access you do not recognise.
What we do not collect
We never see or store your card number, CVV, UPI PIN or bank credentials. Payments are handled entirely inside Razorpay's checkout; we receive only a confirmation and a reference number. We do not sell personal data, and we do not run advertising trackers or third-party analytics scripts that follow you across other sites.
Why we hold it
- To run your account and let you sign in.
- To store, redirect and report on the codes you have made.
- To apply your plan's limits fairly, and to stop one account claiming a promo code or the member plan repeatedly.
- To send transactional email and SMS — one-time passcodes, password resets, and notices that a plan is about to lapse.
- To keep the service secure and investigate abuse.
We rely on performing our contract with you for the first three, on your consent for one-time passcodes, and on our legitimate interest in a working, non-abused service for the rest.
Who else sees it
Only the processors we need to run the service, each seeing only what their job requires:
- Razorpay — payment processing. Subject to their own privacy policy.
- Google — only if you choose to sign in with Google.
- Our email and SMS providers — to deliver passcodes and account notices. They receive the address or number and the message, nothing more.
- Our hosting and database providers — who store the data on our behalf and do not use it for anything else.
We will disclose data to a public authority only where the law actually requires it, and we will tell you unless we are forbidden from doing so.
A word about what you encode
A QR code is not a secret. Anything you bake into one — a Wi-Fi password, a phone number, a private link — can be read by anyone who scans it, or who photographs it off a wall. Please treat a printed code as public, because it is.
Cookies
We set one essential cookie: the session cookie that keeps you signed in. There are no advertising or cross-site tracking cookies. Clearing it signs you out.
How long we keep things
Account details and saved codes are kept while your account is open. Your plan may cap how many codes we keep, and older static codes are pruned once that cap is passed — dynamic codes are never pruned automatically, because deleting one would break a link already printed on something. Payment records are kept for as long as tax and accounting law requires. Closing your account deletes your codes, designs, scan logs and sign-in history.
Your rights
You can ask us for a copy of your data, ask us to correct it, ask us to delete your account and everything attached to it, or object to a particular use. Email admin@idzone.infrom your account's address and we will act within 30 days. Deleting a dynamic code stops its short link working, so make sure nothing printed still depends on it.
Children
The service is not aimed at anyone under 13, and we do not knowingly collect their data. If you believe a child has created an account, write to us and we will remove it.
Changes
If we change this policy we will update the date at the top, and for anything that materially changes what we collect or who sees it, we will email account holders before it takes effect.