TrustQRby Pwscoding

Legal

Privacy Policy

What personal data we collect, why we collect it, who we share it with, and what you can ask us to do about it. Written to meet the Digital Personal Data Protection Act, 2023.

Effective from

1. Who is responsible for your data

Pwscoding, a sole proprietorship operated by Shadabalam Jamal Ahmed Khan, at 104, Saeed Manzil, Dongre Compound, Kausa, Mumbra, Thane, Maharashtra — 400612, India, operates TrustQR, the AI Chatbot and this website.

Which role we play depends on whose data it is, and this distinction runs through the whole policy:

  • For business owners who hold an account with us, we are the Data Fiduciary. We decide what we collect and why, and this policy governs it.
  • For members of the public who scan a business’s QR code and send that business private feedback, or who chat with a business’s bot, we are a Data Processor. That data belongs to the business you were dealing with; we only hold it for them. See section 6.

2. What we collect from business owners

Account

  • Your email address, and a securely hashed version of your password. We never store the password itself.
  • If you use “Continue with Google”: your name, email address and profile picture from Google. We ask for identity only — not access to your Gmail, Drive or contacts.

Your business

  • Business name, category, address, phone number, website, opening hours, logo, and your Google review link. Most of this is filled in for you from Google’s public listing when you search for your business.
  • Your Google rating and review count, recorded when you joined and again on days you open your dashboard, so we can show you how they have changed.
  • If you connect your Google Business Profile: a token that lets us read your reviews. You can disconnect at any time, which deletes the token and the reviews we stored with it.

Payments

The plan you bought, the amount, the date, and the reference IDs Razorpay gives us. We never receive or store your card number, CVV, UPI PIN or net-banking credentials — those go directly to Razorpay, which is RBI-authorised and PCI-DSS compliant.

Technical and usage

  • A session cookie that keeps you logged in across our apps. It is essential to the Service — you cannot use a logged-in area without it. We do not use advertising or cross-site tracking cookies.
  • IP address and request metadata in our server logs, kept for security and abuse prevention.
  • Which pages of the dashboard you use, so we can see what is working.

Optional

If you add your own OpenAI or Anthropic API key, we store it encrypted and only ever show you a masked preview. It is used solely to generate content for your account, and deleting it in settings deletes it from our database.

3. Why we use it, and on what basis

Under the DPDP Act we must tell you the purpose of each use. We use your data to:

  • Create and run your account, and keep you logged in — necessary to provide the service you asked for.
  • Generate your QR code, review page, suggested review text and reply drafts.
  • Take payment, give you a receipt, and know what your plan entitles you to.
  • Email you about your account: trial started, trial ending, trial expired, payment received, and important service or policy changes. These are service messages, not marketing, and you cannot opt out of them while you hold an account.
  • Ship your Premium QR Stand, where your plan includes one.
  • Detect and prevent abuse, fraud and security incidents.
  • Meet legal and tax obligations.

We rely on your consent, given when you create an account and accept our Terms of Service, and on the legitimate uses the DPDP Act permits — including performing the contract you entered into with us and complying with law. You can withdraw consent at any time (section 8), though doing so generally means we can no longer provide the Service.

We do not sell your data

We have never sold personal data and do not intend to. We do not share it with advertisers, data brokers or list vendors. The only parties who receive it are the service providers in section 5, who process it on our instructions to run the product.

4. AI Chatbot data

  • The website pages we crawl and the documents you upload, plus the numeric representations (embeddings) we derive from them so your bot can find relevant answers.
  • Conversations between your bot and your website visitors, and any phone number a visitor gives at the number gate. These are your leads; they appear in your inbox.

Do not upload documents containing personal data about others, payment details, or confidential material you are not entitled to share. Your bot may repeat what is in them.

5. Who else touches your data

We use a small number of providers. Each gets only what it needs for its job.

Razorpay
Payment processing. Receives your name, email, phone and payment details directly. India.
Google
Business listing lookup (Places API), sign-in, and — only if you connect it — your Business Profile reviews. Google also receives a request when a customer taps through to post a review.
OpenAI / Anthropic
Generating suggested reviews, reply drafts and chatbot answers. They receive the business details and text needed for that generation. United States.
Cloudflare R2
Storage for uploaded documents and customer feedback photos. The bucket is private and has no public URL.
Vercel / Netlify
Application and website hosting.
Our email provider
Sending account and service emails over SMTP.

Some of these process data outside India. Where that happens we rely on the transfer mechanisms permitted under the DPDP Act and on each provider’s own contractual protections.

We will also disclose data where the law requires it, or to establish or defend a legal claim. If we are ever compelled to hand over your data, we will tell you unless we are legally barred from doing so.

6. If you scanned a QR code or chatted with a bot

You are not our customer — you are the customer of the business whose code you scanned. Here is exactly what happens with what you type.

  • Anonymous usage events. We record that a page was opened, which option was chosen, and whether text was copied, against a random ID stored in your browser. It carries no name, no phone number and no account, and we cannot use it to identify you.
  • Private feedback. If you choose to tell the business what went wrong, whatever you write — and your name, phone, email and photos if you provide them — is stored and shown to that business only. It is not published anywhere, not posted to Google, and not shown to other businesses. Name, phone and email are optional; the feedback works without them.
  • Reviews you post on Google. We never post on your behalf. If you tap through to Google, you are signed in as yourself and what you publish is between you and Google, under Google’s own terms. The suggested text we show is a starting point generated by an AI model — please change it so it reflects what actually happened to you.
  • Chatbot conversations. What you type is sent to an AI provider to produce an answer, and is visible to the business in their inbox.

To access, correct or delete feedback you sent, contact the business directly — it is their record. If you cannot reach them, write to us at pwscoding@gmail.com and we will pass it on and help get it actioned.

7. How long we keep things

Account and business profile
While your account exists, and for 30 days after you ask us to delete it.
Customer feedback and photos
While the owning business’s account exists, unless they or the customer asks us to delete it sooner.
Payment records
Eight years, as required by Indian tax and accounting law. This survives account deletion — we are not permitted to erase it on request.
Anonymous usage events
Up to 24 months, then aggregated.
Server logs
Up to 90 days.
Google connection token
Until you disconnect, which deletes it immediately.

8. Your rights

Under the DPDP Act, 2023 you may ask us to:

  • Tell you what we hold about you and who we have shared it with.
  • Correct or complete anything inaccurate. Most of it you can edit yourself in the dashboard.
  • Erase your data, subject to the records we are legally required to keep (see payment records above).
  • Withdraw consent, as easily as you gave it.
  • Nominate someone to exercise these rights if you die or become incapacitated.
  • Complain — to our Grievance Officer below, and after that to the Data Protection Board of India.

Email the Grievance Officer to exercise any of these. We may ask you to confirm your identity first, so that someone else cannot obtain or delete your data by pretending to be you.

9. Security

  • Passwords are hashed with bcrypt, never stored in plain text.
  • API keys you supply are encrypted before they are written to the database.
  • Feedback photos live in a private bucket with no public URL and are served only to the authenticated owner.
  • All traffic runs over HTTPS. Session cookies are HTTP-only and scoped to our own domains.
  • Public endpoints are rate-limited to blunt scraping and abuse.

No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the Data Protection Board of India as the DPDP Act requires.

10. Children

The Services are for businesses and are not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child’s data has reached us, tell us and we will delete it.

11. Changes to this policy

If we change how we use your data in a way that materially affects you, we will email the address on your account before it takes effect. The effective date at the top of this page always reflects the current version.

12. Grievance Officer

As required by the DPDP Act, 2023 and the Information Technology (Intermediary Guidelines) Rules, 2021:

Name
Shadabalam Jamal Ahmed Khan
Designation
Grievance Officer
Address
104, Saeed Manzil, Dongre Compound, Kausa, Mumbra, Thane, Maharashtra — 400612, India
Response time
We acknowledge within 48 hours and resolve within 30 days.

If you are not satisfied with our response, you may complain to the Data Protection Board of India.