Legal

Privacy Policy

Last updated: 8 October 2026

In short: QRwik helps shops put their catalogue, orders, bookings, reviews and loyalty behind one QR code, and send WhatsApp and email messages to their own customers. We collect only what these features need. We do not sell personal data, we do not use it for advertising, and data we receive from Meta is used only to run the WhatsApp features a shop has switched on. You can ask us to delete your data at any time — see Data Deletion.

1. Who we are

QRwik (www.qrwik.com) is operated by QRwik, a sole proprietorship of Md Rehan Ansari, Ranchi, Jharkhand, India (“QRwik”, “we”, “us”). This policy explains how we handle personal data when you use our website, the QRwik merchant dashboard, a shop’s QRwik page (for example qrwik.com/s/…), and messages sent through QRwik.

It is written to meet India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) and its Rules, the Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and Meta’s Platform Terms and Developer Policies.

2. Shops, customers and our role

  • Shops (merchants) are the businesses that sign up for QRwik. For a shop’s own account data — the owner’s name, email, phone, billing — QRwik decides why and how it is used, and acts as the data fiduciary.
  • Customers of a shop are people who scan a shop’s QR code, place an order or booking, leave a review, join a loyalty club, or receive the shop’s messages. The shop decides why it collects and contacts its customers and is the data fiduciary for that data; QRwik processes it on the shop’s behalf (as a data processor) to provide the service.

If you are a customer of a shop, you can contact the shop directly, or contact us and we will help.

3. Information we collect

3.1 From shops

  • Account details: owner or staff name, email address, mobile number, and a password (stored only as a one-way hash).
  • Shop details: shop name, address, business type, country, opening hours, logo, banners, product or service photos, prices and descriptions.
  • Plan and billing records: the plan chosen, payment amount, date and the UPI transaction reference you submit. We do not collect or store card or bank login details.
  • Content the shop adds: customer lists it imports, offers and coupons, broadcast messages, documents uploaded to train its assistant, and replies to customers.
  • Messaging connection: when a shop connects WhatsApp, the WhatsApp number and the connection credentials described in section 4.

3.2 From customers of a shop

  • Contact details you enter: name, mobile number and, where asked, email address.
  • Orders and bookings: items, quantities, notes, date and time chosen, table or pickup details (for example a hotel pickup point for a tour), and order status.
  • Reviews and feedback: your rating and any private feedback you send to the shop. Public Google reviews are written by you on Google, not stored by us.
  • Loyalty: membership, points, rewards, and your birthday (day and month only) if you choose to give it.
  • Messaging choices: whether you agreed to receive offers, and any request to stop them.

3.3 Collected automatically

  • A random device identifier stored on your phone so a shop page can remember your cart and your own orders.
  • Technical data: IP address, browser and device type, pages requested, and timestamps — used for security, abuse prevention and fixing errors.
  • Sign-in sessions for shop accounts (a secure cookie), including the device type and IP address of each session.

We do not collect sensitive personal data such as health, financial account or biometric information, and we ask shops not to put it into QRwik.

4. Data from Meta and WhatsApp

A shop can connect its own WhatsApp Business account to QRwik by signing in with Facebook through Meta’s official sign-up window (Embedded Signup), using Meta’s WhatsApp Business Platform. With the shop’s permission, we receive:

  • The shop’s Meta business ID, WhatsApp Business Account ID, phone number ID, display name and phone number.
  • An access token that lets QRwik act for that WhatsApp Business Account only, with the permissions the shop approved (whatsapp_business_management and whatsapp_business_messaging).
  • Account information Meta provides through the platform: message templates and their approval status, messaging limits, quality rating, and message counts and costs.
  • Message events: delivery and read receipts, and messages that customers send to the shop’s WhatsApp number.

We never receive or store your Facebook password. Our commitments for data received from Meta (“Platform Data”):

  • We use it only to provide the WhatsApp features the shop asked for — sending its messages, showing its replies, templates, limits and costs in its dashboard.
  • We do not sell, license or rent it, and we do not use it for advertising, profiling, or to build data about people for anyone else.
  • We share it only with the service providers listed in section 8 that help us run QRwik, under confidentiality obligations.
  • Access tokens are encrypted at rest and visible to no one at QRwik in plain text.
  • When a shop disconnects WhatsApp or asks us to delete its data, we delete the tokens and stop all access, and we delete the related data as described in section 11 and on our Data Deletion page.
  • We comply with Meta’s Platform Terms, Developer Policies and the WhatsApp Business Messaging Policy.

5. How we use information

  • To provide the service: show a shop’s page, take orders and bookings, send order updates, tickets and receipts, run reviews and loyalty, and show the shop its dashboard.
  • To send messages the shop asks us to send — on WhatsApp or email — to customers who have agreed to hear from that shop.
  • To create and secure accounts: sign-in, one-time codes, preventing fraud, spam and abuse, and keeping logs needed for security.
  • To bill shops for their QRwik plan and keep the records the law requires.
  • To answer support requests and tell shops about important changes to the service.
  • To improve QRwik using aggregated, de-identified usage information.

We process personal data on the basis of consent (for example a customer agreeing to receive a shop’s offers), to perform our agreement with a shop, for legitimate uses allowed by the DPDP Act (such as a purchase you asked for), and to comply with law. You can withdraw consent at any time; this does not affect processing that already happened.

6. How WhatsApp messages are processed

  • Messages are sent from the shop’s own WhatsApp number, on the shop’s instruction. QRwik does not send its own marketing to a shop’s customers.
  • Shops must have each customer’s permission (opt-in) before sending offers, and must follow WhatsApp’s policies. QRwik sends offers only to customers marked as having agreed, and honours opt-outs.
  • To deliver a message, QRwik passes its content and the recipient’s number to WhatsApp (operated by Meta Platforms, Inc. and WhatsApp LLC). On the WhatsApp Business Platform, Meta processes these messages as a service provider to the shop under its WhatsApp Business terms.
  • Messages customers send to the shop are shown to the shop in its dashboard. We do not read them for any other purpose and do not use them for advertising.
  • Meta charges for business messages are billed by Meta directly to the shop. QRwik does not receive, hold or mark up these payments.

To stop a shop’s WhatsApp messages, tell the shop, or email us at support@qrwik.com with your number and the shop’s name — we will add your number to that shop’s do-not-message list. Every marketing email has an unsubscribe link.

7. AI features

Some features — like the shop assistant that answers customer questions, or help writing product descriptions and messages — send the relevant text (for example the shop’s catalogue, documents the shop uploaded, and the customer’s question) to Google’s Gemini API to generate a reply. We do not use your data to train AI models, and we send only what the feature needs. AI answers can be wrong; shops are responsible for checking what they publish.

8. Who we share it with

We do not sell personal data. We share it only as follows:

RecipientWhy
The shop you interact withYour orders, bookings, feedback, loyalty and contact details go to that shop so it can serve you.
Meta Platforms / WhatsAppDelivering WhatsApp messages and reading account information, as described in sections 4 and 6.
Amazon Web ServicesHosting our servers and storing uploaded files (photos, documents).
SupabaseHosting our database (Mumbai, India region).
VercelHosting our website.
ResendSending emails (sign-in codes, receipts, a shop’s email campaigns).
Google (Gemini API)Generating AI replies and drafts, as described in section 7.
AuthoritiesWhen required by law, court order, or to protect people’s safety or our legal rights.

Our service providers may only use the data to provide their service to us. If QRwik’s business is transferred, the data would move with it under the same protections, and we would tell shops in advance.

9. Cookies and local storage

We use only what the service needs to work: a secure sign-in cookie for shop accounts, and local storage on your device to remember your session, cart and device identifier. We do not use advertising or third-party tracking cookies. Clearing your browser data removes them; you will then need to sign in again.

10. Where data is stored and how it is protected

Our database is hosted in India (Mumbai). Some service providers, including Meta, Google, Vercel and Resend, may process data on servers outside India; such transfers follow the DPDP Act and any restrictions notified by the Government of India.

  • All traffic is encrypted in transit (HTTPS).
  • Passwords are stored as one-way hashes; WhatsApp and other access credentials are encrypted at rest.
  • Access to production data is limited to people who need it, and administrator access requires two-step verification.
  • Each shop can see only its own data.

No system is perfectly secure. If a personal data breach occurs, we will inform affected shops and people and the Data Protection Board of India as the law requires.

11. How long we keep it

DataKept for
Shop account and shop contentWhile the account is active. Deleted within 30 days after the shop closes its account or asks us to delete it.
Customer data held for a shopWhile the shop’s account is active, or until the shop or the customer asks us to delete it.
WhatsApp access tokensUntil the shop disconnects WhatsApp or deletes its account; then deleted.
Billing and payment recordsAs long as Indian tax and accounting laws require.
Security logsOnly as long as needed to keep the service secure.
BackupsDeleted data leaves our backups within a further 30 days.

12. Your rights

Under the DPDP Act you can:

  • get a summary of the personal data we hold about you and how it is used;
  • have it corrected, completed or updated;
  • have it erased, unless the law requires us to keep it;
  • withdraw consent you gave;
  • have a grievance resolved, and nominate a person to exercise these rights if you die or become incapable.

Email support@qrwik.com from the email or number linked to your data. We may ask you to confirm it is you. We acknowledge requests within 3 working days and resolve them within 30 days. If you are not satisfied, you may complain to the Data Protection Board of India. People in the UAE, Saudi Arabia and elsewhere can make the same requests and we will handle them under the laws that apply there.

For steps to delete your data, including removing a Facebook or WhatsApp connection, see Data Deletion.

13. Children

QRwik is meant for businesses and adults. Shop accounts may only be opened by people aged 18 or over. We do not knowingly collect personal data of children; if you believe a child has given us data, write to us and we will delete it.

14. Grievance Officer

Grievance Officer: Md Rehan Ansari
Email: support@qrwik.com
Address: QRwik, a sole proprietorship of Md Rehan Ansari, Ranchi, Jharkhand, India

We acknowledge every grievance within 3 working days and resolve it within 30 days.

15. Changes to this policy

We will update this page when our practices change and show the new date at the top. If a change is significant, we will tell shops by email or in the dashboard before it takes effect.