Privacy Policy

Last modified: May 28, 2026

1. Introduction & Scope

Welcome to Smart QR Review (“we,” “us,” or “our”). We operate the reputation management and Google Review automation platform accessible via https://smartqrreview.vetechno.net/ and its related subdomains.

This Privacy Policy describes how we collect, use, store, share, and protect personal and business data when you register as a customer (a “Merchant”), scan our generated QR codes, or leave ratings and feedback through our feedback channels.

Our Pledge: No Selling of Personal Data

We value trust above all else. Smart QR Review does **not** sell, lease, rent, or trade your personal data, your business details, or your customers' feedback data to third-party advertisers or brokers for any commercial purpose.


2. Information We Collect

We collect data to provide, maintain, and optimize our services. This collection falls into the following categories:

  • Account Information: When you register as a Merchant, we collect your name, business name, work email address, phone number, password hash, and localized business address.
  • Google Integrations Data: To redirect happy customers and manage review prompts, we collect your Google Place ID, Google Business Profile location name, and public review summaries via Google APIs.
  • Customer Ratings & Feedback: If an end-customer scans your Merchant QR code:
    • We collect rating values (1 to 5 stars).
    • For positive ratings (3 to 5 stars), we provide AI-generated review suggestions and redirect customers to your Google review link. The written text of positive reviews is not stored in our databases or displayed in the merchant dashboard (only aggregate rating metrics are kept for analytics).
    • For low ratings (1 to 2 stars), we collect the private feedback text, customer name, contact details (email/phone if provided), and timestamp. This data is stored internally and displayed privately in the merchant dashboard to help resolve issues.
  • QR Code Scan Analytics: We collect aggregate metadata of scans, including timestamps, browser user-agent strings, and geographical region (inferred from IP addresses), to compile your dashboard analytics. We do not link these IPs to specific individual identities.
  • AI Prompt Contents: Text prompts used in the AI Smart Reply tool and review suggestions are processed temporarily to create recommendations.

3. AI-Generated Content & LLM Handling

Smart QR Review leverages advanced Large Language Models (LLMs) to construct personalized review suggestions for customers and auto-generate smart replies for merchants.

How AI Data is Handled:

  • We do not submit direct personally identifiable information (PII) of your end-customers to AI processing partners unless explicitly included in the feedback text.
  • All AI processing is conducted via secure, enterprise API interfaces. Our contract terms with AI model providers ensure that your inputs and outputs are **not** used to train public models.
  • AI-generated text is stored in your secure account database for editing, rendering, and analytics display.

4. Cookies & Analytics Tracking

We utilize cookies, web beacons, and persistent tokens to manage session states, maintain security, remember user language/country preferences, and track aggregate user flows.

You can read the complete breakdown of cookie identifiers, lifespans, and direct management in our Cookie Policy. We use internal analytics tools and standard analytics partners (like Google Analytics) to measure site traffic and identify performance bugs.


5. Payment Processing & Gateways

Smart QR Review integrates third-party, PCI-DSS compliant payment gateways (such as Stripe) to manage subscription billing, trials, upgrades, and cancellations securely.

Credit Card Security:

  • We do **not** store or have direct access to your credit card number, expiration date, or CVV code on our servers.
  • All credit card inputs are transmitted directly to the gateway via secure, tokenized iframes.
  • The payment processor returns a billing token, billing metadata (card brand, last 4 digits, expiration month/year), and transaction logs, which are stored in our secure database.

6. Third-Party Integrations & Secure Cloud

To keep our application fast and reliable, we host our data and run services using secure, industry-leading infrastructure providers.

  • Supabase / AWS: All account structures, business data, feedback text, and QR configs are housed on highly secure cloud servers with strict firewall policies and row-level database security.
  • Google API Services: We access Google APIs to verify Place IDs and render business cards. Your Google Business connection is utilized solely to query review states as requested by your dashboard triggers.
  • Email and SMS Gateways: We utilize secure transactional mail services to deliver alerts, password resets, and customer feedback reports to your inbox.

7. GDPR & International Compliance

For merchants and visitors residing in the European Economic Area (EEA), United Kingdom, or Switzerland, we process data in compliance with the General Data Protection Regulation (GDPR).

Lawful Bases for Processing:

  1. Performance of a Contract: Processing is required to create your account, configure QR Codes, and manage subscription billing.
  2. Legitimate Interests: Running scan analytics to prevent fraud, tracking site traffic, and generating review suggestions.
  3. Consent: When you or your customer provides explicit optional data (e.g., email address in feedback forms).

8. Your Rights & Account Deletion Requests

Depending on your jurisdiction (such as GDPR in Europe or CCPA in California), you possess the following rights regarding your data:

  • Right to Access: Request a complete copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate business or profile details.
  • Right to Erasure (Deletion): Ask us to completely purge all your account information, QR code definitions, and feedback logs.
  • Right to Restrict Processing: Request restrictions on automated processes or AI suggestion operations.

How to Request Account Deletion:

To completely delete your account and remove all related data, please email support@vetechno.net with the subject line "Account Deletion Request - [Your Registered Email]". We will verify your identity and fulfill the request within 30 days, purging all credentials, logs, and business databases.


9. Security Practices

We implement comprehensive technical, administrative, and physical safeguards.

  • All connections are forced over HTTPS using Transport Layer Security (TLS 1.3).
  • Sensitive values like database passwords and third-party API tokens are encrypted at rest.
  • Access logs are routinely audited for brute force logins, scraping attempts, and rate limit violations.

* Note: While we enforce robust security controls, no data transmission over the internet or storage system is guaranteed to be 100% secure.


10. Contact Us & Data Controller

If you have questions about this policy, want to appeal a data decision, or wish to reach our Data Protection Officer, please contact us:

  • Email: support@vetechno.net
  • Mailing Address: Smart QR Review Compliance Team, Sukhdev Vihar, Okhla, New Delhi, Delhi 110025, India