Privacy Policy
Last Updated: August 28, 2026
1. Scope
This policy explains which Pro UPI QR features run entirely in your browser and which optional account or cloud features send limited data to our service providers. We minimize collection and do not ask for a UPI PIN, banking password, card number, or OTP.
2. Local-First Tools
Static QR generators, printable documents, calculators, image tools, and decoders normally process their form data and uploaded files inside your browser. That content is not uploaded to Pro UPI QR. A generated upi://pay link opens a UPI app; Pro UPI QR does not receive your UPI PIN or process the resulting bank transaction.
3. Browser Storage and Optional Groq Requests
Many tools save drafts in localStorage on your device. Clearing site data removes those drafts. The menu tool can optionally call Groq directly from your browser using an API key you provide; when you use that option, the key is kept in browser storage and your menu prompt is sent directly to Groq under Groq's terms. It is not routed through or stored by our server.
4. Accounts and Dynamic QR Campaigns
Clerk processes account identity, authentication cookies, and session data for sign-in and dashboard features. Merchant profiles store an account identifier, merchant name, UPI ID, and secret API credential in Vercel KV. For a dynamic QR campaign, we store the account identifier, server-generated campaign ID, title, HTTPS or UPI destination, category, optional expiry date, pause state, and aggregate mobile/desktop scan counts. The destination is disclosed when someone follows that campaign's QR. Individual scan histories and precise locations are not retained by the campaign service.
5. Checkout and Payment-Response Data
Merchant checkout sessions store the merchant name and UPI ID, order reference, amount in paise, safe return URL, status, and any transaction reference submitted by the customer. A submitted reference is marked pending until the merchant confirms it. Checkout sessions expire after 24 hours. The separately signed payment-response API may retain order status, transaction reference, amount, and provider for 90 days in Vercel KV.
6. Hosting, Security, and Technical Logs
Vercel hosts the site and server functions and may process standard request information such as IP address, user agent, timestamps, and error logs under its own privacy terms. We use short-lived hashed request fingerprints for abuse rate limits; the rate-limit keys expire with their configured windows. Clerk and Groq process data only for the features described above.
7. Retention and Deletion
Dynamic campaigns remain until their owner deletes them or we remove them for abuse. Checkout sessions expire after 24 hours, and signed payment-response records expire after 90 days. Merchant account settings remain while the account is active. To request account or merchant-profile deletion, email us from the address associated with your account. Provider security logs follow the provider's retention policy.
8. Analytics, Advertising, and External Links
We do not run Google Analytics or Google AdSense. Vercel Speed Insights records cookie-free Core Web Vitals (LCP, INP, CLS) for the page, not form contents. Vercel Web Analytics records page views and named product events such as QR generated, PNG/PDF export, share, copy, and tool error. Those events include only an action name and a short tool slug. They never include a VPA, payee name, amount, invoice text, or uploaded file. Links to UPI apps, affiliate merchants, or other websites leave Pro UPI QR and are governed by those services.
9. Contact and Data Requests
For privacy questions, access requests, deletion requests, or corrections, email privacy@proupiqr.in. Include only the information needed to locate your account; never email a UPI PIN, OTP, or banking password.