QRCertificates
Legal

Privacy Policy

This policy explains what we collect, why, and the choices you have. It is written to be readable — not to hide behind jargon.

Last updated: 1 July 2026. This is a clear-language document, not legal advice. Questions? [email protected] · +91 84030 73319

Who we are & scope

QRCertificates (“we”, “us”) provides a platform to design, issue, deliver, and verify digital certificates. This policy explains what we collect, why, and the choices you have. It applies to our website, issuer dashboard, and APIs. It is written in clear language and is not a substitute for legal advice.

Information we collect

We collect:

  • Account details you provide — your name, email, organization, and login credentials.
  • Certificate & recipient data you choose to issue — recipient names, emails, courses, dates, and any fields you add to a template.
  • Payment information — handled by our payment partner; we retain invoices and credit balances, not your full card number.
  • Usage & device data — log data, IP address, and privacy-respecting analytics needed to run and secure the service.

How we use your information

To issue and verify credentials, deliver them on your behalf, provide support, process payments, prevent fraud and abuse, improve the service, and comply with law. We do not use recipient data for advertising, and we never sell personal information.

Legal basis & consent

Where required — including under India’s Digital Personal Data Protection Act, 2023 (DPDP) and the GDPR for visitors in the EU/UK — we process personal data on the basis of your consent, the performance of our contract with you, and our legitimate interest in running a secure service. As an issuer, you are responsible for having a lawful basis to provide us the recipient data you upload.

Public verification data

A credential’s public verification page displays only what is needed to confirm authenticity and issuer identity — typically the recipient name, credential title, issue date, and issuing organization. You control which fields a certificate carries. Verification is public by design so credentials can be independently trusted, with no login required.

Cookies & analytics

We use strictly-necessary cookies to run the dashboard and privacy-respecting analytics to understand aggregate usage. You can control cookies through your browser. Verifying a credential never requires a login or a cookie.

How we share

We share data only with the processors needed to run the service — for example payment processing (Razorpay), transactional email delivery, and cloud hosting/storage — under appropriate data-processing agreements, and where required by law. We do not sell your data.

International transfers

Our infrastructure and sub-processors may store or process data outside your country (including in the EU and on global edge networks). Where we transfer personal data across borders, we apply appropriate safeguards consistent with applicable law.

Data retention

Issued credentials are retained so they remain verifiable for their lifetime — that is the purpose of a verifiable certificate. Account and billing records are kept while your account is active and as required for legal and tax purposes. You can revoke a credential at any time and request deletion of your account data, subject to records we must keep.

Security

Credentials are cryptographically signed (Ed25519). We use encryption in transit, access controls, and reputable infrastructure. No system is perfectly secure, but we work to protect your data and to notify you of material incidents as required by law.

Your rights

Subject to applicable law, you may access, correct, export, or delete your personal data, withdraw consent, or object to certain processing. Indian users have rights under the DPDP Act, 2023, including grievance redressal; EU/UK visitors have rights under the GDPR. To exercise any right, contact us using the details below.

Children

QRCertificates is intended for organizations and is not directed to children. We do not knowingly collect data from children without appropriate consent.

Changes to this policy

We may update this policy; material changes will be communicated through the service or by email. The “last updated” date above reflects the current version.

Contact & grievances

For any privacy question, data request, or grievance, contact our support / grievance team:

We aim to acknowledge grievances promptly and resolve them within the timelines required by applicable law.