Privacy Policy
This policy explains what information QRTap handles, why we handle it, who can see it, and the controls available to you. It covers our website, account services, public profiles, and trusted-introduction workflows.
Effective and last updated:QRTap uses account and professional-network information to provide profiles, relevant matches, and consent-led introductions. Google sign-in is used only to authenticate you and establish your account. We do not sell personal information, publish private contact details by default, or access your Gmail, Google Drive, Google Calendar, or Google Contacts through sign-in.
Scope and responsibility
This Privacy Policy applies to QRTap at www.qrtap.in, its authenticated member and organiser workspaces, public QRTap profile pages, and related support interactions (together, the “Service”). QRTap, based in Bengaluru, Karnataka, India, is responsible for the information it processes to operate the Service.
If an organisation, accelerator, association, employer, or community provides your access, that organisation may separately control membership information and decide how its network uses QRTap. In that situation, QRTap may process information on the organisation’s instructions. Contact the organisation for questions about its own decisions; contact us for questions about QRTap’s platform processing.
Information we collect
Information you or your organisation provide
- Account and identity: name, email address, profile image, account identifier, sign-in method, and authentication status.
- Professional profile: job title, company, location, biography, languages, industries, organisation membership, role, chapter, verification status, introduction availability, and public profile slug.
- Needs and offers: titles, descriptions, categories, industries, geography, deal type, value band, availability, and expiry or status information.
- Connections and introductions: requested purpose, participants, connector, context, fields selected for sharing, approvals or declines, meeting and next-action details, outcome category or value band, consent records, and proof timeline.
- Public profile enquiries: a visitor’s name, email, intent, reason for contact, consent timestamp, request status, and a shortened hashed email fingerprint used in the audit record.
- Support and communications: messages, feedback, attachments, and information needed to investigate or respond to a request.
Information collected automatically
We and our infrastructure providers may receive IP address, browser and device type, operating system, referring page, pages or features used, timestamps, approximate region, diagnostic events, security events, and cookie or similar identifiers. QRTap uses an IP-derived key temporarily to rate-limit public connection requests; the submitted request record does not store the raw IP address.
Please do not submit passwords, government identifiers, payment-card or bank details, health information, or other sensitive personal data in free-text profile, need, introduction, or outcome fields. Account passwords are stored only as one-way, salted password hashes and are not available to QRTap in readable form.
Google sign-in data and Google API disclosure
When you choose “Continue with Google,” Google asks you to select or authenticate a Google Account. QRTap receives the basic information needed for sign-in: your Google account’s unique identifier, name, email address, email-verification status, and profile image when available. We use this information to authenticate you, maintain a secure session, display your identity, prevent misuse, and associate your sign-in with the appropriate QRTap account or organisation.
QRTap’s standard Google sign-in does not request permission to read your Gmail, files, contacts, calendar, payments, or other Google product content. We do not use Google sign-in information for advertising, sell it, or allow humans to read it except where necessary for security, support, legal compliance, or with your affirmative permission.
QRTap’s use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements. You can revoke QRTap’s Google access from your Google Account connections. Revoking Google access stops future Google sign-in but does not automatically delete information already held in QRTap; use the deletion process in Section 11 for that.
How we use information
We use personal information to:
- create, authenticate, secure, and support accounts and sessions;
- operate professional profiles, QR or NFC-linked public pages, vCard downloads, memberships, needs, offers, matching, and organisation workspaces;
- identify relevant professional matches and explain why a path may fit;
- route introduction requests, record purpose-specific sharing choices, obtain connector and recipient decisions, schedule next actions, and produce QRTap Proof records;
- provide organisation administrators with member management, audit, export, event, activation, and privacy-safe outcome information within their network;
- respond to support, privacy, security, and grievance requests;
- measure reliability and feature use, debug problems, protect the Service, prevent fraud or abuse, and enforce our Terms of Service;
- comply with law, resolve disputes, and protect the rights and safety of QRTap, our users, and others; and
- improve the Service using aggregated or de-identified insights that are not intended to identify an individual.
We do not make decisions producing legal or similarly significant effects solely through automated matching. A match is a recommendation; people decide whether an introduction proceeds.
Legal grounds for processing
Depending on where you live and the context, we rely on one or more of the following grounds: performing our contract with you or the organisation providing your account; your consent, including consent to share selected details for a specific introduction; our legitimate interests in operating, securing, improving, and measuring a professional-network service; and compliance with legal obligations.
Where we rely on consent, you may withdraw it for future processing. Withdrawal does not make earlier lawful processing invalid and may prevent a requested introduction or feature from continuing. Where an organisation controls the processing, its lawful basis may apply.
Profile, introduction, and network visibility
QRTap is designed around purpose-specific visibility, but information is not private in every context. Your name, professional role, company, biography, and other fields marked public can be viewed by anyone with your public profile link. Verified members may see network-only profile details and active needs. Organisation administrators can see information needed to operate their network. Introduction participants can see the request context, selected sharing fields, decisions, timeline, and agreed next steps.
Do not include confidential third-party information in a profile, need, connection reason, introduction context, note, or outcome unless you are authorised to share it with the intended audience. A recipient may retain information after it has been shared, so use the minimum information necessary.
Retention and deletion
We retain information only for as long as needed for the purpose collected, the organisation’s instructions, security and dispute prevention, or legal obligations. Retention depends on the record:
- the QRTap server session cookie lasts no longer than eight hours and is revoked when you sign out or reset your password;
- public connection-request records are configured to expire 90 days after submission;
- an active need is time-bound by default, while its underlying record may remain as part of account, audit, or outcome history;
- profile, membership, offer, introduction, consent, task, proof, and audit records are kept while the relevant account or organisation uses the Service and afterwards only as needed for legitimate recordkeeping, disputes, security, or law;
- Google sign-in and Resend delivery records are retained according to our provider configuration and their applicable retention controls; and
- backup copies may remain for a limited recovery cycle before they are overwritten.
You may request account deletion at any time. Until automated self-service deletion is available, verified requests are handled manually. We will delete or de-identify information that is not required to complete an organisation instruction, preserve a consent or security record, resolve a dispute, or comply with law. We may retain a minimal record of the request and action taken.
Security and international transfers
We use safeguards appropriate to the nature of the information, including HTTPS, secure and HTTP-only session cookies in production, server-side token verification, role and participant checks, validation, rate limiting, restricted database access, audit events, and private/no-store controls on sensitive exports. No internet service is completely secure, and we cannot guarantee absolute security.
Our providers may process information in India, the United States, or other countries where they operate. These countries may have different data-protection rules. Where required, we use contractual or other recognised safeguards for cross-border transfers and limit providers to information needed for their services.
If you believe an account or personal information has been compromised, contact privacy@qrtap.in promptly.
Your choices and privacy rights
Depending on your location and relationship with QRTap, you may have the right to:
- access or receive a summary or copy of personal information we hold about you;
- correct or update inaccurate or incomplete information;
- delete personal information, subject to lawful and necessary retention;
- withdraw consent or change an introduction-sharing decision before the information is released;
- object to or restrict certain processing;
- receive portable information where applicable;
- revoke Google access through your Google Account;
- nominate another person to exercise applicable rights in the event of death or incapacity where local law provides; and
- raise a grievance or complain to the data-protection authority available in your jurisdiction.
Send a request to privacy@qrtap.in. State the right you wish to exercise and the email address and organisation connected with the account. We may ask for information reasonably necessary to verify identity and authority. If an organisation controls your account, we may refer the request to that organisation or assist it with the response. We aim to respond within 30 days, or within another period required or permitted by applicable law.
Children
QRTap is a professional service intended for adults aged 18 or older and is not directed to children. We do not knowingly collect personal information from a child. If you believe a child has provided information to QRTap, contact us so we can investigate and delete it where appropriate.
Changes to this policy
We may update this policy as the Service, providers, or law changes. We will post the revised policy here and update the effective date. If a change materially affects how we use personal information, we will provide additional notice through the Service, by email, or through the organisation providing your account when reasonably practicable. Earlier versions may be requested from us.
Contact and grievances
For privacy questions, rights requests, account deletion, or grievances, contact the QRTap Privacy and Grievance Contact at privacy@qrtap.in.
QRTap Privacy TeamBengaluru, Karnataka, India
Include “Privacy Request” in the subject line, the email and organisation linked to your account, and enough detail for us to understand the request. Please do not send passwords, authentication tokens, or government identification unless we specifically request a secure verification method.