BinRo
Legal

Privacy Policy

We believe you have the right to know exactly how BinRo handles your data — in plain language.

Effective Date: July 9, 2026  |  Version 2.0
ℹ️

Plain-language summary: BinRo is a QR code safety and payment-fraud detection app. We collect data to analyse QR codes for fraud, power community safety features, and keep your account secure. We do not sell your personal data. We do not store your card numbers or UPI credentials. In-app purchases on Android are processed by Google Play Billing; on iOS by Apple In-App Purchase. Optional website donations are processed by Razorpay. In all cases, BinRo never receives or stores your actual payment credentials.

Contents
  1. Who We Are
  2. Data We Collect
  3. How We Use Your Data
  4. Payments & Transactions
  5. QR Code & UPI Data
  6. Firebase & Third-Party Services
  7. Data Pattern Analysis
  8. Data Sharing & Disclosure
  9. Data Retention
  10. Data Security & Breach Policy
  11. Profile & Privacy Controls
  12. Your Rights
  13. Cookies & Tracking
  14. Advertising
  15. Government & Law Enforcement
  16. Children's Privacy
  17. International Data Transfers
  18. Changes to This Policy
  19. Contact Us

1. Who We Are

BinRo is a mobile application (Android and iOS) and web platform designed to help users scan, analyse, generate, and manage QR codes with a focus on fraud prevention in the Indian digital payment ecosystem — including UPI, BharatQR, and 80+ payment apps.

BinRo is operated as a private software project under the laws of India, supported by the Kerala Startup Mission. Our registered contact address is Kerala, India.

This Privacy Policy applies to:

By using any BinRo service, you agree to the collection and use of information as described in this policy. If you do not agree, please discontinue use of BinRo immediately.

2. Data We Collect

We collect only the data necessary to operate BinRo's services. Below is a complete breakdown of every category of data we collect, why we collect it, and the legal basis under India's Digital Personal Data Protection Act, 2023 (DPDPA).

2.1 Account & Identity Data

2.2 QR Code & Scan Data

2.3 Payment & Transaction Data

Please see Section 4 (Payments & Transactions) for the full breakdown. In summary:

2.4 Usage & Behavioural Data

2.5 Device & Network Data

2.6 Camera & Media Data

Camera privacy: All camera frames are processed entirely on your device using on-device QR decoding. We do not upload your camera feed or individual frames to our servers. Images are only transmitted to our servers if you explicitly choose to upload a photo from your gallery to scan for a QR code.

2.7 Data You Submit Voluntarily

3. How We Use Your Data

We use your data for the following purposes. The legal basis for each use is noted in brackets, referencing India's Digital Personal Data Protection Act, 2023.

Purpose Data Used Legal Basis
Authenticate your account and maintain secure sessions Account & identity data, device data Contract
Analyse QR codes for safety and fraud in real time QR scan data, device data Contract
Sync scan history, favourites, and generated codes across devices QR scan data, account data Contract
Verify in-app purchases and unlock paid features Transaction ID, receipt token Contract
Send push notifications about QR safety alerts, friend activity, and app updates Push token, account data Consent
Build and improve our fraud detection models using aggregated, anonymised patterns Anonymised scan & behavioural data Consent
Power community trust scores from aggregated user reports Community reports, scan velocity Contract
Show relevant in-app advertising to keep BinRo free Aggregated, non-PII usage data Consent
Debug crashes and improve app stability Crash logs, device data Legitimate interest
Detect and prevent abuse, fraud, and spam Behavioural data, device data, IP Legitimate interest
Comply with Indian law and respond to lawful government requests Account data, scan data (as required) Legal obligation

4. Payments & Transactions

BinRo offers optional in-app purchases (such as premium features or support contributions) processed exclusively through the official billing systems of your device's app store. Here is exactly how it works:

4.1 How Payments Are Processed

🔒

BinRo never handles your payment credentials. We do not have access to your card number, CVV, expiry date, UPI ID, bank account number, net banking credentials, or Apple ID password. All payment processing is performed entirely by Google Play Billing (Android) and Apple In-App Purchase (iOS).

On Android, purchases are processed by Google Play using your Google account's saved payment method. Google's Google Payments Privacy Notice governs that transaction.

On iOS, purchases are processed by Apple using your Apple ID's payment method. Apple's Apple Privacy Policy governs that transaction.

4.2 What BinRo Receives

After a successful payment, the app store sends BinRo only the following limited information to verify your purchase:

This purchase information is linked to your BinRo account solely to activate the features you paid for. It is not used for advertising profiling or shared with third parties beyond what is necessary to verify the transaction.

4.3 Razorpay (Website Donations)

If you make a voluntary contribution via the BinRo website, payment is processed by Razorpay Software Private Limited, a PCI-DSS compliant payment gateway licensed by the Reserve Bank of India. Razorpay's Privacy Policy governs the data they process. BinRo receives only a transaction reference ID and the amount contributed — no card details or bank information.

4.4 Refunds

4.5 Financial Data We Do Not Collect

⚠️

BinRo never collects, stores, or transmits: credit/debit card numbers, UPI IDs or VPAs belonging to you as a payer, net banking credentials, bank account numbers, IFSC codes, CVV/CVC codes, ATM PINs, OTPs related to payments, or Apple ID / Google account passwords.

Note: When you scan a payment QR code, the payee's UPI ID or merchant VPA embedded in that QR code may be processed by our fraud-detection engine. This is limited to the payee's public merchant identifier — not your own payment credentials. See Section 5 for details.

5. QR Code & UPI / Payment QR Data

BinRo specialises in scanning and analysing payment QR codes, including UPI QR codes, BharatQR, and QR codes from 80+ Indian payment apps. Here is how we handle this sensitive data:

5.1 What UPI / Payment QR Codes Contain

A typical UPI QR code encodes publicly visible merchant information such as:

This information is publicly embedded in the QR code and is required for the payment to work. BinRo analyses this data to detect fraudulent or cloned merchant QR codes.

5.2 How We Process Payment QR Data

5.3 BharatQR & Multi-App Support

BinRo parses QR code formats across 80+ Indian payment applications including PhonePe, Google Pay, Paytm, BHIM, Amazon Pay, and others. This parsing is performed on-device. The decoded content may be sent to our servers for safety analysis as described above.

ℹ️

BinRo is not a payment app. We do not hold, transfer, or process funds. We are a security verification tool. If you have payment-related issues, contact your payment provider directly.

6. Firebase & Third-Party Services

BinRo relies on the following third-party services to deliver its core functionality. Each service processes certain data and is governed by its own privacy policy:

Service Provider Purpose Data Shared
Firebase Authentication Google LLC User account creation, login, session management Email, Google ID, auth tokens
Firebase Firestore Google LLC Primary database for scan history, QR data, user profiles, community reports Account data, scan data, community data
Firebase Realtime Database Google LLC Real-time features such as live scan counts and trust scores Anonymised aggregated scan/trust data
Firebase Storage Google LLC Profile photo storage and uploaded images for scanning Profile photos, uploaded scan images
Firebase Cloud Messaging (FCM) Google LLC Delivering push notifications to your device Push token, notification content
Google Safe Browsing API Google LLC Checking URLs decoded from QR codes against Google's threat intelligence database URLs extracted from scanned QR codes
OpenAI API OpenAI, L.L.C. AI-powered QR code analysis and safety explanations QR code content (no personal identifiers)
Razorpay Razorpay Software Pvt. Ltd. Website donation processing Transaction amount; payment credentials handled by Razorpay only
Google Play Billing Google LLC Android in-app purchase processing Transaction ID, product ID, receipt token
Apple In-App Purchase Apple Inc. iOS in-app purchase processing Transaction ID, product ID, receipt token
Expo Push Notifications Expo (by Shopify Inc.) Cross-platform push notification delivery Push token, notification payload

Firebase (Google Cloud) is compliant with GDPR, SOC 2 Type II, ISO 27001, and ISO 27701. All Firebase data processing occurs under Google's Firebase Privacy and Security documentation.

We are not responsible for the independent data practices of these third-party providers. We select providers that meet high security and compliance standards, but we encourage you to review their individual privacy policies.

7. Data Pattern Analysis & Threat Intelligence

BinRo maintains a continuously updated threat intelligence database derived from community scan data and reports. This database is the engine that powers our real-time QR code safety scores.

All pattern analysis uses anonymised and aggregated data only. We do not build databases that link specific QR code content to identifiable individuals.

8. Data Sharing & Disclosure

We may share your data only in the following circumstances:

8.1 Service Providers

We share data with the third-party services listed in Section 6 solely to deliver BinRo's functionality. These providers are contractually restricted from using your data for their own commercial purposes.

8.2 Threat Intelligence Partners

Anonymised URL, domain, and QR threat patterns (never linked to your identity) may be shared with threat intelligence networks to broaden fraud protection for the wider ecosystem.

8.3 Advertising Partners

Only aggregated, non-personally-identifiable usage data (such as general app category usage, device type, and approximate region) may be shared with advertising partners to serve relevant in-app ads. See Section 14 for your opt-out options.

8.4 Legal & Safety Disclosures

We may disclose data when required by:

8.5 Business Transfers

In the event of a merger, acquisition, or sale of all or substantially all of our assets, your data may be transferred to the acquiring entity under equivalent privacy protections. You will be notified of any such transfer via email or in-app notice.

🚫

We never sell your personal data. We do not sell your name, email address, phone number, specific QR scan content, payment credentials, UPI information, or any directly personally identifiable information to any third party for commercial purposes — ever.

9. Data Retention

10. Data Security & Breach Policy

10.1 Security Measures

10.2 Data Breach Response

Despite our best efforts, no system is completely immune to security incidents. If a breach occurs that affects your personal data, here is what you can expect from us:

11. Profile & Privacy Controls

Public Account (Default)

Private Account

Friends System

Scan History Visibility

Push Notifications

12. Your Rights

Under India's Digital Personal Data Protection Act, 2023 (DPDPA) and applicable international frameworks, you have the following rights regarding your personal data:

Right What It Means How to Exercise It
Access Request a full copy of all personal data we hold about you Email us at ahmedsameerbinan2@gmail.com
Correction Update your name, email, or profile photo Via Account Settings in the app, or by emailing us
Erasure / Deletion Permanently delete your account and personal data (within 30 days) Account Settings → Delete Account, or email us
Portability Receive your personal data in a structured, machine-readable format (JSON) Email us at ahmedsameerbinan2@gmail.com
Withdraw Consent Opt out of personalised advertising or AI training use of your data Email us at ahmedsameerbinan2@gmail.com
Object / Restrict Object to or restrict certain processing of your data Email us and we will assess your request
Lodge a Complaint Complain to the Data Protection Board of India or your local data protection authority Via the Board's official channel once established under DPDPA 2023
Nominate Nominate another person to exercise your data rights in the event of your death or incapacity Email us at ahmedsameerbinan2@gmail.com

We will respond to all verifiable rights requests within 30 days. We may need to verify your identity before processing requests. We do not charge a fee for reasonable requests.

Note: Some rights are limited where data has been fully anonymised and incorporated into community or AI datasets — anonymised data cannot be attributed to a specific individual and is therefore outside the scope of data subject rights.

13. Cookies & Tracking Technologies

13.1 Mobile App

The BinRo mobile app does not use browser cookies. Instead, we use:

13.2 Website

The BinRo website may use the following types of cookies:

You can control cookies through your browser settings. Blocking essential cookies may affect website functionality.

14. Advertising & Keeping BinRo Free

BinRo's core safety features are and will remain completely free. In-app advertising helps us sustain the project without charging users.

To opt out of personalised advertising:

15. Government & Law Enforcement Requests

BinRo operates under Indian law. We comply with lawful government and law enforcement requests for user data, including those made under:

Our process for responding to government requests:

16. Children's Privacy

BinRo is not intended for users under 13 years of age (or under 18 where applicable local law requires parental consent for data processing of minors).

17. International Data Transfers

BinRo's primary user base is in India. Our backend infrastructure runs on Google Firebase, which stores and processes data in Google Cloud data centres. Firebase data for India-based users is processed within Google's infrastructure, which may include servers located outside India.

Google Cloud and Firebase comply with applicable cross-border data transfer requirements, including standard contractual clauses where required. By using BinRo, you consent to the transfer of your data to Google's global infrastructure as necessary to provide the service.

Calls to the OpenAI API (for AI-powered analysis) involve data transfer to OpenAI's servers in the United States. Only QR code content (no personal identifiers) is included in these requests. OpenAI complies with applicable data transfer frameworks.

18. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

Continued use of BinRo after accepting the updated policy constitutes your agreement to the revised terms. If you do not agree to any changes, you should discontinue use of BinRo and request deletion of your account.

We recommend bookmarking this page and reviewing it periodically. The effective date at the top of this page reflects the most recent revision.

19. Contact Us

For any privacy questions, data access or deletion requests, or to exercise any of your rights described in this policy, please reach out to us:

📧 Email: ahmedsameerbinan2@gmail.com

🌐 Website: https://binan-maker.github.io/binro

📍 Address: Kerala, India

We aim to respond to all privacy-related enquiries within 5 business days. For urgent matters involving children's data or potential security incidents, please include "URGENT" in your subject line.

Back to Home