Privacy and data stewardship
This Privacy Policy explains how Platform Foundry LLC collects, uses, discloses, protects and retains personal information in connection with IndustryQR, https://industryqr.com, https://app.industryqr.com, our public QR routes, tenant environments and related support and commercial activities.
This Policy applies when you visit our public pages, create or use an account, scan an IndustryQR-managed QR code, use an authenticated scanner, submit an enquiry or support request, purchase a subscription, or otherwise interact with the Services.
Platform Foundry LLC ("Platform Foundry", "we", "us" or "our") is generally the controller or business responsible for personal information used for our own account administration, authentication, billing administration, platform security, fraud prevention, service improvement, support, legal compliance and business operations.
For operational information submitted to or generated within a customer's tenant—including QR Records, user-entered content, scan-action evidence and tenant-directed scan processing—the customer normally determines why and how that information is used. In those circumstances, the customer is generally the controller or business and Platform Foundry acts as its processor or service provider. The exact role depends on the activity, applicable law and any written agreement.
If your information was submitted by your employer, another organisation or an IndustryQR tenant, that organisation's own privacy notice and instructions may also apply. Privacy requests concerning tenant-controlled data may need to be directed to that organisation; we will assist or route requests where appropriate.
The information collected depends on how the Services are used. It may include:
We may receive information directly from you, from the customer or tenant that administers your account, automatically from your browser or device, from payment and infrastructure providers, or from authorised integrations.
"Customer Data" means information submitted, entered, uploaded, stored, generated or processed by or for a customer through the Services. We treat Customer Data and other non-public customer information as confidential unless the customer has made it public, deliberately uses a public-publishing feature, or disclosure is permitted by a written agreement or applicable law.
We use Customer Data only as reasonably necessary to provide, configure, host, maintain, secure and support the Services; follow authorised customer instructions; administer accounts and billing; troubleshoot issues; maintain backup and continuity; comply with law; and improve reliability, capacity and security using aggregated or de-identified information that does not reasonably identify a person or disclose Customer Data.
We do not sell or rent Customer Data. We do not disclose it to competitors or unrelated third parties for their independent commercial use. We do not use a customer's non-public data, name, logo, screenshots, project, results or working relationship in marketing or case studies without prior written consent.
A signed service agreement, confidentiality agreement, order form or data processing addendum may provide additional or stronger obligations. That written agreement controls to the extent of any conflict.
We may use personal information to:
We do not use precise scanner coordinates for advertising, continuous tracking or to infer sensitive personal characteristics. We do not use Customer Data for unrelated third-party marketing.
Where laws such as the EU or UK GDPR require a lawful basis, we rely on one or more of the following, depending on the processing:
You may withdraw consent at any time, but withdrawal does not affect processing already carried out lawfully and may not affect processing supported by another lawful basis.
When a person scans an IndustryQR-managed QR label, the Services may record the time, QR token or Record context, route mode, resolver outcome, referrer, broad device/browser context, IP address and approximate network-derived region. These records support routing, security, operational history, diagnostics, abuse prevention and customer analytics.
Public scan logging is designed to be restrained. Raw IP addresses and detailed user-agent information are restricted technical data and are not ordinarily shown in standard tenant analytics. Tenant-facing reports generally favour broad derived region, operational outcomes, anomaly indicators and aggregated information.
A public scan does not ordinarily identify the scanner by name unless the person signs in, submits information or otherwise interacts with an identified workflow. On Growth and Pro, eligible public landing and protected landing routes may request one precise scanner GPS position where platform, plan and tenant controls permit. Direct external-URL routes continue immediately without that GPS request. Protected or authenticated routes may require login and then associate activity with the authorised user.
Customers are responsible for giving workers, contractors, visitors or other scanners any additional workplace or context-specific notice required for the customer's use of scan records.
Where the feature is enabled by Platform Foundry, the customer’s Growth or Pro plan and the customer’s Tenant Administrator settings, IndustryQR may request one browser-reported precise GPS position from the scanner device on an eligible public or authenticated scan. Public precise scan GPS is off by default for each tenant. IndustryQR does not add a separate GPS-sharing choice or interstitial; the browser or operating system controls the single permission request.
The GPS request is point-in-time only. IndustryQR does not continuously monitor the device and does not make a QR label or physical item independently trackable. The reported position is evidence about the scanner device at the time of the scan; it is not proof of the QR-labelled item’s continuing position, ownership, custody or presence.
If permission is denied, unavailable, inaccurate, produces an error or times out, the Services record the applicable outcome and continue the public result, protected sign-in or normal authenticated scan/action pathway. Such outcomes are not silently treated as a confirmed mismatch. GPS accuracy depends on the device, browser, signal and environment.
Where configured, the reported scanner GPS position may be compared with expected GPS coordinates supplied by the customer for the QR Record, assigned Location or Site. Expected GPS coordinates are customer-entered operational reference data and are separate from scanner GPS and approximate IP/network-derived region.
IndustryQR may calculate accuracy quality, expected source, tolerance, distance, match status and anomaly outcomes. On Growth and Pro, exact latitude and longitude may be visible only to authorised Tenant Administrators and Tenant Managers when all controls permit; Operators and Readers cannot view them. Appropriate Platform Foundry support or security access remains restricted. Pro also permits an individual QR Record to use its own expected GPS coordinates instead of relying only on its assigned Site or Location.
Exact scanner latitude and longitude are short-retention data. The Growth plan maximum is 30 days and the Pro plan maximum is 90 days, subject to the customer’s lower selected period, technical operation, legal holds and written agreements. The platform purges exact coordinates after the applicable period while derived outcomes—such as permission, accuracy, distance, expected source, match and anomaly status—may remain under the normal scan-history retention policy.
Depending on plan and settings, authorised users may add photographs, notes, acknowledgements, acceptor names or other evidence to Scan Actions. This information may contain personal, workplace, safety, operational, customer or supplier information.
The customer determines whether these fields should be used and is responsible for lawful collection, appropriate notice, access permissions, retention settings and internal policies. Users should not upload highly sensitive, regulated or unrelated personal information unless its use has been assessed and authorised for the deployment.
An acknowledgement flag records that an action was marked acknowledged. It is not an electronic signature and does not prove that a named acceptor personally selected the control. Customers should not use IndustryQR evidence as the sole basis for high-risk employment, safety, legal or disciplinary decisions without appropriate verification.
The Services use cookies and related technical storage necessary for session management, authentication, security, routing, load handling and service operation. These technologies may store session identifiers and technical preferences and help distinguish legitimate requests from abuse.
We do not use the Services to sell personal information or for third-party cross-context behavioural advertising. If we introduce non-essential analytics, advertising pixels or similar tracking, we will update the relevant notice and provide consent or preference controls where required by law.
You may configure your browser to block or delete cookies, but essential cookies are required for login and parts of the Services may not function correctly without them.
Subscription payments are processed through Stripe or another disclosed payment provider. Payment providers collect and process payment-card, bank, billing, device and fraud-prevention information under their own privacy terms. Platform Foundry generally receives payment status, customer and subscription identifiers, invoice references and limited billing details rather than complete payment-card numbers.
We use payment and subscription information to create checkout sessions, activate and administer subscriptions, process renewals and cancellations, manage failed payments, reconcile accounts, prevent fraud and meet financial-record obligations.
We may disclose information to the following categories of recipients only as reasonably necessary:
Service providers may change as the platform evolves. They may process information only for authorised service purposes and subject to applicable contractual, privacy and security terms. We do not disclose Customer Data to unrelated parties for their independent advertising or commercial exploitation.
Platform Foundry is established in the United States, and the Services use international infrastructure and service providers. Personal information may therefore be processed in the United States, United Kingdom, European Economic Area, Australia or other countries where we, our customers or providers operate.
Privacy laws and government-access rules may differ between countries. Where applicable law requires safeguards for an international transfer, we use appropriate contractual, organisational or other lawful mechanisms, which may include data-processing agreements, standard contractual clauses or recognised transfer frameworks where available and suitable.
Customers requiring a particular hosting region, transfer arrangement or data-processing addendum should obtain written confirmation before submitting regulated or location-restricted data.
We retain information only for as long as reasonably necessary for the purposes described in this Policy, including service delivery, customer-selected plan and retention settings, security, audit, backup, billing, tax, legal compliance, dispute resolution and enforcement.
| Data category | General retention approach |
|---|---|
| Account and tenant records | For the account or customer relationship and a reasonable period afterward for legal, billing, security and continuity needs. |
| QR Records, routes, labels and operational history | According to customer instructions, product functionality, plan limits, account status and written agreements. |
| Scan events and action records | According to plan and tenant retention settings, technical limits and legal requirements. Some plan limits may be reserved for progressive enforcement. |
| Exact scanner coordinates | Growth maximum 30 days and Pro maximum 90 days, subject to a lower tenant setting and exceptions described above. |
| Derived GPS outcomes and anomalies | May remain for the applicable scan-history period after exact coordinates are purged. |
| Photos and attachments | According to the applicable feature, customer instructions, plan/storage terms and legal requirements. |
| Security, audit and verification records | As reasonably necessary to protect accounts, investigate incidents, demonstrate compliance and resolve disputes. |
| Billing and transaction records | For required accounting, tax, fraud-prevention and legal periods. |
Deletion from an active system may not immediately remove information from backups, logs, archives or records retained for legal reasons. Backup copies are isolated from ordinary use and are overwritten or deleted according to normal continuity cycles. We may retain aggregated or de-identified information that no longer reasonably identifies an individual.
On account closure, export, return and deletion depend on product functionality, the customer's instructions, plan, written agreement and reasonable technical limitations. Customers should export required records before termination.
We use reasonable administrative, technical and organisational safeguards designed for the nature of the Services and information involved. These may include tenant separation, role-based access controls, restricted application state, password hashing, verification controls, audit logging, encrypted transport, provider security controls, backups, monitoring and limited support access.
Access to non-public information is limited to authorised personnel, contractors and providers with a legitimate need. Support or security access may be logged and is used only for authorised purposes.
No internet, cloud, storage or security system is completely secure. Customers are responsible for their users, credentials, permissions, endpoint devices, lawful data collection and the security of third-party destinations. Please notify us promptly if you suspect unauthorised access or a security incident.
If we confirm an incident affecting personal information, we will assess it and provide notices or cooperation required by applicable law or a relevant written agreement.
Depending on your location and the applicable law, you may have rights to request access, correction, deletion, restriction, portability or information about processing; to object to certain processing; to withdraw consent; and to complain to a privacy authority. Some rights are subject to exceptions, verification and the role in which we process the information.
You may update certain account details through the Services or your Tenant Administrator. For other requests, contact us using the details below and identify the customer or tenant involved. We may need to verify your identity and authority. We will not discriminate against you for exercising applicable privacy rights.
Where Platform Foundry processes information solely on behalf of a customer, we may refer the request to that customer and assist it in responding. We may refuse, limit or charge for requests where permitted by law, including requests that cannot be verified, are manifestly unfounded or excessive, compromise another person's rights, or conflict with legal retention duties.
You may unsubscribe from optional marketing emails using the message link or by contacting us. Service, security, billing and account communications are not marketing and may continue while the account or relationship remains active.
Individuals may have the rights described above under the GDPR or UK GDPR and may lodge a complaint with their local supervisory authority or, in the United Kingdom, the Information Commissioner's Office. Where we act as processor, the customer remains primarily responsible for notices, lawful basis and responding to rights requests concerning tenant-controlled processing.
To the extent applicable, residents may have rights to know, access, correct or delete personal information; receive information about categories, sources, purposes and recipients; obtain a portable copy; and opt out of sale, sharing or certain targeted advertising. We do not sell personal information and do not share it for cross-context behavioural advertising.
Precise device GPS coordinates may be treated as sensitive personal information. Where collected, we use them only for the customer-enabled operational scan, expected GPS comparison, security and related service purposes described in this Policy—not to infer characteristics or for advertising. We do not offer a financial incentive for personal information. An authorised agent may submit a request where permitted, subject to verification.
Where the Australian Privacy Act and Australian Privacy Principles apply, individuals may request access to or correction of personal information and may complain about its handling. We aim to collect information reasonably necessary for the Services, manage it transparently and explain overseas processing.
Where applicable, local laws may provide rights of access, correction, withdrawal of consent, complaint or other controls. We will respond in accordance with the law that applies to the relevant activity and may require the customer controlling the data to participate.
The Services are business and operational tools and are not directed to children. Accounts may be created only by persons at least 18 years old or the age of legal majority in their jurisdiction. Customers must not knowingly authorise children to use the Services or submit children's personal information unless expressly agreed and lawfully configured. Contact us if you believe a child's information has been submitted improperly.
IndustryQR allows customers to route QR codes to customer-selected landing pages, external websites, forms, applications, files and other destinations. Those third parties may collect information under their own privacy policies. Platform Foundry does not control and is not responsible for their privacy, security, content or data practices.
Before entering credentials, payment information or sensitive data after scanning a QR code, check the destination domain and the identity of the organisation requesting the information. Customers are responsible for the destinations and content they configure.
We may update this Policy to reflect changes in the Services, data practices, providers, legal requirements or risk controls. The effective date at the top identifies the current version. Material changes may be notified through the Services, email, account notice or another reasonable method.
Where consent is legally required for a new use, we will seek it before that use. Continued use after an update does not override non-excludable privacy rights.
Contact us with questions, privacy requests, complaints or concerns about Customer Data, scanner information or this Policy. Please provide enough detail to identify the relevant account, tenant, scan or interaction without sending unnecessary sensitive information.
We will investigate privacy complaints and respond within the period required by applicable law. You may also complain to the privacy or data-protection authority in your jurisdiction. This Policy should be read with the Terms of Service and any applicable customer agreement or data processing addendum.