Privacy Policy
Updated 9 October 2026. What stays on your phone, what reaches the billing server, and what permissions do.
Local use and optional backup
Your UPI ID, shop name, preferences, setup test mark and manual customer-payment records are saved in browser storage. They stay on this device until you select Save my shop while signed in. That choice enables the optional backup described below. Device access, clearing storage or changing browsers can expose or remove local data. CSV exports are separate files under your control.
Camera and QR photos
The camera is used only while the QR scanner is open. Closing the scanner or leaving setup stops its stream. Uploaded QR photos are decoded locally and not uploaded. No QR photo is saved to the billing database. UPI payment apps read the payee, name, amount and note encoded in a QR when it is scanned.
Sign-in and optional shop backup
You can try the counter without signing in. Google sign-in stores your verified Google identifier and email; mobile sign-in sends your number to 2Factor to deliver and verify an OTP. BilltoQR stores verified login identities, temporary challenges and expiring HttpOnly sessions. We do not receive your Google password, Gmail, contacts, bank password or UPI PIN. Linking a second login method requires access to the signed-in account and verification of the new method.
Select Save my shop to send your shop name, receiving UPI ID, optional shop details, fee settings, manual payment history and saved part-paid balances to our private Supabase PostgreSQL database. After this choice, edits are backed up when connected. A new blank device can restore that saved copy after sign-in; an existing local shop requires an explicit choice. Pending offline changes remain on that device until saved. Conflicts retain the local copy for export. QR photos are decoded locally and are not uploaded.
Razorpay and subscription records
When you choose paid checkout, Razorpay’s checkout loads and receives the email prefill and subscription reference. Razorpay collects the payment information and recurring-payment authorization you provide inside checkout. BilltoQR stores the plan, amount in paise, consent time, terms version, subscription/payment/invoice references, verified paid period and cancellation state. Signed provider events are checked server-side. BilltoQR does not store card details, UPI PINs or bank OTPs. This subscription flow is separate from customers paying your shop.
Installation and notifications
Installation adds the app icon and caches public app files for use on your device. Notification permission enables a New bill shortcut, not bank-payment alerts or access to other apps. You can disable it in Settings or your phone permissions. Availability varies by device. The app uses no advertising trackers. The website and the BilltoQR app pages use Vercel Web Analytics, which records anonymous page views and performance data without cookies or any shop, UPI or payment details. Server network traffic still exposes ordinary request metadata to the hosting provider; request limits briefly use connection IP addresses in memory; SMS budgets temporarily store hashed client IP and phone-based counters in the database to limit abuse and costs.
Usage statistics
To fix problems and see whether the app is useful, the counter sends anonymous usage events to our private database: a random device ID, which screens open, when a QR is shown or a payment is marked received (with an amount range such as 100–500, never the exact amount), failures, language and whether the app is installed. Your shop name, and a tester label if you opened a link that has one, are stored so we can tell businesses apart; signing in links them to your account. We never send your UPI ID, customer details or exact bill amounts, and no advertising or session-recording tools are used. The app sends nothing if your browser has Do Not Track turned on. Ask support to delete these records.
Retention, deletion and support
Setup drafts expire after 24 hours when read. Sign-in challenges expire after 10 minutes, and billing sessions after 30 days; expired rows are cleaned on subsequent use. Local history and free-QR allowance remain until this site’s storage is cleared. Saved shop data, account, consent and financial records are retained as needed to operate subscriptions and meet applicable accounting or legal obligations. Request account-data access or deletion using the support contact below; records required by law may be retained. Clear this device removes local shop/history and detaches backup, but does not cancel AutoPay or erase saved shop or server billing data. Stop renewals separately before closing an account.
Who runs BilltoQR?
Operator details are being finalized. Paid checkout is disabled until they are available.