Privacy and data stewardship
Privacy Policy
This Privacy Policy explains how Platform Foundry LLC collects, uses, discloses, protects and retains personal information in connection with IndustryQR, https://industryqr.com, our public QR routes, tenant environments and related support and commercial activities.
Effective date: 21 July 2026Operator: Platform Foundry LLCGlobal business service
Our core position: customer and tenant information is confidential by default. We do not sell or rent Customer Data or personal information, and we do not use a customer's name, logo, screenshots, project or non-public relationship for publicity without prior written consent.
1. Scope and privacy roles
This Policy applies when you visit our public pages, create or use an account, scan an IndustryQR-managed QR code, use an authenticated scanner, submit an enquiry or support request, purchase a subscription, or otherwise interact with the Services.
Platform Foundry LLC ("Platform Foundry", "we", "us" or "our") is generally the controller or business responsible for personal information used for our own account administration, authentication, billing administration, platform security, fraud prevention, service improvement, support, legal compliance and business operations.
For operational information submitted to or generated within a customer's tenant—including QR Records, user-entered content, scan-action evidence and tenant-directed scan processing—the customer normally determines why and how that information is used. In those circumstances, the customer is generally the controller or business and Platform Foundry acts as its processor or service provider. The exact role depends on the activity, applicable law and any written agreement.
If your information was submitted by your employer, another organisation or an IndustryQR tenant, that organisation's own privacy notice and instructions may also apply. Privacy requests concerning tenant-controlled data may need to be directed to that organisation; we will assist or route requests where appropriate.
2. Information we collect
The information collected depends on how the Services are used. It may include:
- Account and identity information: name, email address, username, organisation, role, status, timezone, invitation details and account preferences.
- Authentication and security information: password hashes, verification records, login events, failed-login counts, session identifiers, IP address, device/browser information and security audit data. We do not store account passwords in readable form.
- Customer and subscription information: company name, contact details, billing email, plan, subscription status, transaction references and customer-support history.
- Tenant operational data: QR Records, QR Types, sites, locations, expected-position metadata, route and destination information, label templates, print history, imports, notes, references and configuration settings.
- Scan and action information: scan time, QR Record/token context, route outcome, authenticated user where applicable, action selected, requirement status, acknowledgement flag, Needs Attention state, acceptor details, notes and evidence.
- Location-related information: broad IP/network-derived country, region or city; tenant-entered expected coordinates; browser permission and accuracy outcomes; and, only where enabled and permitted, a one-time authenticated scanner position.
- Files and communications: photographs, attachments, support messages, enquiry content, onboarding information and correspondence.
- Technical and usage information: pages, requests, timestamps, diagnostics, error data, browser/operating-system context and service-performance information.
We may receive information directly from you, from the customer or tenant that administers your account, automatically from your browser or device, from payment and infrastructure providers, or from authorised integrations.
3. Customer Data and confidentiality
"Customer Data" means information submitted, entered, uploaded, stored, generated or processed by or for a customer through the Services. We treat Customer Data and other non-public customer information as confidential unless the customer has made it public, deliberately uses a public-publishing feature, or disclosure is permitted by a written agreement or applicable law.
We use Customer Data only as reasonably necessary to provide, configure, host, maintain, secure and support the Services; follow authorised customer instructions; administer accounts and billing; troubleshoot issues; maintain backup and continuity; comply with law; and improve reliability, capacity and security using aggregated or de-identified information that does not reasonably identify a person or disclose Customer Data.
We do not sell or rent Customer Data. We do not disclose it to competitors or unrelated third parties for their independent commercial use. We do not use a customer's non-public data, name, logo, screenshots, project, results or working relationship in marketing or case studies without prior written consent.
A signed service agreement, confidentiality agreement, order form or data processing addendum may provide additional or stronger obligations. That written agreement controls to the extent of any conflict.
4. How we use information
We may use personal information to:
- create and administer accounts, tenants, roles and subscriptions;
- authenticate users, issue verification codes and protect account access;
- provide dynamic QR routing, landing pages, label output, scan history, operator actions, evidence, analytics and customer-selected features;
- process authorised scans and compare permitted scanner-location data with tenant-entered expected positions;
- provide onboarding, support, communications and service notices;
- process payments and maintain financial, tax and transaction records;
- monitor availability, diagnose faults, prevent abuse, investigate security incidents and enforce our Terms;
- comply with legal obligations, lawful requests and dispute-resolution requirements;
- develop and improve features, usability, performance and capacity using appropriate safeguards; and
- protect our rights, users, customers, systems and legitimate business interests.
We do not use precise scanner coordinates for advertising, continuous tracking or to infer sensitive personal characteristics. We do not use Customer Data for unrelated third-party marketing.
5. Lawful bases
Where laws such as the EU or UK GDPR require a lawful basis, we rely on one or more of the following, depending on the processing:
- Contract: processing necessary to provide the Services, administer a subscription or take steps requested before entering a contract.
- Legitimate interests: operating, securing, supporting and improving a business platform; preventing fraud and abuse; maintaining audit records; and protecting customers and systems, where those interests are not overridden by individual rights.
- Legal obligation: processing needed for tax, accounting, legal, regulatory, security or lawful-request obligations.
- Consent: where required, including browser permission for precise device location and consent for non-essential cookies or marketing communications.
- Customer instructions: where we act as a processor or service provider for the customer, subject to the customer's lawful basis and instructions.
You may withdraw consent at any time, but withdrawal does not affect processing already carried out lawfully and may not affect processing supported by another lawful basis.
6. QR scans and technical data
When a person scans an IndustryQR-managed QR label, the Services may record the time, QR token or Record context, route mode, resolver outcome, referrer, broad device/browser context, IP address and approximate network-derived location. These records support routing, security, operational history, diagnostics, abuse prevention and customer analytics.
Public scan logging is designed to be restrained. Raw IP addresses and detailed user-agent information are restricted technical data and are not ordinarily shown in standard tenant analytics. Tenant-facing reports generally favour broad derived location, operational outcomes, anomaly indicators and aggregated information.
A public scan does not ordinarily identify the scanner by name unless the person signs in, submits information or otherwise interacts with an identified workflow. Public QR pages do not currently request precise GPS location. Protected or authenticated routes may require login and then associate activity with the authorised user.
Customers are responsible for giving workers, contractors, visitors or other scanners any additional workplace or context-specific notice required for the customer's use of scan records.
7. Precise GPS and expected position
Authenticated scanner location
Where the feature is enabled by Platform Foundry, the customer's plan and the customer's Tenant Administrator settings, the authenticated Operator Scanner may request one browser-reported device position after displaying a location notice and triggering the device's permission control. The browser or operating system controls the permission prompt.
The location request is point-in-time only. IndustryQR does not continuously monitor the device and does not make a QR label or physical item independently trackable. The position is evidence about the scanner device at the time of the scan; it is not proof of the physical item's continuing location, ownership, custody or presence.
If permission is denied, unavailable, inaccurate or times out, the Services record the applicable outcome and are designed to continue the normal authenticated scan/action pathway rather than silently treating the result as a confirmed mismatch. GPS accuracy depends on the device, browser, signal and environment.
Comparison and visibility
Where configured, the reported scanner position may be compared with an expected position supplied by the customer for the QR Record, assigned Location or Site. Expected-position coordinates are customer-entered operational reference data and are separate from scanner GPS and approximate IP/network-derived location.
IndustryQR may calculate accuracy quality, expected source, tolerance, distance, match status and anomaly outcomes. Exact latitude and longitude are separately controlled and, when all controls permit, are limited to authorised Tenant Administrators, Tenant Managers and appropriate Platform Foundry support or security personnel.
Retention
Exact scanner latitude and longitude are short-retention data. The initial default is 30 days and the current Pro plan maximum is 90 days, subject to the customer's lower selected period, technical operation, legal holds and written agreements. The platform purges exact coordinates after the applicable period while derived outcomes—such as permission, accuracy, distance, expected source, match and anomaly status—may remain under the normal scan-history retention policy.
Public-scanner precise GPS is not part of the current released public service. If it is introduced later, we will update this Policy and the scanner-facing notice before activation.
8. Photos, notes and action evidence
Depending on plan and settings, authorised users may add photographs, notes, acknowledgements, acceptor names or other evidence to Scan Actions. This information may contain personal, workplace, safety, operational, customer or supplier information.
The customer determines whether these fields should be used and is responsible for lawful collection, appropriate notice, access permissions, retention settings and internal policies. Users should not upload highly sensitive, regulated or unrelated personal information unless its use has been assessed and authorised for the deployment.
An acknowledgement flag records that an action was marked acknowledged. It is not an electronic signature and does not prove that a named acceptor personally selected the control. Customers should not use IndustryQR evidence as the sole basis for high-risk employment, safety, legal or disciplinary decisions without appropriate verification.
9. Cookies and similar technologies
The Services use cookies and related technical storage necessary for session management, authentication, security, routing, load handling and service operation. These technologies may store session identifiers and technical preferences and help distinguish legitimate requests from abuse.
We do not use the Services to sell personal information or for third-party cross-context behavioural advertising. If we introduce non-essential analytics, advertising pixels or similar tracking, we will update the relevant notice and provide consent or preference controls where required by law.
You may configure your browser to block or delete cookies, but essential cookies are required for login and parts of the Services may not function correctly without them.
10. Payments
Subscription payments are processed through Stripe or another disclosed payment provider. Payment providers collect and process payment-card, bank, billing, device and fraud-prevention information under their own privacy terms. Platform Foundry generally receives payment status, customer and subscription identifiers, invoice references and limited billing details rather than complete payment-card numbers.
We use payment and subscription information to create checkout sessions, activate and administer subscriptions, process renewals and cancellations, manage failed payments, reconcile accounts, prevent fraud and meet financial-record obligations.
11. Disclosure and service providers
We may disclose information to the following categories of recipients only as reasonably necessary:
- the customer, its Tenant Administrators and authorised users;
- cloud hosting, database, application, network, domain, security, monitoring, backup and content-delivery providers, including Oracle and Cloudflare;
- payment providers, including Stripe;
- email and communications infrastructure providers, including PlatformInbox.com and its underlying providers;
- contractors and professional advisers who require access for legitimate development, support, legal, accounting, insurance, audit or compliance purposes;
- authorities, courts or other parties where required by law or reasonably necessary to protect rights, safety, systems or users; and
- a buyer, investor, lender or successor in a merger, financing, reorganisation, acquisition or sale, subject to appropriate confidentiality and legal safeguards.
Service providers may change as the platform evolves. They may process information only for authorised service purposes and subject to applicable contractual, privacy and security terms. We do not disclose Customer Data to unrelated parties for their independent advertising or commercial exploitation.
12. International transfers
Platform Foundry is established in the United States, and the Services use international infrastructure and service providers. Personal information may therefore be processed in the United States, United Kingdom, European Economic Area, Australia or other countries where we, our customers or providers operate.
Privacy laws and government-access rules may differ between countries. Where applicable law requires safeguards for an international transfer, we use appropriate contractual, organisational or other lawful mechanisms, which may include data-processing agreements, standard contractual clauses or recognised transfer frameworks where available and suitable.
Customers requiring a particular hosting region, transfer arrangement or data-processing addendum should obtain written confirmation before submitting regulated or location-restricted data.
13. Retention and deletion
We retain information only for as long as reasonably necessary for the purposes described in this Policy, including service delivery, customer-selected plan and retention settings, security, audit, backup, billing, tax, legal compliance, dispute resolution and enforcement.
| Data category | General retention approach |
|---|
| Account and tenant records | For the account or customer relationship and a reasonable period afterward for legal, billing, security and continuity needs. |
| QR Records, routes, labels and operational history | According to customer instructions, product functionality, plan limits, account status and written agreements. |
| Scan events and action records | According to plan and tenant retention settings, technical limits and legal requirements. Some plan limits may be reserved for progressive enforcement. |
| Exact scanner coordinates | Initial default 30 days; current Pro maximum 90 days, subject to a lower tenant setting and exceptions described above. |
| Derived GPS outcomes and anomalies | May remain for the applicable scan-history period after exact coordinates are purged. |
| Photos and attachments | According to the applicable feature, customer instructions, plan/storage terms and legal requirements. |
| Security, audit and verification records | As reasonably necessary to protect accounts, investigate incidents, demonstrate compliance and resolve disputes. |
| Billing and transaction records | For required accounting, tax, fraud-prevention and legal periods. |
Deletion from an active system may not immediately remove information from backups, logs, archives or records retained for legal reasons. Backup copies are isolated from ordinary use and are overwritten or deleted according to normal continuity cycles. We may retain aggregated or de-identified information that no longer reasonably identifies an individual.
On account closure, export, return and deletion depend on product functionality, the customer's instructions, plan, written agreement and reasonable technical limitations. Customers should export required records before termination.
14. Security
We use reasonable administrative, technical and organisational safeguards designed for the nature of the Services and information involved. These may include tenant separation, role-based access controls, restricted application state, password hashing, verification controls, audit logging, encrypted transport, provider security controls, backups, monitoring and limited support access.
Access to non-public information is limited to authorised personnel, contractors and providers with a legitimate need. Support or security access may be logged and is used only for authorised purposes.
No internet, cloud, storage or security system is completely secure. Customers are responsible for their users, credentials, permissions, endpoint devices, lawful data collection and the security of third-party destinations. Please notify us promptly if you suspect unauthorised access or a security incident.
If we confirm an incident affecting personal information, we will assess it and provide notices or cooperation required by applicable law or a relevant written agreement.
15. Privacy rights and choices
Depending on your location and the applicable law, you may have rights to request access, correction, deletion, restriction, portability or information about processing; to object to certain processing; to withdraw consent; and to complain to a privacy authority. Some rights are subject to exceptions, verification and the role in which we process the information.
You may update certain account details through the Services or your Tenant Administrator. For other requests, contact us using the details below and identify the customer or tenant involved. We may need to verify your identity and authority. We will not discriminate against you for exercising applicable privacy rights.
Where Platform Foundry processes information solely on behalf of a customer, we may refer the request to that customer and assist it in responding. We may refuse, limit or charge for requests where permitted by law, including requests that cannot be verified, are manifestly unfounded or excessive, compromise another person's rights, or conflict with legal retention duties.
You may unsubscribe from optional marketing emails using the message link or by contacting us. Service, security, billing and account communications are not marketing and may continue while the account or relationship remains active.
16. Regional disclosures
European Economic Area and United Kingdom
Individuals may have the rights described above under the GDPR or UK GDPR and may lodge a complaint with their local supervisory authority or, in the United Kingdom, the Information Commissioner's Office. Where we act as processor, the customer remains primarily responsible for notices, lawful basis and responding to rights requests concerning tenant-controlled processing.
California and other United States states
To the extent applicable, residents may have rights to know, access, correct or delete personal information; receive information about categories, sources, purposes and recipients; obtain a portable copy; and opt out of sale, sharing or certain targeted advertising. We do not sell personal information and do not share it for cross-context behavioural advertising.
Precise geolocation may be treated as sensitive personal information. Where collected, we use it only for the customer-enabled operational scan, expected-position comparison, security and related service purposes described in this Policy—not to infer characteristics or for advertising. We do not offer a financial incentive for personal information. An authorised agent may submit a request where permitted, subject to verification.
Australia
Where the Australian Privacy Act and Australian Privacy Principles apply, individuals may request access to or correction of personal information and may complain about its handling. We aim to collect information reasonably necessary for the Services, manage it transparently and explain overseas processing.
Canada, Singapore and other regions
Where applicable, local laws may provide rights of access, correction, withdrawal of consent, complaint or other controls. We will respond in accordance with the law that applies to the relevant activity and may require the customer controlling the data to participate.
17. Children
The Services are business and operational tools and are not directed to children. Accounts may be created only by persons at least 18 years old or the age of legal majority in their jurisdiction. Customers must not knowingly authorise children to use the Services or submit children's personal information unless expressly agreed and lawfully configured. Contact us if you believe a child's information has been submitted improperly.
18. Third-party destinations
IndustryQR allows customers to route QR codes to customer-selected landing pages, external websites, forms, applications, files and other destinations. Those third parties may collect information under their own privacy policies. Platform Foundry does not control and is not responsible for their privacy, security, content or data practices.
Before entering credentials, payment information or sensitive data after scanning a QR code, check the destination domain and the identity of the organisation requesting the information. Customers are responsible for the destinations and content they configure.
19. Changes to this Policy
We may update this Policy to reflect changes in the Services, data practices, providers, legal requirements or risk controls. The effective date at the top identifies the current version. Material changes may be notified through the Services, email, account notice or another reasonable method.
Where consent is legally required for a new use, we will seek it before that use. Continued use after an update does not override non-excludable privacy rights.