GDPR & CCPA Compliant

Privacy Policy & Data Security

GTIN Router is designed with Consumer Privacy First. Learn how we handle consumer QR code scan telemetry, salted SHA-256 IP hashing, and enterprise data protection.

1. Zero Plaintext IP Storage (Salted SHA-256 Hashing)

When a consumer scans a GTIN Router 2D QR Digital Link code on physical packaging, their raw IP address is processed temporarily in volatile memory solely to calculate rough geographical analytics (country/region). Raw IP addresses are NEVER stored in database tables or log persistent storage. Instead, IP addresses are immediately hashed using a cryptographic secret salt and UTC date (SHA-256(IP + Salt + Date)). This ensures 100% GDPR and CCPA privacy compliance while preventing individual consumer tracking.

2. Scan Telemetry & Aggregated Analytics

GTIN Router collects non-identifiable telemetry to provide CPG brands with performance analytics:

  • Timestamp of QR scan resolution
  • Aggregated geographical region (Country / State based on IP lookup)
  • Device Type & User-Agent (Mobile OS, POS Register, Desktop Browser)
  • GS1 GTIN & Batch Identifier (AI 10 / AI 21) scanned

3. Enterprise Account & Billing Information

Account registration details (email, organization name, GTIN prefix) are stored securely in SOC-2 compliant encrypted database infrastructure with strict multi-tenant access controls. Payment processing is handled exclusively by PCI-DSS Level 1 certified payment networks; GTIN Router never receives or stores credit card numbers on its servers.

4. Cookies & Data Rights

GTIN Router uses essential session cookies solely to authenticate dashboard account users. We do not use third-party tracking cookies on QR resolution paths. Under GDPR and CCPA, customers have the right to request export or deletion of their organization data by contacting support.