Legal
Privacy Policy
Version 1.14 · Effective September 2026 · Applies to every YE-Tra plan (Free Trial, Starter, QR Suite, Growth, Scale, Custom)
YE-Tra ("we", "us", "our") is a platform operated by CalmCoral Private Limited that connects physical products to AI-generated digital pages via scannable QR codes, with an admin dashboard, a per-brand client portal, and real-time scan analytics. This policy explains what data we collect, why, and how it's protected — across every plan we offer. YE-Tra is currently offered as a beta product — as we add or change features during this phase, the categories of data described below may evolve, and we'll update this policy accordingly (see §13).
1. Who this policy covers
This policy applies to three groups of people, differently:
| Who | What this policy covers for them |
| Brands / clients | Anyone who signs up for a YE-Tra account (any plan) to manage products, generate QR codes, and view analytics. |
| Shoppers | Anyone who scans a YE-Tra QR code in a store or on packaging — no account or personal information is required to do this. |
| Site visitors | Anyone browsing our public marketing pages, including the Contact Us form. |
2. Information we collect
From brands, at signup and while using the platform
- Name, company name, contact email, and optional phone number
- Sign-in is handled through AWS Cognito, our identity platform, with Google Sign-In as a federated option — we never see or store your password ourselves; we only receive your verified name and email once you've signed in
- Security question answers you choose, used only to verify your identity if you ever need support-assisted account recovery
- For accounts that require it: owner/employee identity verification details (e.g. a business registration number or employee ID, plus an uploaded approval document)
- Product URLs and any manual content you submit for AI page generation
- Billing plan, coupon usage, and payment-confirmation status (see §4 of our platform documentation for how payment is currently handled — no card details ever pass through or are stored on our servers)
From your employees, if you issue Employee or Virtual ID cards
Some plans let a brand generate digital ID cards for their own staff (name, photo, designation/title, employee ID, and the email used to deliver a one-time PIN and QR verification link). This data is submitted by you about your own employees, not collected by us directly — you're responsible for having your employees' consent to include them, and we process it solely to generate, deliver, and PIN-verify their card. A verified visitor's card also shows a rolling weekly re-verification status. The photo is used for visual display and human identity confirmation only — we do not perform facial recognition or any other biometric matching against it.
From prospects who book a live demo
Our public "Book a Demo" calendar collects a name, email, company, phone number, and any notes you enter. The confirmation email itself may be delivered via Gmail — see §7. Video-call access uses a Jitsi Meet room (a free third-party video service run by 8x8, Inc.) — no account or app install is required on either side, and the room's web address is a random, unguessable identifier per booking, not shared with anyone else. We are not currently creating a Google Calendar event or sharing your booking details with Google for this purpose (we may enable optional Google Calendar/Meet integration in the future, in which case this policy will be updated first).
Customer reviews you choose to submit
A logged-in client can optionally submit a review (your name, an optional role/title, a written quote, and a star rating) from their dashboard. Unlike every other data category on this page, an approved review is deliberately published on our public website as a testimonial — only after we've reviewed and approved it. You can withdraw a submitted review, published or not, at any time from your dashboard.
From shoppers, when they scan a QR code
- A cryptographically hashed version of their IP address — the original IP is never stored
- Device/browser type (user agent string), timestamp, and which store location the scan came from (if the QR is store-specific)
- Nothing that identifies the shopper personally — no name, no account, no cross-site tracking
From anyone using our Contact Us form
- Whatever name, contact detail, and message you choose to submit — used only to respond to your inquiry
3. How we use it
- To create and operate your account, and enforce the limits/features of your plan
- To generate AI-written product pages and respond to shopper chatbot questions
- To record and display scan analytics (per-product, per-store, and over time) back to the brand that owns the QR code
- To verify your identity if your account requires it, or if you contact support for account recovery
- To send you account-related notices and, if you've opted into them, product updates
- To generate, deliver, and PIN-verify Employee/Virtual ID cards you create for your own staff, including their periodic rolling re-verification
- To detect and prevent abuse, fraud, or tampering with QR codes and scan data
We do not sell personal information, and we do not use shopper scan data for advertising.
4. AI-generated content
When you submit a product URL, we use an AI service to read the publicly available information at that URL and generate marketing copy, a product page, and chatbot responses. A few important points:
- AI-generated content is based entirely on your own submitted product URL and may occasionally be inaccurate — you're asked to review each page before distributing its QR code, and this is confirmed via an explicit on-screen acknowledgement every time you download a QR code.
- Everything shown reflects what your own web page says at the time it's read — we don't independently verify, fact-check, or edit your product information. If your source page contains outdated, incorrect, or incomplete information, that's not something YE-Tra is responsible for; ensuring your own page is accurate and meets any legal or quality requirements that apply to your product category is your responsibility as the account holder.
- That acknowledgement is logged (timestamp, product, and which policy version was in effect) so there's a clear record of when AI-generated content was reviewed and accepted.
- We don't publicly name which underlying AI service we use, since that's an implementation detail that can change; what matters for your privacy is that submitted product data is processed solely to generate your page and chatbot responses, not for any other purpose.
5. Scan & shopper data
Every scan of a YE-Tra QR code is logged so the brand that owns it can see analytics. We deliberately minimize what's collected:
- IP addresses are hashed on arrival using a one-way cryptographic function — we do not store, and cannot recover, the original IP.
- Scan URLs are cryptographically signed; tampered or forged links are rejected automatically, so scan counts reflect real activity.
- No shopper account, cookie-based cross-site tracking, or advertising identifier is created or used.
Competitor-comparison consent: a brand's aggregate scan-count data is visible, by default, only to that brand and to YE-Tra staff. During onboarding — before any QR code is generated — every brand is asked whether their scan counts may also appear in competitor-comparison reports and dropdowns shown to other brands on the platform. This is opt-in: declining, or never answering, keeps that brand's data out of every other brand's competitor view, with no effect on their own dashboard analytics. The choice can be changed at any time from the brand's dashboard (Privacy Preferences). Accounts created before this feature existed were defaulted to opted out (matching their actual prior state — their data was never shared before), and are asked to make a real choice the next time they log in, rather than that default silently standing in for their decision indefinitely.
6. Cookies & sessions
YE-Tra uses first-party session cookies only — there are no third-party advertising or analytics cookies on the platform, and no cookie-consent banner is shown because nothing here is used for tracking or advertising.
| Cookie | Purpose | Lifetime |
| Client session | Keeps you signed in to your client portal | Until you log out or the browser session ends |
| Admin session | Separate, independent sign-in for the admin dashboard | 12 hours |
Our public pricing table also saves your chosen display currency (USD/INR/CAD) in your browser's local storage, purely so it's remembered on your next visit — it never leaves your device, isn't sent to us, and isn't used to identify or track you.
7. Sharing & processors
We share information only with the service providers necessary to run the platform, under confidentiality obligations. We do not sell personal information to anyone, and we don't share brand or shopper data with other brands on the platform.
| Provider | What it's used for |
| AWS Cognito | Our identity platform — manages client account authentication and session security |
| Google | Federated Sign-In option through AWS Cognito; delivering transactional email (PIN codes, receipts, booking confirmations). Not currently used for demo-booking video calls (see Jitsi/8x8 below). |
| Jitsi / 8x8, Inc. | Provides the video-call room for booked demos, via 8x8's free public Jitsi Meet service — no YE-Tra account or app install needed by either party; each room's address is a random, unguessable identifier generated per booking |
| Our AI content provider | Reads product data you submit to generate marketing copy, product pages, and chatbot responses (see §4) — we don't publicly name the specific service since that's an implementation detail that can change; enterprise clients with their own compliance requirements can request our current subprocessor list under NDA (see §14) |
| Razorpay | Processes real subscription payments for India-billed accounts — no card details ever pass through or are stored on our servers |
| AWS (cloud hosting) | Runs the application and stores account/product data securely |
Enterprise clients can request a signed Data Processing Addendum covering these subprocessors — contact us (§14).
If YE-Tra is involved in a merger, acquisition, financing, or sale of some or all of its assets, your information may be transferred as part of that transaction; we'll require any successor to honor this Privacy Policy (or one at least as protective) for information collected under it.
8. Data retention
- Deleted products are kept in a recovery cache for 10 days before permanent removal, in case of accidental deletion.
- Deleted QR Suite site summaries are kept in a trash folder for 30 days before permanent removal.
- Identity verification documents are retained for as long as your account remains active and verification is required. You have 10 days from signup to complete verification — see our Terms of Service §2 for what happens if that window passes.
- Employee/Virtual ID card data is retained for as long as that employee's card remains active, or until you delete it from your dashboard.
- A submitted review (published or not) is retained until you withdraw it or we remove it; published reviews are removed from the public website immediately on withdrawal or unpublishing.
- If you close your account, we delete or anonymize personal data within a reasonable period, except where we're required to retain records by law.
9. Security
- Client accounts sign in via AWS Cognito (with Google as a federated option) — we never see or store your password.
- QR/scan URLs are cryptographically signed to prevent tampering and forged scan inflation.
- IP addresses are hashed before storage; we never persist raw IPs from a scan event.
- Login attempts are rate-limited to reduce automated password-guessing.
- Access to identity verification documents and admin tools is restricted to authorized account administrators.
No system is perfectly secure, but we design for data minimization first — the less personal data we hold, the less there is to protect.
If a breach occurs: in the unlikely event of a security incident affecting your personal data, we will investigate promptly, take steps to contain and remediate it, and notify affected account holders without undue delay, along with any regulator we're legally required to notify. Where a client's own end-users (e.g. staff issued an Employee/Virtual ID card) are affected, we'll notify the client so they can inform their own staff.
10. Your rights & choices
- Access & correction — update your name, email, and phone anytime from My Profile in the client portal.
- Sign-in & security — your account signs in via AWS Cognito (with Google as a federated option), so password resets and lockout recovery happen through that sign-in provider directly, not YE-Tra support — we never see or store your password, so we cannot reset it or verify your identity to unlock it on your behalf.
- Pause or close your account — paid plans can self-service pause a subscription (nothing is deleted, everything resumes exactly where it left off) or request account closure via support.
- Data export or deletion requests — contact us (see §14) and we'll respond within a reasonable timeframe.
11. Regional compliance
We built this platform with two specific privacy regimes in mind:
- India — Digital Personal Data Protection Act, 2023 (DPDP Act): scan pages carry a plain-language notice that no personal information is collected from shoppers, consistent with data-minimization principles under the Act. See our dedicated DPDP Compliance section for the full notice.
- Canada — PIPEDA: we collect only what's needed to operate the service, hash IP addresses rather than storing them raw, and this policy is written to meet PIPEDA's openness and accountability principles. See our dedicated PIPEDA Compliance section for the full notice.
If your jurisdiction has additional requirements we haven't addressed here, please contact us — we're happy to clarify or accommodate.
12. Children's privacy
YE-Tra is a business-to-business platform intended for brands, retailers, and their adult staff. It is not directed at children, and we do not knowingly collect personal information from anyone under 18. Shoppers scanning a QR code are not required to provide any personal information regardless of age.
13. Changes to this policy
We may update this policy as the platform evolves. The version number and effective date at the top of this page will change whenever we do, and material changes will be communicated to active clients via email or an in-dashboard notice. Continuing to use YE-Tra after a change takes effect means you accept the updated policy.
This page is provided for transparency about our data practices and does not constitute legal advice. If you need a jurisdiction-specific legal opinion, please consult a qualified lawyer.