YE-Tra ← Back to home
Legal

Privacy Policy

Version 1.14 · Effective September 2026 · Applies to every YE-Tra plan (Free Trial, Starter, QR Suite, Growth, Scale, Custom)
On this page
  1. 1. Who this policy covers
  2. 2. Information we collect
  3. 3. How we use it
  4. 4. AI-generated content
  5. 5. Scan & shopper data
  6. 6. Cookies & sessions
  7. 7. Sharing & processors
  8. 8. Data retention
  9. 9. Security
  10. 10. Your rights & choices
  11. 11. Regional compliance
  12. 12. Children's privacy
  13. 13. Changes to this policy
  14. 14. Contact us

YE-Tra ("we", "us", "our") is a platform operated by CalmCoral Private Limited that connects physical products to AI-generated digital pages via scannable QR codes, with an admin dashboard, a per-brand client portal, and real-time scan analytics. This policy explains what data we collect, why, and how it's protected — across every plan we offer. YE-Tra is currently offered as a beta product — as we add or change features during this phase, the categories of data described below may evolve, and we'll update this policy accordingly (see §13).

1. Who this policy covers

This policy applies to three groups of people, differently:

WhoWhat this policy covers for them
Brands / clientsAnyone who signs up for a YE-Tra account (any plan) to manage products, generate QR codes, and view analytics.
ShoppersAnyone who scans a YE-Tra QR code in a store or on packaging — no account or personal information is required to do this.
Site visitorsAnyone browsing our public marketing pages, including the Contact Us form.

2. Information we collect

From brands, at signup and while using the platform

From your employees, if you issue Employee or Virtual ID cards

Some plans let a brand generate digital ID cards for their own staff (name, photo, designation/title, employee ID, and the email used to deliver a one-time PIN and QR verification link). This data is submitted by you about your own employees, not collected by us directly — you're responsible for having your employees' consent to include them, and we process it solely to generate, deliver, and PIN-verify their card. A verified visitor's card also shows a rolling weekly re-verification status. The photo is used for visual display and human identity confirmation only — we do not perform facial recognition or any other biometric matching against it.

From prospects who book a live demo

Our public "Book a Demo" calendar collects a name, email, company, phone number, and any notes you enter. The confirmation email itself may be delivered via Gmail — see §7. Video-call access uses a Jitsi Meet room (a free third-party video service run by 8x8, Inc.) — no account or app install is required on either side, and the room's web address is a random, unguessable identifier per booking, not shared with anyone else. We are not currently creating a Google Calendar event or sharing your booking details with Google for this purpose (we may enable optional Google Calendar/Meet integration in the future, in which case this policy will be updated first).

Customer reviews you choose to submit

A logged-in client can optionally submit a review (your name, an optional role/title, a written quote, and a star rating) from their dashboard. Unlike every other data category on this page, an approved review is deliberately published on our public website as a testimonial — only after we've reviewed and approved it. You can withdraw a submitted review, published or not, at any time from your dashboard.

From shoppers, when they scan a QR code

From anyone using our Contact Us form

3. How we use it

We do not sell personal information, and we do not use shopper scan data for advertising.

4. AI-generated content

When you submit a product URL, we use an AI service to read the publicly available information at that URL and generate marketing copy, a product page, and chatbot responses. A few important points:

5. Scan & shopper data

Every scan of a YE-Tra QR code is logged so the brand that owns it can see analytics. We deliberately minimize what's collected:

Competitor-comparison consent: a brand's aggregate scan-count data is visible, by default, only to that brand and to YE-Tra staff. During onboarding — before any QR code is generated — every brand is asked whether their scan counts may also appear in competitor-comparison reports and dropdowns shown to other brands on the platform. This is opt-in: declining, or never answering, keeps that brand's data out of every other brand's competitor view, with no effect on their own dashboard analytics. The choice can be changed at any time from the brand's dashboard (Privacy Preferences). Accounts created before this feature existed were defaulted to opted out (matching their actual prior state — their data was never shared before), and are asked to make a real choice the next time they log in, rather than that default silently standing in for their decision indefinitely.

6. Cookies & sessions

YE-Tra uses first-party session cookies only — there are no third-party advertising or analytics cookies on the platform, and no cookie-consent banner is shown because nothing here is used for tracking or advertising.

CookiePurposeLifetime
Client sessionKeeps you signed in to your client portalUntil you log out or the browser session ends
Admin sessionSeparate, independent sign-in for the admin dashboard12 hours

Our public pricing table also saves your chosen display currency (USD/INR/CAD) in your browser's local storage, purely so it's remembered on your next visit — it never leaves your device, isn't sent to us, and isn't used to identify or track you.

7. Sharing & processors

We share information only with the service providers necessary to run the platform, under confidentiality obligations. We do not sell personal information to anyone, and we don't share brand or shopper data with other brands on the platform.

ProviderWhat it's used for
AWS CognitoOur identity platform — manages client account authentication and session security
GoogleFederated Sign-In option through AWS Cognito; delivering transactional email (PIN codes, receipts, booking confirmations). Not currently used for demo-booking video calls (see Jitsi/8x8 below).
Jitsi / 8x8, Inc.Provides the video-call room for booked demos, via 8x8's free public Jitsi Meet service — no YE-Tra account or app install needed by either party; each room's address is a random, unguessable identifier generated per booking
Our AI content providerReads product data you submit to generate marketing copy, product pages, and chatbot responses (see §4) — we don't publicly name the specific service since that's an implementation detail that can change; enterprise clients with their own compliance requirements can request our current subprocessor list under NDA (see §14)
RazorpayProcesses real subscription payments for India-billed accounts — no card details ever pass through or are stored on our servers
AWS (cloud hosting)Runs the application and stores account/product data securely

Enterprise clients can request a signed Data Processing Addendum covering these subprocessors — contact us (§14).

If YE-Tra is involved in a merger, acquisition, financing, or sale of some or all of its assets, your information may be transferred as part of that transaction; we'll require any successor to honor this Privacy Policy (or one at least as protective) for information collected under it.

8. Data retention

9. Security

No system is perfectly secure, but we design for data minimization first — the less personal data we hold, the less there is to protect.

If a breach occurs: in the unlikely event of a security incident affecting your personal data, we will investigate promptly, take steps to contain and remediate it, and notify affected account holders without undue delay, along with any regulator we're legally required to notify. Where a client's own end-users (e.g. staff issued an Employee/Virtual ID card) are affected, we'll notify the client so they can inform their own staff.

10. Your rights & choices

11. Regional compliance

We built this platform with two specific privacy regimes in mind:

If your jurisdiction has additional requirements we haven't addressed here, please contact us — we're happy to clarify or accommodate.

12. Children's privacy

YE-Tra is a business-to-business platform intended for brands, retailers, and their adult staff. It is not directed at children, and we do not knowingly collect personal information from anyone under 18. Shoppers scanning a QR code are not required to provide any personal information regardless of age.

13. Changes to this policy

We may update this policy as the platform evolves. The version number and effective date at the top of this page will change whenever we do, and material changes will be communicated to active clients via email or an in-dashboard notice. Continuing to use YE-Tra after a change takes effect means you accept the updated policy.

14. Contact us

Questions about this policy, or a request to access, correct, export, or delete your data?

Email: support@ye-tra.com

This page is provided for transparency about our data practices and does not constitute legal advice. If you need a jurisdiction-specific legal opinion, please consult a qualified lawyer.