BarcodeScanner AI

Privacy Policy

Last updated: 3 October 2026

This Privacy Policy explains how DRB Services Kft. ("we", "us", "our") collects, uses, shares and protects personal data when you use Barcode Scanner, including the Barcode Scanner mobile app, the web portal at app.barcodescanner.ai, our website at www.barcodescanner.ai and the Barcode Scanner app for Shopify (together, the "Service").

Barcode Scanner is a business tool for warehouse and e-commerce teams. It is used to scan barcodes, pick, pack, receive, transfer and return products, and to sync this work with the online store or shipping platform connected by the business customer.

You can ask us to delete your data at any time by emailing [email protected]. Section 9 explains how.

1. Who we are

The data controller responsible for your personal data is:

DRB Services Kft.
Sellő utca 6, 2000 Szentendre, Hungary
Company registration number: 13-09-195642
EU VAT number: HU26536424
Email: [email protected]

2. Our role: controller and processor

  • We are the controller of the data we need to run your account: account owner details, billing records, and how you use the Service.
  • We act as a processor for our business customers when the Service handles data from their own store or shipping platform, such as order details and warehouse activity logs. The business customer (your employer, or the merchant who installed the app) decides what that data is used for, and we process it only on their instructions. If you are a warehouse operator using a device set up by your employer, or a shopper who bought from one of our merchants, you can contact that business or us directly. We will help them answer your request.

3. Data we collect

Account and company information

When you register in the portal, or install our Shopify app, we collect:

  • first name, last name and email address
  • company name and tax/VAT number
  • your password (stored only as a one-way hash)
  • optional branding settings, such as your company logo and brand colour

Device operator information

Account owners can create operator logins for their staff. For each operator we store their name, email address and a hashed password.

Device information

When the mobile app is registered to an account, we store a device label (a name chosen by the account owner), a device identifier generated by the app, and the registration date. We use these only to link the device to your account and to apply your plan's device limit. We do not use them for advertising or to track you across other apps or websites.

Warehouse activity and scan data

When the app is used, we record what happens so that the account owner can see it in the portal: logins and logouts, product and order scans (including failed scans and the scanned barcode), picking, packing, receiving, transfer and return events, return reasons, and the time of each event. Each event is linked to the company, the device and the operator who carried it out (name and email). These records can include order numbers and the products in an order, but not the shopper's name, email or address.

Store and order data from connected platforms

When a business connects a store or shipping platform (for example Shopify, Magento, Unas, Logzi or ShipStation), the Service reads and updates products, inventory, orders and fulfillments in that platform. Order data can include shoppers' names, email addresses, phone numbers and shipping addresses. We fetch this data only when it is needed to complete a task, such as showing an order to pack or printing a shipping label. We do not store shoppers' names or contact details in our own databases.

To keep these connections working, we securely store the access credentials (API keys or access tokens) that you provide or that the platform issues to us.

Camera

The mobile app uses your device's camera only to read barcodes. Images from the camera are processed on the device and are not stored or uploaded to us.

Billing information

We keep records of your subscription, plan, payment method type (bank transfer, card or Shopify billing) and invoices. If you pay through Shopify, Shopify handles the payment. We never receive or store your full card details.

Support and AI assistant

If you contact us, we keep your message and our reply.

On plans that include it, you can use the AI assistant in the portal and in the mobile app. To answer a question, it looks up only your own company's data: warehouse activity (for example recent events and picking, packing, receiving and return sessions, with the operator's name, the device name and the time) and product details from your catalog and connected store (name, SKU, barcode, warehouse location, stock quantity and price). Your question, the conversation so far and these lookup results are sent to OpenAI to produce the answer, as described in Section 7. Email addresses are removed from the looked-up data before it is sent. We do not store the conversations on our servers: in the portal they are kept in your browser until you delete them, and in the mobile app they are kept on the device until you delete them or sign out.

Website and portal usage

Our website and portal use cookies and similar technologies, as described in Section 10.

Data we do not collect

We do not collect your precise location, contacts, photos, health data or financial account details. We do not use advertising identifiers, and we do not sell personal data.

4. How we use your data

We use personal data to:

  • provide the Service: create and secure your account, register devices, record warehouse activity, show reports, and sync with your connected platforms (legal basis: performance of a contract)
  • bill you: manage subscriptions, issue invoices and keep accounting records (legal basis: contract and legal obligation)
  • communicate with you: send password resets, sign-in codes, service notices and replies to support requests (legal basis: contract and legitimate interests)
  • keep the Service secure and reliable: prevent misuse, investigate errors and monitor performance (legal basis: legitimate interests)
  • improve the Service: understand how features are used, in aggregated form (legal basis: legitimate interests, or your consent for analytics cookies)
  • meet legal obligations, such as tax and accounting rules (legal basis: legal obligation)

We do not use automated decision-making that has legal or similarly significant effects on you.

5. Shopify merchants and their customers

This section applies when a merchant installs the Barcode Scanner app from the Shopify App Store.

What we access and why

With the merchant's permission, the app accesses the store's products, inventory, locations, orders and fulfillment orders. We use this access only to provide the app's features to that merchant: finding products by barcode or SKU, picking and packing orders, updating stock levels, and fulfilling orders.

From the Shopify store we also receive the shop's domain, plan and contact email, and the store owner's name. We use these to create and manage the merchant's Barcode Scanner account.

Customer data

Orders can contain personal data about the merchant's customers, such as their name, email address, phone number and shipping address. We process this data:

  • only for the merchant, and only to carry out the order-handling actions the merchant asks for
  • only when needed, at the moment an order is opened, packed or fulfilled; we do not store customers' names or contact details on our servers
  • never for any other purpose: we do not use it for marketing, profiling or analytics, we do not combine it with data from other stores, and we do not sell or share it with anyone except the service providers listed in Section 7

Data requests and deletion through Shopify

We respond to Shopify's privacy requests:

  • Customer data requests: when a merchant's customer asks to see their data, we provide the merchant with any personal data we hold about that customer.
  • Customer erasure requests: when a merchant's customer asks to be forgotten, we delete any personal data we hold about that customer.
  • Shop erasure requests: when a merchant uninstalls the app, we immediately deactivate the store, cancel its subscription, and delete its operator logins and access tokens. When Shopify sends the shop erasure request 48 hours later, we delete the merchant's account details and the store's activity data. The only exception is data we must keep by law, such as invoices.

We complete these requests within 30 days. Customers can also send their request to the merchant they bought from, or to us at [email protected].

Billing

Charges for the Shopify app are billed through Shopify. We do not receive or store merchants' payment card details.

6. Sharing your data

We do not sell or rent personal data. We share it only with:

  • Your organisation. Activity linked to an operator is visible to the account owner and to other people they give access to.
  • Platforms you connect, such as Shopify, Magento, Unas, Logzi or ShipStation. We send them the data needed to carry out the actions you request. Their own privacy policies apply to the data they hold.
  • Service providers who process data for us, under contracts that require them to protect it and use it only on our instructions (see Section 7).
  • Authorities, where the law requires it, or to protect our rights, our users or the public.
  • A successor, if our business is merged or sold. We would tell you before your data becomes subject to a different privacy policy.

7. Service providers

We use the following providers to run the Service:

  • DigitalOcean: hosting, databases and file storage. Our servers and databases are located in the EU (Frankfurt, Germany).
  • Resend: sending transactional emails, such as password resets and sign-in codes
  • Sentry: error and performance monitoring for our servers
  • OpenAI: powers the optional AI assistant in the portal and the mobile app. It receives your question, the conversation so far, and the data needed to answer it: warehouse activity results (which may include operator names, but not email addresses) and product details (name, SKU, barcode, warehouse location, stock quantity and price). It never receives shoppers' names, email addresses, phone numbers or shipping addresses, and product images are not sent to it. Under OpenAI's API terms, this data is not used to train their models, and OpenAI keeps it for no more than 30 days, for abuse monitoring, before deleting it.
  • Google (Google Tag Manager, Google Analytics and Google Ads): website and portal analytics and measuring our ads, only if you accept cookies
  • Jotform: our contact form
  • Shopify: app installation, sign-in and billing for merchants who use our Shopify app

Some of these providers may process data outside the European Economic Area, including in the United States. Where they do, we rely on appropriate safeguards, such as the EU-U.S. Data Privacy Framework or the European Commission's Standard Contractual Clauses.

8. How long we keep data

  • Account, operator, device and activity data is kept while your account is active. When the account is closed, or when we receive a deletion request, we delete it within 30 days.
  • Shopify customer data is not stored. It is only processed while an order is being handled.
  • AI assistant conversations are not stored on our servers. The data sent to OpenAI to answer a question is deleted by OpenAI within 30 days.
  • Shopify store data is deleted when Shopify sends the shop erasure request, 48 hours after the app is uninstalled (see Section 5).
  • Invoices and accounting records are kept for 8 years, as required by Hungarian accounting law.
  • One-time sign-in codes expire after 60 seconds and are deleted within 24 hours.
  • Server backups are overwritten on a rolling basis, so deleted data is also removed from backups within 30 days.

After deleting an account, we may keep anonymised statistics that cannot identify any person, company or store. This does not apply to data from Shopify stores, which we delete in full.

9. How to request deletion of your data

You can ask us to delete your personal data at any time, whether you are an account owner, a device operator, a Shopify merchant or a merchant's customer.

To request deletion:

  1. Send an email to [email protected] with the subject "Data deletion request".
  2. Send it from the email address linked to your data, or tell us which account, company or Shopify store it relates to.
  3. Say whether you want your whole account deleted, or only certain data (for example, a single operator's data).

What happens next:

  • We confirm we have received your request within 3 business days. If we cannot tell that the request comes from you, we may ask you to confirm it from your registered email address.
  • We delete the data within 30 days: your account and company details, operators, devices, activity and scan history, connected-platform credentials and uploaded files.
  • We email you once the deletion is complete.
  • We keep only what we must keep by law, such as invoices and accounting records (see Section 8). We do not use that data for anything else.

Deletion is permanent and cannot be undone. Deleting your account does not delete data stored in your own store or shipping platform, such as your Shopify products and orders.

Account owners can also remove individual devices and operators at any time in the portal. Shopify merchants can stop all further data access by uninstalling the app.

10. Cookies and similar technologies

Our website and portal use:

  • Essential cookies and storage: a sign-in token that keeps you logged in, your language preference, and browser storage for portal features such as your AI assistant chat history. The portal does not work without these.
  • Analytics cookies: set through Google Tag Manager and Google Analytics, to help us understand how our website and portal are used.
  • Advertising cookies: set through Google Ads, to measure whether our ads lead to visits and enquiries.

Analytics and advertising cookies are only set if you accept them in the cookie banner. You can change your choice at any time with the "Cookie settings" link at the bottom of every page.

You can block or delete cookies in your browser settings. Blocking essential cookies will prevent you from signing in to the portal. The mobile app does not use cookies.

11. Security

We protect personal data with industry-standard measures:

  • all data is encrypted in transit (HTTPS/TLS) and at rest
  • passwords are stored only as one-way hashes, and sign-in codes are short-lived and single-use
  • access to production systems and personal data is limited to staff who need it, protected by strong authentication, and logged
  • test and development environments are kept separate from production

No method of transmission or storage is completely secure, but we work to protect your data. If a personal data breach affects you, we will notify you, the affected merchants and the authorities where the law requires it.

12. Your rights

Under the EU General Data Protection Regulation (GDPR) and similar laws, you have the right to:

  • access the personal data we hold about you and get a copy of it
  • correct inaccurate data
  • delete your data (see Section 9)
  • restrict or object to certain processing
  • receive your data in a portable format
  • withdraw consent at any time, where we rely on consent

To exercise these rights, email [email protected]. We will respond within one month. You also have the right to complain to a data protection authority. In Hungary this is the National Authority for Data Protection and Freedom of Information (NAIH, www.naih.hu). You may also contact the authority in your own country.

California residents: we do not sell or share personal information for cross-context behavioural advertising. You may request access to or deletion of your personal information using the contact details above, and we will not discriminate against you for exercising these rights.

13. Children

The Service is a business tool and is not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.

14. Changes to this policy

We may update this Privacy Policy from time to time. We will post the new version on this page and update the "Last updated" date. If the changes are significant, we will also notify account owners by email or in the portal.

15. Contact us

If you have questions about this Privacy Policy or your personal data, contact us at:

DRB Services Kft.
Sellő utca 6, 2000 Szentendre, Hungary
Email: [email protected]