Privacy notice v3
What we collect,
and what we don't.
Version v3, in force 15 September 2026, under India's Digital Personal Data Protection Act, 2023. The version you agreed to is recorded against your membership, so we can always say what you were told. If we change anything material here, we publish a new version and ask you again.
What a scan records
There is no moment before a scan in which to ask you, and you scanned the code to get an answer. So this is a notice, not a gate — the verdict page carries one line linking here. There is no cookie banner because there is one cookie: first-party, strictly functional, and described below.
- The code, the time, and your IP address.
- An approximate city derived from that IP against an offline database. City level only — never coordinates.
- Your browser's user-agent, and the language it asks for.
- Whether the scan arrived from a camera or from a link somebody sent you — a forwarded link is a counterfeit signal.
- When a code verifies as GENUINE: a random identifier in your browser, kept a year, so re-scanning your own product keeps saying “verified by you” on any network. It contains nothing about you and is sent only to this site.
If you join a brand's rewards programme
This one needs your consent, and this is what you are agreeing to.
- Your mobile number, verified by a one-time code, becomes your AVRA identity. It works across every brand on AVRA, so you have one wallet.
- The brand sees your number in a masked form, your rewards, and what you tell us about where you bought this. The partner who prints the brand's labels may administer the programme for them.
- We keep your reward and payout records for 8 years, because tax law says so. You can close your account any time — your profile goes, those records stay.
- Rewards are for adults only; a UPI payout needs your own bank account.
If you report a fake
What you type goes to the brand, and to the partner who prints its labels if the brand uses one, so that somebody can investigate it. Your phone number is optional; if you give one it is erased after 90 days.
What we never ask for
Not your date of birth, your age, your address, your email (unless a brand asks and you tick a second box), or your name beyond what a UPI payout needs. A mobile browser cannot give us your phone number, your IMEI, your SIM, your contacts, a stable device id or your advertising id — and we do not fingerprint your device. That last one is a choice, not a limitation: our counterfeit signal is a property of the code — one code seen from many networks — which needs no identity at all.
- We do not sell your data.
- We do not market to you without a separate tick.
How long, per thing
| What | Kept | Then |
|---|---|---|
| Scan: the full IP address | 30 days | truncated to the network prefix — the counterfeit rule counts networks over a week, and a prefix serves it |
| Scan: the user-agent string | 90 days | reduced to the browser family |
| Scan: the browser identifier | 400 days | cleared (the cookie itself lasts a year) |
| Scan: the row | for ever | it holds no personal data after the two sweeps above |
| A fake report: your phone number | 90 days | erased |
| Rewards, redemptions, payouts | 8 years | financial record |
| Your profile (name, UPI id, PAN) | until you close the account | erased on close |
These sweeps run on our worker every day. They are a job, not a promise on a page.
Your rights
Ask us to delete your personal data through the customer-care contact on the product page, or at connect@avrascan.com. You can close your account from the Account page: the profile is erased immediately, and the financial records above stay for as long as tax law requires. The same contact is our grievance contact.
Transfers outside India
We process your data in India. A brand may download a statement of its own payouts, and if that brand's group is outside India, the brand — not AVRA — becomes responsible for that transfer. Those statements carry masked phone numbers and no PANs.
How we count visits to this website
We run our own copy of Umami, an open-source analytics tool, on the same server as this site. Nothing about your visit is sent to Google, Meta, LinkedIn or anyone else — the only server your browser talks to is ours. We record the page you looked at, the address of the page that linked you here (browsers usually trim it to the site's domain), your screen size, your language, your approximate location — country, region and city, looked up from your IP address — and the family of your browser, operating system and device.
We do not set a cookie and we do not store your IP address. A session identifier — a one-way hash of your IP address, your browser string and a value that changes at the start of every calendar month — groups your visits within that month. It cannot be turned back into your IP address, and it is not carried from one month to the next. That is why this site has no cookie banner.
We do not run this on the pages that matter most. The verification pages — /s/…, /verify and your rewards pages — load no analytics of any kind. A page whose job is to tell you whether the thing in your hand is genuine should ask your phone for nothing else.
If we ever add a conversion pixel for a paid campaign, it will load on the contact page only, after you have submitted the form, and it will be listed here the same day.
IP geolocation data by DB-IP (db-ip.com), CC BY 4.0. Earlier versions of this notice are kept in our repository at docs/notices/.