Skip to content

AVRA product

AVRA Signal: Scan Data

Every scan, counted and placed — including the ones that should not have happened.

01 /Overview

What your labels did after they left the factory.

Once a unit leaves the gate, a brand that sells through distribution normally knows two things about it: that it was dispatched, and that it has not come back. Every scan of an AVRA label writes a row — when, what verdict, from roughly where, in what language the phone asked for the page, and whether a camera or a forwarded link opened it.

Signal is what those rows become. Counts and a thirty-day series. A live feed. Two maps, one exact and one approximate, and each says which of its data it could not place. Three named alerts with stated thresholds. And a read-only link you can hand to a distributor or a lawyer without giving them a login.

It is included with every batch. There is no separate charge and nothing to upgrade to.

named alert rules, with stated thresholds
3
maps — one exact, one approximate
2
third-party trackers on the scan page
0
days until IP, user agent and device token are reduced
30 / 90 / 400
Personal data on a scan row, by dayDay 0: Scan written: the full IP, the user-agent string and the device token. Day 30: The IP is truncated to its network prefix (a /24). Day 90: The user-agent string is reduced to the browser family. Day 400: The device token is cleared — its cookie lived a year. The row itself stays for ever, holding no personal data.0123day 0day 30day 90day 400
  1. day 0 — time · verdict · code · IP · user agent · approximate city · language · camera or link · device token
  2. day 30 — the IP becomes a /24 network prefix. The clone-attack rule counts distinct networks, so it loses nothing.
  3. day 90 — the user agent becomes a browser family.
  4. day 400 — the device token is cleared. Its own cookie only lived a year.
FIG 4.1One scan, and what it stops being. Personal fields a scan row still holds, by day. The row itself stays for ever — it is the product, and by day 400 it holds no personal data.

02 /How it works

Three rules, two maps, one link.

  1. Every scan writes one row.

    Time, code, verdict, an approximate city resolved offline from the IP at scan time against a local database — never a lookup to a third party, never coordinates — the first language tag the browser asked for, and one bit recording whether a referrer was present. The referrer itself is never stored, because the URL a buyer came from can name a private group chat and the useful signal is one bit: a camera app sends no referrer, so a scan that has one was forwarded, pasted or embedded.
  2. Three rules run continuously.

    Each one has a stated threshold and a name, listed below.
  3. Two maps, and neither one lies.

    The pincode map is exact, because a human typed the pincode into a reward claim or a warranty registration; it is drawn by state, from the postal circle, beside a list of the busiest pincodes. The scan map is approximate and stops at the state, because Indian carrier-grade NAT puts a Nashik scan on Mumbai's gateway — the wrong city and the right state. Both report what they could not place, on the map itself rather than in a footnote.
  4. Consumers can report a fake, and the report lands on the right desk.

    A photo, a location, a shop name and a phone number the reporter consented to give. The report belongs to the brand whose code was scanned and is worked by the partner who prints its labels: reviewing, confirmed, dismissed, all audited. The reporter's phone is erased after 90 days.

The three alerts

The three alert rules, when each fires and what it usually means
AlertFires whenWhat it usually means
Clone attackOne code is claimed past its limit from three or more distinct networks in a weekCopies of one label are in circulation
Print-file leakTen or more of your own not-yet-activated labels are scanned in a weekThe print file or a roll left the building. QC test scans are normal; ten different labels are not
Fake sightingCodes that were never issued by anyone are being scannedSomebody is printing codes that look like ours. Routed to AVRA, then to the brand it concerns
The scan map and the pincode map compared
Scan mapPincode map
Built fromThe IP behind each scanPincodes a person typed on a reward claim or a warranty registration
PrecisionApproximate — state onlyExact — then drawn by state, from the postal circle
ZoomCapped at 4×, on purposeThe busiest pincodes are listed beside the map
What it could not placeCounted as unknown, on the mapA pincode that is not six digits is counted as unplaced, never guessed
FIG 4.2The two maps. A map that is confidently wrong is worse than no map. We show both rather than averaging them into one convincing lie.

03 /What your team sees

One screen, and a link you can send to somebody without a login.

The dashboard carries the alerts, the genuine rate, the thirty-day series, scans by city, the two maps and the live feed.

The share link is unguessable, read-only, rotatable and revocable — rotate it and the old link dies at once. It carries no personal data at all. It exists because the people who most need to see this — a distributor being asked a hard question, a lawyer preparing a notice, a retail chain's compliance desk — are exactly the people you do not want to give a console login.

The Purchases view

Where rewards or warranty are running, a second view aggregates what buyers told you: the trade-versus-consumer split, the top ten pincodes, the top ten shops, the price band actually paid, the camera-versus-forwarded split and the languages asked for.

Two rules govern that screen. Every figure carries its denominator, because “100% trade” over two answers is not a finding. And a rejected or voided claim is not a distribution fact — somebody decided it was not real, so its pincode does not move the map.

The only thing a consumer sees of Signal is the report form: one tap from a suspicious verdict, a photo, where they bought it, and a number to reach them on. It is the cheapest sensor network in this business and the only one that tells you about a fake you never printed a label for.

04 /Where it fails

What this data is not.

A scan is not a sale.

It is somebody pointing a phone at a label. Scan counts correlate with distribution and with consumer curiosity, and they are not a sell-through number. Anyone who tells you otherwise is selling a dashboard.

The scan map is approximate, and we cap the zoom on purpose.

Carrier-grade NAT means a scan's city is normally wrong rather than occasionally wrong. We roll up to the state and stop there. A brand that could zoom to a street would open a counterfeit investigation into a distributor who did nothing.

The alerts are rules, not intelligence.

Three deterministic thresholds, stated above. They will miss a patient counterfeiter who claims one code a week from a different network, and they will occasionally fire on a legitimate oddity. They are honest and they are auditable, which we prefer to anomaly detection nobody can question.

There is no supply chain here.

No aggregation to carton or pallet, no distributor check-in, no shipment events. Signal tells you where a label was scanned, not where a carton was sent. If you need to know which distributor received which batch, that is track and trace and it is not built.

Not every unit is scanned.

A realistic consumer scan rate is in low single-digit percentages, so every map on this page is drawn from a sample. Read it as a sample.

Personal data does not stay.

By day 30 the IP is a network prefix, by day 90 the user agent is a family name, by day 400 the device token is gone. If you need raw IPs for an investigation, run the export inside thirty days.

No consumer marketing, from us.

No segments, no campaigns to buyers, no email or WhatsApp blasts to people who scanned. The data is yours to act on; the tooling to act on it is not part of Signal.

05 /Integration

None. It is already on.

Signal is not configured, purchased or switched on. Every batch that verifies produces it. The only setup decisions are who on your team gets a login (each brand gets one, invited by email and activated with a WhatsApp OTP) and whether you want a share link to hand out.

There is no export API and no BI connector. Exports are files, and a CSV that a person downloads is audited.

06 /What it costs

Nothing extra.

Included with every label. There is no per-scan charge, no analytics tier, no seat price and nothing behind a paywall on this page. Consumer scans are free and always will be, for a reason that is more practical than generous: charging per scan would give a brand a reason to want fewer scans, and fewer scans is the opposite of what this product is for.

We reserve a fair-use ceiling to protect against bot traffic against a brand's codes, and we will call you before we ever apply it.

What decides your rate →

07 /Questions

Questions.

Who owns the scan data?

You do. AVRA processes it on your behalf, does not resell it and does not use it for anyone else. A partner sees only the brands it serves. This is a sentence no competitor site we reviewed has written, and it is worth putting in the contract as well as on the page.

How accurate is the location?

The scan map is approximate: a city resolved from an IP against a local database, rolled up to the state and zoom-capped there, because India's carrier NAT makes city-level claims unreliable. The pincode map is exact, because a person typed it. We show both instead of averaging them into one convincing wrong answer.

Do you track consumers?

No. There is a first-party cookie set on a genuine verdict, so a buyer re-scanning their own label is greeted rather than accused; the cookie lasts a year and the token is cleared from our records after 400 days. We deliberately do not collect precise location on arrival, viewport, device memory, canvas, WebGL, fonts, or date of birth. We record the first language tag and one bit saying whether a referrer existed. That is the list.

Can I get the raw scan log out?

As a file, from the console, audited. There is no API and no direct database access. If you need raw IPs, take the export inside thirty days — after that the IP is a network prefix.

What is a “genuine rate”, exactly?

The share of decisive verifications that returned GENUINE. A Dual Code shelf scan answers VALID and is not decisive, so it is not counted either way — including it would flatter the number.

Does a consumer fake report reach me?

It lands on the brand that owns the code and is worked by the partner who prints your labels. New reports ride the alert feed; confirmed ones count on your dashboard and as a bare number on the public share link — never the details, and never the reporter's phone, which is erased after ninety days.

What if someone scans a code that was never ours at all?

That raises a fake-sighting alert to AVRA, because no brand owns a code that was never issued. If the reporter tells us what the pack said, we route it to the brand it concerns. It is the only way to learn about a counterfeiter who did not bother copying your label.

Can I share this with a distributor without giving them a login?

Yes — that is what the share link is for. Read-only, unguessable, no personal data on it, and revocable in one click.

Print one batch and scan it yourself.

The fastest way to judge this is a sheet of real labels and a phone.

Trust, made visible.

connect@avrascan.com · +91 91737 47583 · Navacara Infotech, Ahmedabad, Gujarat, India