App name: ZZZ QRPoint
Platform: iOS
This policy explains what information "ZZZ QRPoint" (the "App") handles and how it is used. Please read it before using the App.
1. Overview
The App is a serverless shop point-card app that turns paper stamp cards into a smartphone app. Points are exchanged solely by displaying QR codes on screen and scanning them with the camera between the shop's device and the customer's device. No account registration or login is required.
All content you handle in the App (shop name, reward definitions, device signing keys, card point balances, and transaction history) is stored on the devices themselves. We operate no server, and none of this content is transmitted to or collected by the developer or third parties.
The App performs no analytics. To sustain operations, the App may display banner ads served by a third-party ad provider on the Shop screen and the My Cards screen. Internet access is used only for serving/displaying ads and for fetching the logo image URL configured by the shop (see "6. Third-party services").
2. Information handled on the device
2.1 Shop profile (shop mode)
- The shop name, reward definitions, logo image URL, and grant rules you enter in Settings
- The shop name, rewards, and logo URL are included in the card-issue QR code and stored on customers' devices that scan it
- No real name, phone number, or email address is requested
2.2 Device signing keys
- The App automatically generates an Ed25519 key pair on the device for signing and verification
- The shop key signs every QR code the shop issues (card issue, point grant, redemption, settlement) to prevent impersonation and tampering; customers generate a per-card key to sign their card QR
- Private keys are stored only in the device's secure storage (Keychain / Keystore) and never leave the device. Only public keys are shared via QR codes for signature verification
2.3 Card balances and history (customer mode)
- Cards per registered shop (shop name, logo, rewards, point balance) and the history of grants/redemptions are stored in a local database on the device
- History is used to display balances and to prevent the same QR code from being scanned twice
- The shop's device does not keep per-customer balances; balances exist only on the customer's device
3. Purposes of use
- Registering shop cards by scanning the shop's card-issue QR
- Generating and verifying QR codes for point grants, reward redemption, and settlement
- Signing and verifying QR codes (authenticity of the issuer and integrity of the content)
- Storing and displaying point balances and history on the device
- Preventing double grants/deductions from re-scanning the same QR code
4. Where information is stored
- ✅ Stored only in the App's private storage on your device (private keys in secure storage)
- ✅ Card content (shop name, rewards, logo) is also stored on customer devices that scan the card-issue QR
- ❌ No transmission to any server operated by the App's developer (no such server exists)
- ❌ No cloud backup
- ❌ No mechanism for the developer to access your data
5. About QR code exchange
- Every QR code (card issue, grant, redemption, settlement) is signed with the issuer's private key and verified by the receiver; QR codes with invalid signatures are discarded
- Point-related QR codes expire in about 30 seconds and each can be used only once (duplicate prevention)
- QR codes shown on screen can be seen and photographed by people nearby. Do not include information you want to keep private in the printed card-issue QR
6. Third-party services
6.1 Advertising
To sustain operations, the App may display banner ads served by a third-party ad provider on the Shop screen and the My Cards screen. To serve ads, the ad provider may collect and use advertising identifiers (IDFA, etc.) and device information. See the ad provider's privacy policy for details.
Your App content (balances, shop names, keys) is never sent to the ad provider.
6.2 Logo image fetching
The App downloads the logo image once from the https URL configured by the shop and caches it on the device. This request goes to the image host the shop chose (e.g., the shop's website). Subsequent displays use the cache with no network access.
6.3 Services NOT used
- ❌ Analytics tools
- ❌ Crash reporting tools
- ❌ User authentication / login / accounts
- ❌ Any backend server operated by the App's developer
- ❌ In-app purchases (none at present)
7. Required permissions
| Permission | Purpose |
|---|---|
| Camera | Used only to scan QR codes (card issue, grants, redemption, settlement). Camera images are never stored or transmitted |
| Internet | Used only for serving/displaying ads and fetching the shop logo image URL. Point exchange itself happens via QR codes only, and your App content is never sent to the internet |
You can revoke these permissions at any time in the device settings. The App does not request microphone, location, contacts, or photo permissions.
8. Deleting your data
- In customer mode, you can delete a card from the card detail screen (its points, history, and cached logo are removed)
- Uninstalling the App permanently deletes all data it stored on the device (keys, shop profile, cards, balances, history, logo caches)
- Cards stored on customers' devices are deleted by the customers' own delete operations
9. Security
Every QR code carries an Ed25519 digital signature, verified by the receiver for issuer authenticity and content integrity. The shop's public key received at card registration is pinned on the device and used for later verification. Point-related QR codes expire in about 30 seconds, and reuse of the same QR code is rejected by recording transaction IDs (UUIDs).
Please also understand the limits: point exchange is intended as a simple in-store stamp card. Do not use it to manage money or anything equivalent to legal tender or electronic money.
10. Children's privacy
The App has no server that collects or stores personal information. It is not directed at children under 13 and does not knowingly collect personal information from children under 13. If children use the App, we recommend doing so under parental guidance.
11. Changes to this policy
This policy may change without notice. Important changes will be announced together with app updates.
12. Contact
For inquiries about this policy, please use the store page where the App is distributed.