Privacy Policy
Effective Date: January 1, 2026 • Last Updated: September 2026 • Compliant with DPDP Act 2023 (India), GDPR (EU 2016/679), and CCPA/CPRA
1. Commitment to Privacy & Regulatory Compliance
At Bio Manager, operating under the domain miqr.in, we believe privacy is a fundamental human right. As a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (India) and a Data Controller under the General Data Protection Regulation (EU) 2016/679 (“GDPR”), we are committed to processing personal data transparently, securely, and lawfully.
This Privacy Policy explains the categories of personal and non-personal data collected when you register an account, publish a profile, scan a miqr.in QR code, or view a public creator link, as well as the cryptographic safeguards and rights you retain over your information.
2. Categories of Personal Data Collected
We adhere to strict data minimization principles. We collect only what is strictly necessary to deliver our services:
Account & Profile Information
- Registration Credentials: Email address, cryptographically hashed passwords (salted with bcrypt/Argon2). We never store plaintext passwords.
- Public Profile Details: Display name, chosen handle (
miqr.in/username), avatar image URLs, bio biography text, and verification badges. - Outbound Links: URLs, link titles, subtitles, card dimensions, and icons chosen by you to display on your public profile.
- Social Network Links: Usernames or URLs corresponding to connected platforms (e.g. YouTube, GitHub, Twitter, WhatsApp).
Telemetry & Analytics Data
- Privacy-First Aggregated Metrics: When a user visits
miqr.in/usernameor clicks a link, we increment view and click counters. - No PII in Analytics: We do NOT tie visitor IP addresses to link clicks. Analytics events record high-level device types (Mobile, Desktop, Tablet) and anonymized referrer domains.
- Audit Logs: For account security, administrative actions (logins, password modifications) log timestamp and IP address to detect unauthorized access attempts.
3. Lawful Bases for Processing Data
Under international and Indian data protection statutes, we process your personal data solely under the following legal bases:
- Performance of Contract: Processing necessary to maintain your account, route your vanity URL, generate your miqr.in QR code, and render your bio link.
- Consent: Given freely when you register, configure optional profile fields, or request notifications. You may withdraw consent at any time through account settings.
- Legitimate Interests: Protecting the platform against automated scraping, cyber-attacks, distributed denial of service (DDoS), and credential stuffing.
- Compliance with Statutory Legal Obligations: Preserving records when required under Indian law or lawful judicial summons.
4. Absolute Prohibition of Data Selling & Zero Advertising Trackers
Our Privacy Pledge: No Third-Party Ad Brokers
Bio Manager does NOT sell, rent, monetize, or trade your personal data, profile visitors’ telemetry, or click patterns to third-party data brokers, advertising networks, or programmatic marketing exchanges. We do not inject tracking pixels (such as Meta Pixel or TikTok tracking SDKs) into your public profile pages.
5. Enterprise Data Security & Cryptographic Safeguards
We implement industry-leading technical and organizational security measures to shield your data from accidental loss, unauthorized destruction, alteration, or interception:
- Encryption in Transit: All HTTP traffic to miqr.in is strictly enforced over Transport Layer Security (TLS 1.3 / HTTPS) with HTTP Strict Transport Security (HSTS) preloaded.
- Encryption at Rest: Database volumes and backups are encrypted utilizing AES-256 standard encryption.
- Credential Protection: Passwords are protected via multi-round adaptive cryptographic hashing functions. Salted tokens are never decipherable in plaintext.
- Hardened Session Cookies: Tokens are stored exclusively in
HttpOnly,SameSite=Strict, andSecurecookie headers, eliminating client-side JavaScript access and mitigating cross-site scripting (XSS) session interception. - Content Security Policy (CSP): Strict headers prevent cross-site scripting, framing attacks, and unauthorized external resource injection.
6. Your Statutory Rights under DPDP Act 2023 & GDPR
You maintain extensive legal rights concerning your personal data held by Bio Manager:
7. Data Retention & Deletion Schedules
We retain personal data only for as long as your account remains active or as required to fulfill technical, operational, and legal obligations:
- Active Accounts: Profile data, links, and styling parameters are retained continuously while your account remains active.
- Account Deletion: Upon receiving an authenticated request for deletion, all personal data is purged from production databases within seven (7) business days. Rolling cryptographic server backups are overwritten within thirty (30) days.
- Security Audit Logs: IP and session metadata stored in audit records are automatically purged after ninety (90) calendar days.
8. Cross-Border Data Transfers
In delivering high-availability edge services across global points of presence (PoPs), personal data may be processed on servers located outside of your immediate country of residence. All international transfers are conducted strictly pursuant to Chapter III (Section 16) of the Digital Personal Data Protection Act, 2023 (subject to Central Government notifications) and Chapter V of the GDPR utilizing European Commission approved Standard Contractual Clauses (SCCs).
We mandate that all third-party cloud infrastructure providers (such as edge CDN nodes, object storage providers, and encrypted database clusters) maintain rigorous SOC 2 Type II, ISO 27001, and GDPR certifications to ensure uniform data protection standards regardless of geographic location.
9. Specific Disclosures for California Residents (CCPA / CPRA)
Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), California residents are entitled to specific disclosures regarding the collection, use, and disclosure of personal information:
- Notice of Collection: In the preceding 12 months, we have collected identifiers (email address, handle), internet or network activity (device type, referrer domain), and commercial information (subscription status).
- Do Not Sell or Share Personal Information: Bio Manager has NOT sold or shared personal information of any consumer (including minors under 16 years of age) to third parties for monetary or cross-context behavioral advertising in the preceding 12 months.
- Right to Non-Discrimination: We will never deny services, charge differing prices, or provide a substandard quality of service because you exercised any of your rights under the CCPA/CPRA.
- California “Shine the Light” Disclosures: California Civil Code § 1798.83 permits California residents to request details regarding disclosure of personal data to third parties for direct marketing purposes. We disclose zero personal data to third parties for direct marketing.
10. Children’s Online Privacy Protection
Protecting the online privacy of minors is of paramount importance. Bio Manager is not directed to children under the age of 13. In accordance with the Children’s Online Privacy Protection Act (COPPA) and Section 9 of the Digital Personal Data Protection Act, 2023 (processing of personal data of children), we do not knowingly collect or solicit personal information from children under the age of 18 without verifiable parental consent.
If we discover that a child under the age of 18 has established an account without verifiable parental consent, we will immediately initiate the deletion of their personal information and terminate the associated handle. Parents or guardians who believe a child has provided us with personal data may contact us at privacy@miqr.in.
11. Data Protection Officer (DPO) Contact
For any questions, data subject access requests (DSAR), or privacy inquiries regarding our platform, please reach out to our Data Protection Office:
Data Protection Officer: Data Privacy Desk
Platform: Bio Manager (miqr.in)
Official Inquiries: privacy@miqr.in
Response Turnaround: Typically within 48 business hours