Privacy
What we collect, why we collect it, and what we do not do with it.
If you scanned a QR code
To send you a reward we need somewhere to send it. That means a UPI ID, or a bank account number with its IFSC code and the account holder name. Depending on how the business set up the campaign, you may also be asked for your name and mobile number — each of those can be required, optional, or not asked for at all.
Your payment details are encrypted before they are stored, and are never shown back to anyone: not to you, not to the business that issued the code, and not to Kyuq staff. Everywhere a payment destination is displayed it is masked, so a UPI ID appears as something like ab****@ybl.
We also record the time of the claim, the IP address it came from and a fingerprint of the browser. That is for fraud checks —spotting the same person claiming hundreds of codes — and is not used for advertising.
Who sees what
The business that issued the code sees that a claim happened, the masked payment destination, and whatever name or mobile number the campaign asked for. They do not see your full UPI ID or account number.
Kyuq staff can see the same masked information for support and reconciliation. Staff access to a business’s verification documents is recorded in an audit log with the name of the person who opened it.
Your payment provider necessarily receives the destination in order to send the money. That is the whole point of the transaction.
If you run a business on Kyuq
We hold your business details, the people on your team, and the documents you upload to prove the business is real — a PAN card, GST certificate or similar. Those documents are stored privately and are reachable only by your own team and by Kyuq staff reviewing them.
We hold a record of your credit purchases, the codes you generate and the claims made against them. Financial records are kept for as long as tax law requires, which is why deleting an account does not erase them.
How long we keep things
Claim and payout records are kept as financial records. Deleting a business account marks it deleted and releases its identifiers for reuse, but does not remove the transactions that already happened— those are somebody else’s receipt as well as yours.
Fraud signals such as IP addresses are kept for as long as they are useful for detecting repeat abuse.
What we do not do
We do not sell personal information. We do not use claim data for advertising, and we do not build profiles of people who claim rewards across different businesses.
Asking us about your data
Write to support@example.com to ask what we hold about you or to ask for it to be removed. Where a record has to be kept for tax or fraud reasons we will say so rather than quietly refusing.
If your question is about a specific reward, the business that issued the code holds their own copy of that campaign’s data and you may need to ask them too. See the reward terms.
This policy has not been reviewed by a lawyer and the contact details are placeholders. Both must be settled before this site goes live.