PRIVACY POLICY

This Privacy Policy explains how ESSA STUDIO, MCHJ (“Company”, “we”, “us”, “our”) collects, uses, discloses, and otherwise processes information when you use our mobile application “QR Code Reader, Barcode Scan” (also referred to as “BarScanner” or the “App”), our website [https://barscanner.codes](https://barscanner.codes/), and related services (collectively, the “Services”).
If you have questions, contact us at:
Email: support@captain.show

1) SUMMARY (KEY POINTS)

• We provide scanning (QR/barcodes), code generation, scan history/export, and product/price lookup (including via third parties such as eBay, Sovrn, and Barcode Lookup). • We use analytics, attribution, crash reporting, experimentation, subscriptions, and advertising/measurement partners: AppsFlyer, Mixpanel, Sentry, Google Firebase, RevenueCat, Statsig, Meta, TikTok, and advertising platforms such as Google Ads and Meta Ads. • When you tap an external “offer” or “buy” link, we may use affiliate link technology (e.g., Sovrn). Affiliate tracking occurs ONLY after your affirmative click. • You can limit or opt out of certain tracking via device settings (and in-app settings where available). You can also use Sovrn’s opt-out tools (links below).

2) INFORMATION WE COLLECT

We collect information in three ways: (A) information you provide, (B) information collected automatically, and (C) information from third parties. A. Information you provide Depending on how you use the App, you may provide: • Scan Inputs / Content: The QR code or barcode content you scan (which may include URLs, text, contact details, etc.). By default, scan and generation history is stored on your device. If you choose to export/share your history, that content is shared by you through your device’s sharing tools. • Generated Code Content: The text/URL/data you enter to generate a QR code or barcode. • Photos (Photo Search): If you use photo-based product search, you may provide images. We process images to provide the feature. • Support Communications: If you contact support, you may provide your email address and the content of your message, and you may choose to share diagnostics. B. Information collected automatically (Device/Usage/Diagnostics) When you use the Services, we (and our service providers) may automatically collect: • Device identifiers and app identifiers (e.g., device model, OS version, language, app version). • Network and approximate location information (e.g., IP address; coarse location inferred from IP). • Advertising identifiers (e.g., IDFA on iOS with permission; GAID on Android) and attribution identifiers (e.g., AppsFlyer ID). • Usage data (e.g., events such as “scan initiated”, “scan success”, “offer viewed”, “offer clicked”, feature usage, screen views, timestamps). • Diagnostics and crash data (e.g., crash logs, performance data, error traces). C. Information from third parties We may receive information from: • App stores and subscription platforms (Apple App Store / Google Play / RevenueCat) such as subscription status, purchase timestamps, and transaction identifiers. • Advertising and measurement partners (e.g., Meta, TikTok, Google Ads) such as campaign attribution signals (e.g., which campaign led to an install or event).

3) HOW WE USE INFORMATION

We use information to: • Provide core functionality (scan QR/barcodes, generate codes, show history/export). • Provide product lookup and price/offer discovery when you request it. • Operate subscriptions and paywalls (validate entitlement, prevent fraud, provide access to premium features). • Improve the app (analytics, debugging, performance monitoring, feature experimentation/A-B testing). • Measure marketing performance and attribution (e.g., which campaigns drive installs and subscriptions). • Provide and measure advertising (where applicable) and prevent fraud/abuse. • Comply with legal obligations and enforce our terms.

4) PRODUCT LOOKUP, PRICE COMPARISON, AND EXTERNAL OFFERS

When you use product/price features, we may send limited data to third-party providers to fulfill your request: • eBay: to retrieve listings/offers relevant to a product identifier or keywords. • Barcode Lookup: to retrieve product details associated with UPC/EAN/GTIN (subject to their terms). • Other providers used for search/recognition (if applicable). This may include the scanned barcode value (e.g., UPC/EAN/GTIN), query keywords, and technical information required to complete the request (e.g., IP address, device/app metadata). We do not control third-party sites, and their privacy practices apply when you leave our Services.

5) AFFILIATE LINKS (SOVRN) – IMPORTANT DISCLOSURE

We may earn a commission when you click an external merchant link and make a purchase. Some outbound links are “affiliate links.” A. What triggers affiliate tracking / affiliate cookies Affiliate tracking (including the placement of affiliate cookies or similar tracking technologies by third parties) occurs ONLY after you take an affirmative action, such as tapping an outbound offer (“Buy”, “View Offer”, “Shop”, or similar) in the App. We do NOT trigger affiliate tracking merely because the App is installed, open, or running in the background. B. Sovrn as an affiliate technology provider We may use Sovrn to generate or redirect affiliate links and attribute commissions. When you click an affiliate link, Sovrn (and/or the merchant) may process certain technical data to enable link redirection and attribution, such as: • IP address • device/browser information and user agent • timestamps • link identifiers and referral/source identifiers C. Sovrn opt-out tools You can opt out of Sovrn Commerce affiliate tracking using Sovrn’s tools: • Sovrn Privacy Center: https://www.sovrn.com/privacy-policy/policy-center/ (see “Disable Commerce affiliate marketing tracking”) • Sovrn Privacy Policy: https://www.sovrn.com/privacy-policy/privacy-policy/ Note: Opt-out choices may be device/browser specific and may require repeating if you clear cookies or change devices.

6) ANALYTICS, ATTRIBUTION, CRASH REPORTING, EXPERIMENTATION, AND SUBSCRIPTIONS

We use the following categories of partners (examples listed; your exact configuration may vary): A. Attribution and marketing measurement • AppsFlyer (attribution/measurement and fraud prevention signals) • Meta and TikTok (measurement/attribution, where implemented) These partners may receive device identifiers (including advertising IDs where permitted), app events (e.g., install, subscription events), and related technical data to measure marketing performance. B. Product analytics • Mixpanel • Google Analytics (e.g., Firebase Analytics, and potentially other Firebase services) These partners help us understand feature usage and improve the product. C. Crash reporting and diagnostics • Sentry • Firebase Crashlytics (if enabled) These tools collect crash logs and device/app context to help us fix bugs. D. Feature flags / A/B testing • Statsig Used to test and roll out features and measure impact. E. Subscriptions and entitlements • RevenueCat Used to manage subscription status, paywall entitlements, and purchase validation.

7) ADVERTISING AND AD NETWORK DATA SHARING

We may share certain identifiers and event data with advertising networks and platforms such as Google Ads, Meta Ads, and TikTok Ads for: • attribution (which ad led to install/purchase), • measurement (campaign performance), • and (where applicable) targeted advertising. Your choices: • iOS: You can control App Tracking Transparency (ATT) permissions in iOS Settings. If you do not allow tracking, the IDFA will not be available to apps in the standard way. • Android: You can reset or limit your advertising ID in Android settings. • You may also be able to limit ad personalization through Google/Meta/TikTok account settings (where applicable).

8) HOW WE SHARE INFORMATION

We may disclose information: • To our service providers and processors (analytics, attribution, crash reporting, subscriptions, experimentation) who process data on our behalf. • To advertising partners for measurement and (where applicable) targeted advertising. • To affiliate technology providers (such as Sovrn) when you click outbound affiliate links. • To comply with law, respond to lawful requests, protect rights and safety, and prevent fraud/abuse. • In connection with a business transfer (e.g., merger, acquisition, asset sale), subject to applicable law. We do not share your information with third parties for their own marketing purposes unless described in this policy or with your consent.

9) COOKIES AND SIMILAR TECHNOLOGIES

The App itself may not use “cookies” in the same way a website does, but when you open third-party webpages (e.g., in an in-app browser or external browser), those pages and affiliate technology providers may use cookies or similar technologies. Affiliate cookies are generally placed only after you click an outbound merchant link, as described above.

10) DATA RETENTION

We retain information for as long as reasonably necessary to: • provide and maintain the Services, • comply with legal obligations, • resolve disputes, • enforce agreements, and • prevent fraud/abuse. Retention depends on the type of data and the purpose. For example, diagnostics data may be retained for shorter periods than subscription records. Where possible, we apply retention limits in the relevant tools.

11) SECURITY

We use reasonable administrative, technical, and organizational measures designed to protect information. However, no system is 100% secure. Use the Services at your own risk.

12) INTERNATIONAL DATA TRANSFERS

Our service providers may process information in countries other than your own, including the United States. Where required by law, we use appropriate safeguards for cross-border transfers (such as standard contractual clauses or equivalent mechanisms).

13) YOUR PRIVACY RIGHTS AND CHOICES

A. General choices • Limit advertising tracking via iOS/Android settings (ATT / advertising ID controls). • Uninstall the App to stop further collection from the App (note: third-party opt-outs may still be needed). B. EEA/UK/Switzerland (GDPR/UK GDPR) Depending on your location, you can: • request access, correction, deletion, or portability, • object to or restrict certain processing, • withdraw consent where processing is based on consent. To exercise rights, contact us at support@captain.show with the subject “Privacy Rights Request”. You also have the right to lodge a complaint with your local supervisory authority. C. United States (state privacy laws, where applicable) Depending on your state, you may have rights to access, delete, correct, and opt out of certain processing. Under some laws, sharing identifiers with ad/measurement partners may be considered “selling” or “sharing” of personal information for cross-context behavioral advertising. To exercise rights, contact us at support@captain.show with the subject “Privacy Rights Request”.

14) CHILDREN

The Services are not intended for children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided information, contact us and we will take appropriate steps.

15) CHANGES TO THIS POLICY

We may update this Privacy Policy. If we make material changes, we will take reasonable steps to notify you (e.g., in-app notice).

16) CONTACT US

Email: support@captain.show
Privacy page: [https://barscanner.codes/privacy](https://barscanner.codes/privacy)
Terms Of Use: [https://barscanner.codes/termsofuse](https://barscanner.codes/termsofuse)