Privacy Policy
We treat the privacy and personal information of customers and visitors with utmost confidentiality.
We treat the privacy and personal information of customers and visitors with utmost confidentiality.
Last updated: August 25, 2026
barKoder Ltd. ("barKoder", "we", "us" or "our") respects your privacy and is committed to protecting personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable data protection laws.
This Privacy Policy explains how we collect, use, disclose and protect personal data when you visit our website, create or use a barKoder Developer Portal account, request a trial license or quotation, purchase or use our products and services, contact us for support, subscribe to communications, or otherwise interact with barKoder.
It also explains the limited technical information processed in connection with the licensing and operation of the barKoder SDK.
The controller responsible for the processing of personal data described in this Privacy Policy is:
barKoder Ltd.
16 Lyuben Karavelov Street, Apt. 2
Sredets District, Sofia Municipality
Sofia 1142
Republic of Bulgaria
VAT ID: BG206578123
Email: contact@barkoder.com
For questions concerning this Privacy Policy or requests relating to your personal data, you may contact us using the details above.
This Privacy Policy applies to personal data processed by barKoder in connection with:
Applications developed by our customers that incorporate the barKoder SDK are separate applications controlled by those customers.
Except for the limited technical information required for licensing and service administration as described below, barKoder does not determine how customers collect, use, store or otherwise process information obtained through applications incorporating the barKoder SDK.
Customers integrating the barKoder SDK into their applications are responsible for their own compliance with applicable privacy and data protection laws.
The personal data we collect depends on how you interact with barKoder.
When you create or maintain a barKoder Developer Portal account, we may collect:
We process this information to:
Where the processing is necessary to provide services requested by you or your organization, the legal basis is Article 6(1)(b) GDPR.
Where necessary for security, fraud prevention, account administration or protection of our systems, we may rely on our legitimate interests under Article 6(1)(f) GDPR.
When you request or generate a trial license, we may process information including:
We process this information to provide the requested trial, generate and administer the applicable license, communicate with you about the trial and provide technical or commercial assistance.
The legal basis is Article 6(1)(b) GDPR, as the processing is necessary to take steps at your request prior to entering into a contract and to provide the requested trial service.
When you request a quotation, demonstration, pricing information or other commercial information, we may collect:
We use this information to:
The legal basis is Article 6(1)(b) GDPR where the processing relates to steps taken at your request before entering into a contract.
We may also retain relevant business correspondence based on our legitimate interest in managing customer relationships, maintaining commercial records and responding to subsequent inquiries under Article 6(1)(f) GDPR.
When you or your organization becomes a barKoder customer, we may process:
We process this information to perform and administer our contracts, provide licensed products and services, manage subscriptions, invoice customers and provide customer support.
The legal basis is Article 6(1)(b) GDPR.
Where information must be retained to comply with tax, accounting or other legal requirements, the legal basis is Article 6(1)(c) GDPR.
We use Stripe to process payments and provide related payment services.
When you make a payment, certain information may be provided directly to Stripe or otherwise processed through Stripe's payment infrastructure.
Depending on the payment method and transaction, this may include:
barKoder generally receives information confirming the transaction and payment status together with information necessary to administer the relevant purchase, subscription or invoice.
Stripe may process certain personal data as a processor acting on our behalf and may process other information as an independent controller where required to provide payment, fraud-prevention, regulatory or compliance services.
Payment processing necessary to fulfil a purchase or subscription is based on Article 6(1)(b) GDPR.
Processing required by tax, accounting, anti-fraud or other applicable legal obligations may also be based on Article 6(1)(c) GDPR.
When you contact barKoder by email, through the Developer Portal, through a support form or through another communication channel, we process the information you provide to us.
This may include:
Where support relates to a barKoder product, trial, subscription or customer relationship, processing is based on Article 6(1)(b) GDPR.
For general inquiries, processing is based on our legitimate interest in responding to communications and managing our business relationships under Article 6(1)(f) GDPR.
Support requests may be retained for up to three years after completion of the request where necessary to maintain support history, identify recurring technical issues and assist with subsequent requests.
Please avoid submitting personal data contained in scanned barcodes, identification documents or other sensitive materials through support channels unless such information is necessary to resolve your support request.
When you access our website, certain technical information may be processed automatically.
This may include:
IP address; date and time of access; requested URL; referring URL; browser type and version; operating system; device information; HTTP status information; and security and diagnostic information.
We use this information to:
deliver the website; maintain website security; diagnose technical problems; detect abuse and malicious activity; maintain the stability and availability of our services; and generate technical statistics.
The legal basis is our legitimate interest in operating a secure, reliable and functional website under Article 6(1)(f) GDPR.
The barKoder SDK is designed to perform barcode decoding, OCR, document parsing and related image-processing operations within the customer's application, device, browser or other environment in which the SDK is deployed.
During normal SDK scanning operations, barKoder does not collect or store the personal information contained in scanned barcodes.
Decoded barcode content is not transmitted to barKoder merely because the barKoder SDK is used to perform a scan.
Where supported functionality processes images, barcodes, MRZ data, VIN data or other captured information locally, that information remains under the control of the application in which the SDK is integrated.
The customer or application developer determines whether such information is subsequently stored, transmitted or otherwise processed by its application.
barKoder is not responsible for the privacy practices of third-party applications that integrate the barKoder SDK.
Applications incorporating the barKoder SDK may independently collect or process personal data.
The operator or developer of such an application is responsible for:
Questions concerning data collected by a third-party application incorporating the barKoder SDK should be directed to the operator of that application.
Certain barKoder licenses periodically communicate with barKoder's licensing infrastructure.
This communication is separate from the processing of barcode or document content.
It is used to:
Depending on the product, platform and licensing model, the information processed may include technical information such as:
License-validation communications are not intended to contain decoded barcode content, document data or images captured by the customer's application.
Where licensing information is necessary to provide and administer a licensed barKoder product, processing is based on Article 6(1)(b) GDPR.
We may also process limited technical licensing information based on our legitimate interests in protecting our software, preventing unauthorized use, maintaining licensing security and enforcing applicable licensing conditions under Article 6(1)(f) GDPR.
barKoder's public documentation confirms that licensed devices periodically communicate with the licensing server and that the SDK does not store personal information retrieved from scanned barcodes.
We use cookies and similar technologies on our website to operate the website and its services, remember preferences, provide optional functionality, understand how visitors use our website and, where you consent, measure the effectiveness of our marketing activities.
A cookie is a small data file stored on or accessed from your device when you visit a website. Similar technologies may include local storage, pixels, tags and other technologies that store information on or access information from your device.
We classify the cookies and similar technologies used on our website into the following categories:
Necessary cookies are required for the operation, security and core functionality of our website and services.
They may be used for purposes such as:
These technologies are used only where necessary to provide a service or functionality requested by you or to ensure the security and proper operation of our website.
Necessary cookies cannot be disabled through our cookie preference tool because the website or requested service may not function correctly without them.
Where necessary cookies involve the processing of personal data, the applicable legal basis may be Article 6(1)(b) GDPR where processing is necessary to provide a service requested by you, or Article 6(1)(f) GDPR where processing is necessary for our legitimate interest in maintaining the security, integrity and functionality of our website and services.
Functional cookies enable optional website features and allow us to remember choices you make in order to provide a more personalized or convenient experience.
They may be used, for example, to:
Functional cookies are not required for the basic operation of the website. If you do not allow these cookies, some optional features or personalized functionality may not work as intended.
Where consent is required, Functional cookies are activated only after you have selected or consented to the Functional category in our cookie preference tool.
Where personal data is processed through Functional cookies on the basis of your consent, the legal basis is Article 6(1)(a) GDPR.
Analytics cookies help us understand how visitors use our website so that we can measure its performance and improve its content, functionality and usability.
These technologies may allow us to collect information such as:
We currently use Google Analytics for website analytics.
Analytics cookies and similar technologies are activated only after you have consented to the Analytics category in our cookie preference tool, where consent is required by applicable law.
Where personal data is processed through Analytics cookies on the basis of your consent, the legal basis is Article 6(1)(a) GDPR.
You may withdraw your consent at any time through our Cookie Settings.
Marketing cookies and similar technologies are used to measure the effectiveness of advertising campaigns and, where applicable, to support advertising and conversion measurement.
These technologies may be used to:
We may use Google Ads and related Google advertising technologies for these purposes.
Marketing cookies and similar technologies are activated only after you have consented to the Marketing category in our cookie preference tool.
Where personal data is processed through Marketing cookies on the basis of your consent, the legal basis is Article 6(1)(a) GDPR.
You may withdraw your consent at any time through our Cookie Settings.
When you first visit our website, you are provided with options to manage the use of non-essential cookies.
You may:
Necessary cookies remain active because they are required for the operation or security of the website or to provide services requested by you.
Functional, Analytics and Marketing cookies remain disabled unless and until the applicable consent has been provided, except where a particular technology qualifies as strictly necessary under applicable law.
You may change or withdraw your consent at any time through the Cookie Settings available on our website.
Withdrawing consent does not affect the lawfulness of processing carried out before consent was withdrawn.
You may also configure your browser to block or delete cookies. However, disabling Necessary cookies through browser settings may prevent certain parts of our website or Developer Portal from functioning correctly.
We use Amazon Web Services ("AWS") to provide cloud hosting, infrastructure and related technical services.
Information processed through barKoder's website, Developer Portal, licensing infrastructure and other services may therefore be stored or otherwise processed using AWS infrastructure.
AWS acts as a service provider and processor in relation to personal data it processes on our behalf, subject to applicable contractual and data-protection arrangements.
We use appropriate technical, organizational and contractual measures to protect personal data processed through our hosting infrastructure.
Where processing by AWS involves an international transfer of personal data, the safeguards described in the International Data Transfers section below apply.
Further information about how AWS processes personal data is available in the AWS Privacy Notice.
We use Google Analytics to understand how visitors interact with our website and to improve the performance, usability and content of the website.
Google Analytics may process information including:
Where required by applicable law, Google Analytics is used only after you have provided consent through our cookie-consent mechanism.
The legal basis is Article 6(1)(a) GDPR.
Google Analytics information is retained in accordance with our configured analytics retention settings and applicable Google service settings. Our current analytics retention period is up to 14 months, after which information may be deleted or retained only in aggregated form, subject to Google's applicable service functionality.
For information about how Google processes personal data, please refer to Google's Privacy Policy.
You can withdraw your analytics consent at any time through our Cookie Settings.
We may use Google Ads and related conversion-measurement functionality to evaluate the effectiveness of our advertising campaigns.
Where enabled, these technologies may process information concerning:
advertising interactions; website visits; online identifiers; conversions; browser/device information; and related technical information.
Google Ads technologies requiring consent are used only after the appropriate consent has been obtained.
The legal basis is Article 6(1)(a) GDPR.
You can change or withdraw your advertising consent through our Cookie Settings.
For more information about how Google processes personal data in connection with its services, please refer to the Google Privacy Policy.
We may use Google Tag Manager to manage website tags and technologies used on barkoder.com.
Google Tag Manager primarily provides the technical infrastructure used to manage other technologies described in this Privacy Policy.
Where a tag or technology requires consent, it is intended to be activated only in accordance with the applicable consent preferences.
We use Google reCAPTCHA on certain forms and website functionality to help protect our services against automated abuse, spam, fraudulent submissions and malicious activity.
reCAPTCHA may process technical information including:
We use reCAPTCHA based on our legitimate interest in securing our website and preventing automated abuse under Article 6(1)(f) GDPR.
Where applicable law requires consent for particular storage or access to information on the user's device, we apply the relevant consent requirements.
Further information concerning Google's processing is available in Google's Privacy Policy.
We use Stripe to process payments and provide related billing and payment functionality.
Stripe may receive personal data directly from you or from barKoder where necessary to:
prevent fraud;
Depending on the processing activity, Stripe may act as a processor on behalf of barKoder or as an independent controller.
Further information concerning Stripe's processing practices is available in Stripe's Privacy Policy and Stripe Privacy Center.
Where Stripe processing involves international transfers, the safeguards described below apply.
We use external service providers where necessary to operate our business and provide our products and services.
Recipients may include providers of:
Where a service provider processes personal data solely on our behalf, we enter into appropriate contractual arrangements in accordance with Article 28 GDPR.
The use of a processor under Article 28 GDPR does not itself constitute a legal basis for processing. The legal basis applicable to the underlying processing activity is the legal basis described in the relevant section of this Privacy Policy.
We may also disclose personal data to professional advisers, auditors, financial institutions, insurers, courts, governmental authorities, regulators or law-enforcement authorities where reasonably necessary or legally required.
Some of our service providers, infrastructure providers and other recipients may process personal data outside the European Economic Area ("EEA").
Where personal data is transferred from the EEA to a country outside the EEA, barKoder uses an appropriate transfer mechanism in accordance with Chapter V of the GDPR.
Depending on the recipient and destination, such mechanisms may include:
Where the European Commission has determined that a country or recipient provides an adequate level of data protection, personal data may be transferred on the basis of Article 45 GDPR.
For transfers to eligible organizations in the United States, this may include the EU-U.S. Data Privacy Framework where the recipient maintains a valid certification covering the relevant data.
Where no applicable adequacy decision exists, we may rely on the European Commission's Standard Contractual Clauses adopted under Article 46 GDPR, including the clauses adopted by Commission Implementing Decision (EU) 2021/914.
Where appropriate, we may implement supplementary contractual, technical or organizational safeguards.
Where applicable, we may rely on another transfer mechanism permitted under Chapter V GDPR.
We periodically review the transfer mechanisms applicable to our service providers.
If an existing transfer mechanism becomes invalid or unavailable, we will take reasonable steps to implement another lawful mechanism where necessary.
You may contact us at contact@barkoder.com for further information regarding the safeguards applicable to a particular international transfer.
barKoder does not rely on the former EU-U.S. Privacy Shield as a legal basis for international data transfers.
We may disclose personal data where reasonably necessary to:
comply with applicable law; respond to a lawful request from a court, regulator or public authority; investigate suspected fraud, misuse or unlawful activity; protect the security of our systems and services; enforce our agreements and licensing terms; establish, exercise or defend legal claims; or protect the rights, property or safety of barKoder, our customers or others.
Where disclosure is required by law, the legal basis is Article 6(1)(c) GDPR.
Where disclosure is necessary to protect our legitimate business or legal interests, we may rely on Article 6(1)(f) GDPR.
If barKoder undergoes a merger, acquisition, restructuring, financing, sale of assets or another corporate transaction, information relating to customers, users or business contacts may be disclosed or transferred where reasonably necessary in connection with that transaction.
Any such processing will be carried out in accordance with applicable data-protection law and subject to appropriate confidentiality and data-protection safeguards.
The legal basis is our legitimate interest in managing and developing our business under Article 6(1)(f) GDPR.
Where you have requested marketing communications or otherwise provided the required consent, we may use your contact information to send you:
barKoder product news; product updates; technical information; announcements; educational content; offers; event information; and other marketing communications.
Where marketing is based on consent, the legal basis is Article 6(1)(a) GDPR.
You may withdraw your consent at any time by:
using the unsubscribe link contained in the relevant communication; or contacting us at contact@barkoder.com.
Withdrawal of consent does not affect processing carried out lawfully before withdrawal.
Where permitted by applicable law, we may send certain communications to existing business customers concerning similar barKoder products or services. You may object to such direct marketing at any time.
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including satisfying legal, accounting, contractual, security and reporting requirements.
Retention periods depend on the type of information and the purpose for which it is processed.
In particular:
Account information is generally retained while the account remains active and thereafter for a reasonable period necessary to administer previous licenses, comply with legal obligations, resolve disputes and maintain relevant business records.
Information concerning trial licenses, quotations and commercial inquiries may be retained for as long as necessary to respond to the request and for a reasonable period thereafter for commercial follow-up, record keeping and the establishment or defence of legal claims.
Customer, licensing and contractual information is retained for the duration of the applicable commercial relationship and thereafter as necessary to meet statutory retention requirements and applicable limitation periods.
Invoices, transaction information and related accounting records are retained for the period required by applicable tax, accounting and commercial laws.
Support communications may be retained for up to three years following completion of the support request where necessary to maintain support history and assist with recurring technical issues.
Server, diagnostic and security information is retained for only as long as reasonably necessary for security, troubleshooting, fraud prevention and service administration.
License-validation and related technical information is retained for as long as reasonably necessary to administer the applicable license, maintain licensing records, prevent abuse, resolve disputes and establish or defend legal claims.
Google Analytics information may be retained for up to 14 months, subject to our configured analytics settings and Google's applicable service functionality.
Marketing contact information is retained until you unsubscribe, withdraw consent or otherwise object to marketing, subject to retention of limited suppression information where necessary to ensure that your preference continues to be respected.
Information deleted from active systems may remain in secure backup copies for a limited period, generally up to 60 days, before being overwritten or otherwise removed through normal backup-management processes.
We may retain information for a longer period where required by law or where necessary to establish, exercise or defend legal claims.
After the applicable retention period, personal data is deleted or anonymized.
We maintain appropriate technical and organizational measures designed to protect personal data against:
unauthorized access; unlawful processing; accidental loss; destruction; alteration; and unauthorized disclosure.
Our security measures are selected according to the nature of the information processed, the risks associated with the processing and the technologies and services involved.
barKoder maintains an information security management system certified to ISO/IEC 27001:2022.
No method of electronic transmission or storage can be guaranteed to be completely secure, but we continually review and improve our security measures in accordance with applicable requirements and industry practices.
Subject to the conditions and limitations provided by applicable law, you have the following rights.
You have the right to obtain confirmation as to whether we process personal data concerning you and, where applicable, obtain access to that personal data and the information required under Article 15 GDPR.
You have the right to request correction of inaccurate personal data and completion of incomplete personal data under Article 16 GDPR.
You may request deletion of personal data concerning you in the circumstances set out in Article 17 GDPR.
The right to erasure is subject to exceptions, including where continued processing is required by law or necessary for the establishment, exercise or defence of legal claims.
You may request restriction of processing in the circumstances described in Article 18 GDPR.
Where processing is based on your consent or on a contract and is carried out by automated means, you may have the right to receive personal data you provided to us in a structured, commonly used and machine-readable format and to transmit that information to another controller in accordance with Article 20 GDPR.
Where we process personal data on the basis of our legitimate interests under Article 6(1)(f) GDPR, you have the right to object to that processing on grounds relating to your particular situation.
Where you object, we will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms or the processing is necessary for the establishment, exercise or defence of legal claims.
You have the right to object at any time to the processing of your personal data for direct marketing purposes.
If you object to direct marketing, we will no longer process your personal data for that purpose.
Where processing is based on your consent, you may withdraw that consent at any time.
Withdrawal does not affect the lawfulness of processing carried out on the basis of your consent before it was withdrawn.
Cookie consent can be changed through our Cookie Settings.
Marketing consent can be withdrawn through the unsubscribe link included in our marketing communications or by contacting us.
To exercise any of your data-protection rights, contact us at:
contact@barkoder.com
or:
barKoder Ltd.
16 Lyuben Karavelov Street, Apt. 2
Sredets District, Sofia Municipality
Sofia 1142
Republic of Bulgaria
We may request information reasonably necessary to verify your identity before acting on a request.
We normally respond to valid requests within one month, subject to any extension permitted under Article 12 GDPR.
There is normally no fee for exercising your rights. However, we may charge a reasonable fee or refuse to act where permitted by law if a request is manifestly unfounded or excessive.
You have the right to lodge a complaint with a competent data-protection supervisory authority, particularly in the EU or EEA Member State of your habitual residence, place of work or place of the alleged infringement.
barKoder's supervisory authority in Bulgaria is:
Commission for Personal Data Protection (CPDP)
2 Prof. Tsvetan Lazarov Blvd.
Sofia 1592 Republic of Bulgaria
Email: kzld@cpdp.bg
Website: www.cpdp.bg
We encourage you to contact us first if you have concerns about our processing of your personal data so that we can attempt to resolve the matter directly.
barKoder does not make decisions concerning individuals based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect them within the meaning of Article 22 GDPR.
Analytics and advertising technologies may perform statistical measurement, attribution or audience-related processing as described in this Privacy Policy, but barKoder does not use those technologies to make decisions that produce legal or similarly significant effects concerning individuals.
The barKoder website, Developer Portal and commercial SDK services are primarily intended for developers, businesses and professional users and are not directed to children.
We do not knowingly request personal data directly from children through our commercial services.
If you believe that a child has provided personal data to barKoder without an appropriate legal basis, please contact us at contact@barkoder.com so that we can review the matter and take appropriate action.
Our website may contain links to third-party websites, applications or services.
This Privacy Policy does not apply to the independent processing activities of those third parties.
We encourage you to review the privacy information provided by the relevant third party before providing personal data or using its services.
We may update this Privacy Policy from time to time to reflect:
changes to our products or services; changes to our data-processing activities; changes to service providers; technological developments; legal or regulatory requirements; or changes to our business operations.
When we update this Privacy Policy, we will revise the "Last updated" date displayed at the top of the policy.
Where changes materially affect how we process personal data, we will provide additional notice where required by applicable law.
If you have questions about this Privacy Policy, our processing of personal data or your data-protection rights, please contact:
barKoder Ltd.
16 Lyuben Karavelov Street, Apt. 2
Sredets District, Sofia Municipality
Sofia 1142 Republic of Bulgaria
Email: contact@barkoder.com
Telephone: +389 70 243 120
To fully experience the speed and accuracy of the Barcode Scanner SDK on your Android or iOS device, simply head to your preferred App Store by clicking on the respective button, or scan the QR Code with your camera.
Optimizing your experience with our app is effortless using our comprehensive Barcode Scanner SDK testing sheet,
encompassing a variety of 1D and 2D barcode types.
Simply print or display the sheet on your device, and proceed to scan each barcode using our demo app. This efficient testing method ensures that our app seamlessly recognizes and processes diverse barcode formats, assuring you of its reliability and versatility across different code types.