Logotip de Label Codes Label Codes
Blog
search
English Español Français Português Română Deutsch Italiano Nederlands العربية עברית Русский Türkçe Bahasa Indonesia 简体中文 हिन्दी 日本語 한국어 Tiếng Việt বাংলা Polski ไทย Українська Bahasa Melayu Filipino فارسی தமிழ் Svenska Ελληνικά Čeština Magyar Dansk Suomi Norsk Català
No s’ha trobat cap idioma
design_services Crea etiquetes
language

Authoritative English version. To keep every public notice accurate while translations are prepared, this legal document is currently provided in English. The English version controls except where mandatory law requires otherwise.

Legal

Privacy Policy

What Label Codes processes across the website, web label designer, project transfers, and mobile apps—and the choices you have.

calendar_todayEffective August 22, 2026 verified_userVersion 2.0

At a glance

Privacy, in plain language

devices

Mostly local

Spreadsheet parsing, label rendering, downloads, and active projects normally stay in your browser or app.

encrypted

Temporary transfers

Projects you choose to transfer are encrypted before upload and designed to expire within 60 minutes.

tune

Optional access

Camera, Bluetooth, files, integrations, and printing are used only for the features you select.

sell

No data sales

We do not sell personal data or use your label content for third-party advertising.

This summary is only a guide. The complete Policy below explains important details, exceptions, and rights.

On this page

  1. Scope and who we are
  2. Data we handle
  3. Local and hosted processing
  4. Purposes and legal bases
  5. Device permissions
  6. Cookies and storage
  7. Data disclosures
  8. International transfers
  9. Retention
  10. Security
  11. Rights and choices
  12. Children
  13. Policy changes
  14. Contact
Read the Terms of Service arrow_forward

1. Scope and who we are

This Privacy Policy explains how Bino Solutions S.R.L. ("Bino Solutions", "Label Codes", "we", "us", or "our") handles personal data when you use the Label Codes marketing website at labelcodes.com, the label designer at app.labelcodes.com, our Label Codes mobile applications, project-transfer features, and related support or communications (together, the "Services").

Bino Solutions S.R.L., CUI 30248106, Reg. Com. J22/899/2012, is the controller for data used to operate, secure, support, and understand the Services. Our registered address is Bulevardul Primăverii 17B, Bl. G5, Sc. A, Et. 1, Ap. 7, 700171 Iași, Romania. You can contact us at contact@binosolutions.com.

When a business uses Label Codes to process personal data contained in its spreadsheets, inventory records, labels, or connected services, that business decides why and how the data is used. In that situation, the business is generally the controller and we act as its processor or service provider only to the extent that data is sent to our systems. Section 21 of our Terms of Service provides business data processing terms where applicable. Most label content is processed locally as described below. If another organization's privacy notice is presented to you—for example, by your employer, Shopify, Mobile Inventory, a print service, or an app store—that notice also applies to its own processing.

2. Data we handle

Depending on the features you choose, we may handle the following categories of data:

Category Examples How we receive it
Label, project, and inventory content Spreadsheet headers and cells; product names, SKUs, quantities, locations, barcodes, GS1 data, custom fields, text, images, logos, templates, layouts, paper settings, filenames, search/filter values, and project timestamps. You enter, import, generate, save, print, transfer, or retrieve it from a service you connect.
Account and integration data Name, email address, profile image, user or organization identifiers, session information, permissions, Shopify store domain, integration status, and imported Mobile Inventory or Shopify product fields. You provide it, an administrator provides it, or a connected service returns it when an account or integration feature is used.
Transfer and sharing data Encrypted project payload, token, six-letter transfer code, encryption metadata, payload size, expiry time, redemption status, IP address, and security/rate-limit logs. Generated when you choose to move or share a project between devices.
Device, file, and printer data Selected file name, type, size and contents; camera scan result; paired printer name and address stored by the Android app; printer availability, protocol, output mode, DPI, device/browser type, operating system, language, timezone, and network state. Your device provides it when you select a file, scan a transfer code, configure a printer, print, or use the Services.
Usage, diagnostic, and network data IP address, timestamps, pages and features used, clicks, referring URL, browser identifiers, app version, performance traces, crash details, stack traces, and sampled session-replay data. Collected automatically by our sites, applications, servers, and analytics or diagnostics providers.
Marketing and referral data UTM parameters, campaign/source labels, and advertising click identifiers such as gclid, gbraid, or wbraid. Included in links you follow to our marketing website and recorded when you interact with our pages.
Support and communications Name, email address, message contents, attachments, feedback, and our response history. You send it by email, support chat, form, app-store review, or another support channel.
Purchase information, if paid features are offered Product or plan, transaction identifier, store, currency, country, subscription status, and entitlement. We do not receive your full payment-card number from an app store or payment processor. An app store or payment processor sends us transaction and entitlement information.

We also create aggregated or de-identified statistics, such as feature usage and error rates. We may use and share information that cannot reasonably identify you for lawful analytics, security, research, product development, reporting, and business purposes. Where required by law, we will not attempt to re-identify it.

3. What stays local—and what does not

Label Codes is designed so that much of your work can happen on your device:

  • The Android app parses spreadsheets selected through the system file picker and stores active label projects in app-private storage.
  • The web designer normally parses CSV/XLS/XLSX files, generates barcodes, compresses uploaded images, renders labels, and creates PNG, SVG, PDF, ZIP, and project downloads in your browser.
  • The web designer automatically saves datasets, selected rows, images, templates, label settings, and paper settings in that site's browser storage so you can continue your work.
  • Direct Bluetooth printing sends rasterized print commands to your selected paired printer. The hosted designer may receive the printer's name, connection status, protocol, output mode, and DPI from the Android bridge, but not its Bluetooth address. Android System Print or a browser print dialog sends rendered content to the operating system and the print service or destination you choose.

Some features require network processing or disclose data to others:

  • Secure project transfer. When you choose to transfer a project, it is encrypted on your device using AES-256-GCM before upload. Our transfer service receives the encrypted payload and transfer metadata. The raw project key and plaintext project are not sent as part of the upload. Anyone with a valid QR link, token/key combination, or transfer code may be able to retrieve the project during the transfer window, so keep those credentials private.
  • Connected data sources. If you choose Mobile Inventory or Shopify, the Services communicate with those systems and our backend to authenticate the connection, retrieve fields and products, and prepare them for labels. A temporary inventory may be created for a Shopify import and is scheduled for best-effort deletion after retrieval.
  • Automated field detection. For eligible imported or connected datasets, the web designer automatically sends available column or field names—not the row values used in the current implementation—to our backend and then to Google Gemini, with OpenAI as a fallback, to suggest which field contains a barcode. Provider API inputs and outputs may be retained for abuse monitoring, security, legal compliance, and other periods allowed by the configured service and provider terms. Provider terms generally do not use paid/business API inputs and outputs to train general models by default unless the account opts in. Do not put sensitive personal data in column names.
  • Remote images and fonts. If a label refers to an image hosted elsewhere, your browser may request it directly from that host, disclosing ordinary request data such as your IP address and user agent. Google Fonts or similar font services receive request data when a hosted font is loaded.
  • Telemetry and support. Our analytics, error-monitoring, and support tools receive technical and interaction data. Session-replay tools may capture a sampled reconstruction of page interactions; sensitive transfer controls are masked or blocked where configured, but you should not put sensitive data into the Services unless necessary and lawful.

4. Why we use data and our legal bases

Purpose Typical legal basis in the EEA/UK
Provide the designer, app, imports, project storage, transfers, printing, downloads, integrations, accounts, and support you request. Performance of a contract or steps taken at your request before entering one.
Authenticate users, maintain sessions and entitlements, administer organizations, and process purchases. Contract performance; legal obligations for transaction records.
Secure the Services, rate-limit transfers, prevent fraud or abuse, investigate incidents, and enforce our Terms. Our legitimate interests in operating a safe, reliable service; legal obligations where applicable.
Diagnose errors, measure performance and usage, understand referral campaigns, and improve features and usability. Our legitimate interests, balanced against your rights; consent where required for storage, identifiers, analytics, or replay technology.
Answer messages, handle requests and disputes, and send service or policy notices. Contract performance, legitimate interests, and legal obligations.
Comply with law, court orders, tax/accounting rules, and valid government requests; protect rights, safety, and property. Legal obligation and legitimate interests.

We do not use Label Codes data to make decisions that produce legal or similarly significant effects about you without meaningful human involvement. If this changes, we will provide any notice and safeguards required by law.

5. Mobile and browser permissions

We request access only when it supports a feature you use:

  • Camera: scan a Label Codes project-transfer QR code. Camera frames are processed by the scanner and are not intentionally saved or uploaded by this feature; the decoded code is used to retrieve the transfer.
  • Bluetooth / nearby-device connection: list already paired printers, read their name and address, test a connection, and send a print job. The Android app does not use active Bluetooth discovery in the current version.
  • Files and downloads: read only files you select through the system picker and save files to destinations you choose. The Android app does not request broad storage or media-library access.
  • Internet and network state: load the hosted designer, obtain web resources, communicate with integrations, and create or redeem transfers.
  • Browser camera: if you click the web designer's transfer-scan option, scan a project-transfer QR code. Frames remain in the scanner workflow and are not intentionally uploaded by that feature.

The current Android app does not request location, microphone, contacts, calendars, notifications, phone/SMS, biometric, advertising-ID, or broad photo/media permissions. You can deny or revoke optional permissions in your device or browser settings. The related feature may then stop working, while other features should remain available where technically possible.

6. Cookies, browser storage, WebView data, and analytics

We and our providers use cookies, local storage, WebView storage/cache, SDK identifiers, and similar technologies:

  • Functional storage remembers your language, current design step, dataset, selected rows, project/template, label configuration, paper settings, account identifiers, authentication/session tokens, profile data, and support-chat guest identifier. The marketing website may keep a language-preference cookie for up to one year. The web designer's project storage has no automatic expiry and remains until the workflow clears or replaces it, or you clear site/app data.
  • Google Analytics and Firebase Analytics help us understand visits, sessions, devices, referrals, and feature use. The marketing website configures Google advertising, personalization, ad-storage, and analytics-storage consent as denied by default; limited measurement requests may still be sent without using those storage types. Firebase Analytics initializes when the relevant hosted web application loads.
  • Sentry provides error monitoring, performance tracing, and sampled session replay and initializes when the relevant website or hosted web application loads. On the marketing site, replay sampling may increase for error sessions or campaign visits, and diagnostic events may include default request/device data. Label Codes transfer credentials are removed from supported URL fragments before the web application's telemetry initializes.
  • Intercom initializes in the hosted web application to provide support and may use a persistent guest identifier or, if you sign in, your account name, email, and user identifier.

These analytics, diagnostic, and support providers currently initialize automatically on the relevant web pages, subject to any consent control applied in a particular deployment. They apply to our websites and hosted designer, including when the designer is displayed inside the app's WebView. The current native Android binary does not embed native Firebase Analytics, Sentry, Intercom, advertising, billing, or authentication SDKs.

You can clear or block browser storage in your browser settings, clear the Android app's storage, or uninstall the app. Blocking functional storage may erase your saved work or prevent features from operating. Because there is no consistent industry standard for browser "Do Not Track" signals, our Services do not respond uniformly to them. We do not use the Services to sell personal data or share it for cross-context behavioral advertising, so an opt-out signal for those activities should not change our current practices.

7. When we disclose data

We may disclose data only as reasonably necessary for the purposes in this Policy:

  • Infrastructure, security, analytics, field-suggestion, and support providers, including Cloudflare for website delivery/security; Google/Firebase for analytics, authentication, storage, app services, fonts, and Gemini field suggestions; Sentry for diagnostics and replay; Intercom for support; and OpenAI as a fallback field-suggestion provider. These providers process data under their own terms and our applicable agreements.
  • Services and destinations you choose, such as Mobile Inventory, Shopify, a remote image host, a paired printer, Android or browser print services, file-sharing destinations, and app stores.
  • Professional advisers and authorities when reasonably necessary to obtain legal, accounting, insurance, or security assistance; comply with law or valid legal process; investigate abuse; enforce agreements; or protect users, the public, our rights, property, or safety.
  • Corporate transaction participants in connection with a financing, reorganization, merger, acquisition, or sale of all or part of our business, subject to appropriate confidentiality and notice where required.
  • Other parties with your direction or consent.

We do not sell personal data. We do not share personal data for cross-context behavioral advertising or use Label Codes content for third-party advertising. We have not knowingly sold or shared personal information for those purposes during the preceding 12 months.

Providers may update over time as our Services change. Current provider privacy information is available from Cloudflare, Google, Gemini API data-use documentation, Firebase, Sentry, Intercom, and OpenAI.

8. International data transfers

We are based in Romania, and our providers—including Google Gemini and OpenAI for field suggestions—may process data in the European Economic Area, the United States, and other countries where they or their subprocessors operate. Those countries may have different data-protection laws. Where the GDPR, UK GDPR, or similar law requires safeguards, we use an adequacy decision, approved standard contractual clauses, or another lawful transfer mechanism, together with supplementary safeguards where appropriate. Contact us if you want more information about a relevant transfer mechanism.

9. How long we keep data

Retention depends on the data and feature:

  • Local projects and settings remain on your device or in browser storage until replaced, reset, cleared, or the app is uninstalled. Downloaded, exported, shared, and printed copies remain wherever you or a destination stored them.
  • Project transfers are designed to expire within 60 minutes. We attempt to delete the encrypted payload after successful import or at expiry. Non-reversible lookup tombstones used to prevent reuse may remain for up to 24 additional hours. Security and access logs may be kept longer where necessary for rate limiting, incident response, abuse prevention, and legal compliance.
  • Account and integration records remain while the account or integration is active and for a reasonable period afterward to complete deletion, prevent fraud, resolve disputes, maintain backups, and meet legal obligations. OAuth tokens and temporary import resources may remain until revoked, disconnected, expired, deleted by the relevant workflow, or removed under our retention process; provider, cache, and backup cycles may delay deletion.
  • Analytics and diagnostic data is retained according to our configured provider periods and only as long as reasonably necessary to measure trends, diagnose incidents, secure the Services, and improve reliability. We may keep aggregated or de-identified statistics longer.
  • Support, contractual, and transaction records remain as needed to handle the request or relationship and then for applicable limitation, accounting, tax, fraud-prevention, and recordkeeping periods.

We choose a retention period based on the amount, nature, and sensitivity of the data; the purpose for which we use it; security and abuse risks; available deletion controls; and legal requirements. Backups and provider caches may take additional time to cycle out, but access is restricted and the data is not restored except for continuity, security, or legal needs.

10. Security

We use administrative, technical, and organizational measures intended to protect personal data, including HTTPS, access controls, app-private storage, restricted WebView navigation, transfer encryption, rate limits, and credential scrubbing. No method of storage or transmission is completely secure, and we cannot guarantee absolute security. Protect your device, exported files, account credentials, QR links, encryption keys, and six-letter transfer codes. Notify us promptly if you believe the Services or your data have been compromised.

11. Your choices and privacy rights

Controls available to everyone

  • Clear or reset a web project in the designer, clear site data in your browser, or clear/uninstall the mobile app to remove local app data.
  • Deny or revoke camera and Bluetooth access in device/browser settings.
  • Disconnect Shopify or another integration from the applicable account/service controls, where available.
  • If you have a Label Codes account, use any available account-deletion control or email contact@binosolutions.com with the subject "Delete my Label Codes account." We may need to verify that you control the account.
  • Email us to withdraw consent for future processing where consent is the legal basis. Withdrawal does not affect processing already performed lawfully.

EEA, UK, and similar rights

Subject to applicable law and exceptions, you may ask to access, correct, erase, or restrict your personal data; receive portable data you provided; object to processing based on legitimate interests or to direct marketing; and withdraw consent. You may also complain to your local supervisory authority. In Romania, the authority is the National Supervisory Authority for Personal Data Processing (ANSPDCP).

United States state privacy rights

If a state privacy law applies to us and to your data, you may have rights to confirm processing; access, correct, or delete personal data; obtain a portable copy; opt out of sale, targeted advertising, or certain profiling; limit certain uses of sensitive data; appeal a denied request; and receive equal service when exercising a right. Label Codes does not currently sell personal data, share it for cross-context behavioral advertising, or perform qualifying profiling for decisions with legal or similarly significant effects. California residents may also request the categories and specific pieces of personal information collected, the sources, purposes, and categories of recipients. The categories collected in the preceding 12 months are described in Section 2.

To exercise a right, email contact@binosolutions.com with the subject "Privacy request" and identify the Service you used. We may request information reasonably necessary to verify your identity and authority. An authorized agent may submit a request where allowed by law, but we may require proof of authorization and direct identity verification. We aim to respond within the period required by applicable law and will explain any denial and available appeal.

We can directly act only on data controlled by us. Data stored solely on your device must be removed using your device/browser controls. For data controlled by your employer or another Label Codes customer, submit the request to that organization; we will assist it as required by our agreement and law.

12. Children

The Services are designed for business and general productivity use, are not directed to children under 16, and may not be used by them. We do not knowingly collect personal data from a child under 16. If you believe a child under 16 has used the Services or provided personal data, contact us so we can investigate and delete it where required.

13. Changes to this Policy

We may update this Policy to reflect changes in the Services, providers, law, or our practices. We will post the updated version and revise the effective date. If a change materially affects how we use personal data, we will provide additional notice through the Services, by email, or by another reasonable method when required. Where consent is required for a new use, we will request it.

14. Contact us

Bino Solutions S.R.L.
CUI 30248106 · Reg. Com. J22/899/2012
Bulevardul Primăverii 17B, Bl. G5, Sc. A, Et. 1, Ap. 7
700171 Iași, Romania
contact@binosolutions.com

For the fastest handling, use the subject line "Label Codes privacy request."

Logotip de Label Codes Label Codes

Crea etiquetes amb codis de barres o codis QR i etiquetes d’inventari a partir de fulls de càlcul. Organitza el disseny i imprimeix-les des del navegador.

Els nostres productes

Label Codes Blog de Label Codes ZapCount - AI Counter open_in_new Mobile Inventory open_in_new

Aspectes legals i assistència

Contacta amb el servei d’assistència Condicions del servei Política de privacitat Reconeixements
© Label Codes. Tots els drets reservats.
Desenvolupat per Bino Solutions