Label Codes logo Label Codes
Blog
search
English Español Français Português Română Deutsch Italiano Nederlands العربية עברית Русский Türkçe Bahasa Indonesia 简体中文 हिन्दी 日本語 한국어 Tiếng Việt বাংলা Polski ไทย Українська Bahasa Melayu Filipino فارسی தமிழ் Svenska Ελληνικά Čeština Magyar Dansk Suomi Norsk Català
No language found
design_services Etiketten erstellen
language

Authoritative English version. To keep every public notice accurate while translations are prepared, this legal document is currently provided in English. The English version controls except where mandatory law requires otherwise.

Legal

Privacy Policy

What Label Codes processes across the website, web label designer, project transfers, and iOS and Android apps, including the choices you have.

calendar_todayEffective September 17, 2026 verified_userVersion 2.1

At a glance

Privacy, in plain language

devices

Mostly local

Spreadsheet parsing, label rendering, downloads, and active projects normally stay in your browser or app.

encrypted

Temporary transfers

Projects you choose to transfer are encrypted before upload and designed to expire within 60 minutes.

tune

App analytics

The iOS app sends usage and crash diagnostics to Google Firebase. Native label content is not sent for analytics. Read the iOS details.

sell

No data sales

We do not sell personal data or use your label content for third-party advertising.

This summary is only a guide. The complete Policy below explains important details, exceptions, and rights.

On this page

  1. Scope and who we are
  2. Data we handle
  3. Local and hosted processing
  4. Purposes and legal bases
  5. Device permissions
  6. Cookies and storage
  7. iOS app privacy
  8. Data disclosures
  9. International transfers
  10. Retention
  11. Security
  12. Rights and choices
  13. Children
  14. Policy changes
  15. Contact
Read the Terms of Service arrow_forward

1. Scope and who we are

This Privacy Policy explains how Bino Solutions S.R.L. ("Bino Solutions", "Label Codes", "we", "us", or "our") handles personal data when you use the Label Codes marketing website at labelcodes.com, the label designer at app.labelcodes.com, our Label Codes mobile applications, project-transfer features, and related support or communications (together, the "Services").

Bino Solutions S.R.L., CUI 30248106, Reg. Com. J22/899/2012, is the controller for data used to operate, secure, support, and understand the Services. Our registered address is Bulevardul Primăverii 17B, Bl. G5, Sc. A, Et. 1, Ap. 7, 700171 Iași, Romania. You can contact us at contact@binosolutions.com.

When a business uses Label Codes to process personal data contained in its spreadsheets, inventory records, labels, or connected services, that business decides why and how the data is used. In that situation, the business is generally the controller and we act as its processor or service provider only to the extent that data is sent to our systems. Section 21 of our Terms of Service provides business data processing terms where applicable. Most label content is processed locally as described below. If another organization's privacy notice is presented to you (for example, by your employer, Shopify, Mobile Inventory, a print service, or an app store), that notice also applies to its own processing.

2. Data we handle

Depending on the features you choose, we may handle the following categories of data:

Category Examples How we receive it
Label, project, and inventory content Spreadsheet headers and cells; product names, SKUs, quantities, locations, barcodes, GS1 data, custom fields, text, images, logos, templates, layouts, paper settings, filenames, search/filter values, and project timestamps. You enter, import, generate, save, print, transfer, or retrieve it from a service you connect.
Account and integration data Name, email address, profile image, user or organization identifiers, session information, permissions, Shopify store domain, integration status, and imported Mobile Inventory or Shopify product fields. You provide it, an administrator provides it, or a connected service returns it when an account or integration feature is used.
Transfer and sharing data Encrypted project payload, token, six-letter transfer code, encryption metadata, payload size, expiry time, redemption status, IP address, and security/rate-limit logs. Generated when you choose to move or share a project between devices.
Device, file, and printer data Selected file name, type, size and contents; camera scan result; paired printer name and address stored by the Android app; iOS printer profiles including network host/port or Bluetooth peripheral identifier; printer availability, protocol, output mode, DPI, device/browser type, operating system, language, timezone, and network state. Your device provides it when you select a file, scan a transfer code, configure a printer, print, or use the Services.
Usage, diagnostic, and network data IP address, approximate location derived from IP address, timestamps, pages and features used, clicks, referring URL, browser and app-installation identifiers, app version, performance traces, crash details, stack traces, and sampled web session-replay data. The native iOS app's collection is described in Section 6, iOS app privacy. Collected automatically by our sites, applications, servers, and analytics or diagnostics providers.
Marketing and referral data UTM parameters, campaign/source labels, and advertising click identifiers such as gclid, gbraid, or wbraid. Included in links you follow to our marketing website and recorded when you interact with our pages.
Support and communications Name, email address, message contents, attachments, feedback, and our response history. You send it by email, support chat, form, app-store review, or another support channel.
Purchase information, if paid features are offered Product or plan, transaction identifier, store, currency, country, subscription status, and entitlement. We do not receive your full payment-card number from an app store or payment processor. An app store or payment processor sends us transaction and entitlement information.

We also create aggregated or de-identified statistics, such as feature usage and error rates. We may use and share information that cannot reasonably identify you for lawful analytics, security, research, product development, reporting, and business purposes. Where required by law, we will not attempt to re-identify it.

3. Local and hosted processing

Label Codes is designed so that much of your work can happen on your device:

  • The Android app parses spreadsheets selected through the system file picker and stores active label projects in app-private storage.
  • The native iOS app imports selected spreadsheets and images, edits projects, generates barcodes, renders labels, and prepares exports on your device. Projects, imported tables, and printer profiles are saved in app storage. Device backups and any cloud file provider you choose are governed by your device and provider settings.
  • The web designer normally parses CSV/XLS/XLSX files, generates barcodes, compresses uploaded images, renders labels, and creates PNG, SVG, PDF, ZIP, and project downloads in your browser.
  • The web designer automatically saves datasets, selected rows, images, templates, label settings, and paper settings in that site's browser storage so you can continue your work.
  • Direct Bluetooth printing sends rasterized print commands to your selected paired printer. The hosted designer may receive the printer's name, connection status, protocol, output mode, and DPI from the Android bridge, but not its Bluetooth address. Android System Print or a browser print dialog sends rendered content to the operating system and the print service or destination you choose.
  • On iOS, AirPrint sends rendered labels through Apple's print system to your selected destination. Direct network printing sends label commands to the printer host and port you configure without transport encryption. Supported Bluetooth LE printing sends label commands to your selected printer; encryption depends on the printer's configured link security. Use printers and networks you trust.

Some features require network processing or disclose data to others:

  • Secure project transfer. When you choose to transfer a project, it is encrypted on your device using AES-256-GCM before upload. Our transfer service receives the encrypted payload and transfer metadata. The raw project key and plaintext project are not sent as part of the upload. Anyone with a valid QR link, token/key combination, or transfer code may be able to retrieve the project during the transfer window, so keep those credentials private.
  • Connected data sources. If you choose Mobile Inventory or Shopify, the Services communicate with those systems and our backend to authenticate the connection, retrieve fields and products, and prepare them for labels. A temporary inventory may be created for a Shopify import and is scheduled for best-effort deletion after retrieval.
  • Automated field detection. For eligible imported or connected datasets, the web designer automatically sends available column or field names (excluding row values in the current implementation) to our backend and then to Google Gemini, with OpenAI as a fallback, to suggest which field contains a barcode. Provider API inputs and outputs may be retained for abuse monitoring, security, legal compliance, and other periods allowed by the configured service and provider terms. Provider terms generally do not use paid/business API inputs and outputs to train general models by default unless the account opts in. Do not put sensitive personal data in column names. The native iOS import workflow does not use this hosted field-detection feature.
  • Remote images and fonts. If a label refers to an image hosted elsewhere, your browser may request it directly from that host, disclosing ordinary request data such as your IP address and user agent. Google Fonts or similar font services receive request data when a hosted font is loaded.
  • Telemetry and support. Our analytics, error-monitoring, and support tools receive technical and interaction data. Web session-replay tools may capture a sampled reconstruction of page interactions; sensitive transfer controls are masked or blocked where configured, but you should not put sensitive data into the Services unless necessary and lawful. Native iOS analytics and crash reporting are described in Section 6.

4. Why we use data and our legal bases

Purpose Typical legal basis in the EEA/UK
Provide the designer, app, imports, project storage, transfers, printing, downloads, integrations, accounts, and support you request. Performance of a contract or steps taken at your request before entering one.
Authenticate users, maintain sessions and entitlements, administer organizations, and process purchases. Contract performance; legal obligations for transaction records.
Secure the Services, rate-limit transfers, prevent fraud or abuse, investigate incidents, and enforce our Terms. Our legitimate interests in operating a safe, reliable service; legal obligations where applicable.
Diagnose errors, measure performance and usage, understand referral campaigns, and improve features and usability. Our legitimate interests, balanced against your rights; consent where required for storage, identifiers, analytics, or replay technology.
Answer messages, handle requests and disputes, and send service or policy notices. Contract performance, legitimate interests, and legal obligations.
Comply with law, court orders, tax/accounting rules, and valid government requests; protect rights, safety, and property. Legal obligation and legitimate interests.

We do not use Label Codes data to make decisions that produce legal or similarly significant effects about you without meaningful human involvement. If this changes, we will provide any notice and safeguards required by law.

5. Mobile and browser permissions

We request access only when it supports a feature you use:

  • Camera: scan a Label Codes project-transfer QR code. Camera frames are processed by the scanner and are not intentionally saved or uploaded by this feature; the decoded code is used to retrieve the transfer.
  • Bluetooth / nearby-device connection: list already paired printers, read their name and address, test a connection, and send a print job. The Android app does not use active Bluetooth discovery in the current version.
  • iOS Bluetooth and local network: discover and connect to supported Bluetooth LE printers, and connect to network printers you configure. Saved profiles may contain printer names, network hosts and ports, Bluetooth peripheral identifiers, and print settings. These profiles are stored locally and are not added to native Firebase analytics or crash reports by the app.
  • Files and downloads: read only files you select through the system picker and save files to destinations you choose. The Android app does not request broad storage or media-library access.
  • Internet and network state: load the hosted designer, obtain web resources, communicate with integrations, and create or redeem transfers.
  • Browser camera: if you click the web designer's transfer-scan option, scan a project-transfer QR code. Frames remain in the scanner workflow and are not intentionally uploaded by that feature.

The current Android app does not request location, microphone, contacts, calendars, notifications, phone/SMS, biometric, advertising-ID, or broad photo/media permissions. You can deny or revoke optional permissions in your device or browser settings. The related feature may then stop working, while other features should remain available where technically possible.

6. Storage, analytics, and crash reporting

Websites and the hosted designer

We and our providers use cookies, local storage, WebView storage/cache, SDK identifiers, and similar technologies:

  • Functional storage remembers your language, current design step, dataset, selected rows, project/template, label configuration, paper settings, account identifiers, authentication/session tokens, profile data, and support-chat guest identifier. The marketing website may keep a language-preference cookie for up to one year. The web designer's project storage has no automatic expiry and remains until the workflow clears or replaces it, or you clear site/app data.
  • Google Analytics and Firebase Analytics help us understand visits, sessions, devices, referrals, and feature use. The marketing website configures Google advertising, personalization, ad-storage, and analytics-storage consent as denied by default; limited measurement requests may still be sent without using those storage types. Firebase Analytics initializes when the relevant hosted web application loads.
  • Sentry provides error monitoring, performance tracing, and sampled session replay and initializes when the relevant website or hosted web application loads. On the marketing site, replay sampling may increase for error sessions or campaign visits, and diagnostic events may include default request/device data. Label Codes transfer credentials are removed from supported URL fragments before the web application's telemetry initializes.
  • Intercom initializes in the hosted web application to provide support and may use a persistent guest identifier or, if you sign in, your account name, email, and user identifier.

These web analytics, diagnostic, and support providers currently initialize automatically on the relevant web pages, subject to any consent control applied in a particular deployment. They apply to our websites and hosted designer, including when the designer is displayed inside the Android app's WebView or opened from iOS in a browser view. Native mobile telemetry is separate: current Android and iOS builds include Firebase Analytics and Firebase Crashlytics.

You can clear or block browser storage in your browser settings, clear the Android app's storage, or uninstall the app. Blocking functional storage may erase your saved work or prevent features from operating. Because there is no consistent industry standard for browser "Do Not Track" signals, our Services do not respond uniformly to them. We do not use the Services to sell personal data or share it for cross-context behavioral advertising, so an opt-out signal for those activities should not change our current practices.

iOS app privacy: iPhone and iPad

The native iOS app uses Google Firebase Analytics to understand app usage and Firebase Crashlytics to diagnose crashes and improve reliability. Both start automatically in production builds on physical devices. The current iOS app does not provide an in-app switch to disable this collection. The app's local project storage does not prevent these separate diagnostic and usage requests.

  • Usage analytics: an app-instance identifier, automatic app lifecycle and session events, app version, device and operating-system information, language, and approximate location derived by Google from IP address. These identifiers can distinguish an installation even without an account. The app does not attach an account user ID or add custom label-content or print-content events.
  • Crash diagnostics: crash reports and stack traces, app state at the time of a crash, device and operating-system information, installation and session identifiers, and related diagnostic information. Firebase can include Analytics event breadcrumbs preceding a crash and session information used to measure stability.
  • Label content: the native app does not upload your spreadsheet rows, label text, barcode values, images, templates, or print previews for analytics. Content is shared when you choose a project transfer, export, sharing destination, or printer. Opening the hosted web designer uses the separate web processing described above.
  • Advertising and replay: the native iOS app uses the Analytics component without advertising-ID collection. Collection of Apple's vendor identifier, advertising storage, advertising user data, ad personalization, and automatic screen reporting are disabled. The native app does not include Sentry session replay or Intercom; those services can run on the hosted web pages you open.
  • Your controls: iOS permission controls let you restrict camera, Bluetooth, and local-network access. Those permissions do not control Firebase analytics or crash reporting. Clearing browser storage does not disable native Firebase collection. You can contact us about your privacy rights using Section 11; uninstalling the app stops future activity from that installation but does not automatically delete information already received by our providers.

Google processes this usage and diagnostic information for analytics and app reliability. See Firebase privacy information and Google Analytics data disclosures for iOS. Retention and privacy requests are covered in Sections 9 and 11.

7. When we disclose data

We may disclose data only as reasonably necessary for the purposes in this Policy:

  • Infrastructure, security, analytics, field-suggestion, and support providers, including Cloudflare for website delivery/security; Google/Firebase for analytics, native mobile crash reporting through Crashlytics, authentication, storage, app services, fonts, and Gemini field suggestions; Sentry for web diagnostics and replay; Intercom for web support; and OpenAI as a fallback field-suggestion provider. These providers process data under their own terms and our applicable agreements, depending on the platform and features you use.
  • Services and destinations you choose, such as Mobile Inventory, Shopify, a remote image host, a selected printer, AirPrint, Android or browser print services, file-sharing destinations, and app stores.
  • Professional advisers and authorities when reasonably necessary to obtain legal, accounting, insurance, or security assistance; comply with law or valid legal process; investigate abuse; enforce agreements; or protect users, the public, our rights, property, or safety.
  • Corporate transaction participants in connection with a financing, reorganization, merger, acquisition, or sale of all or part of our business, subject to appropriate confidentiality and notice where required.
  • Other parties with your direction or consent.

We do not sell personal data. We do not share personal data for cross-context behavioral advertising or use Label Codes content for third-party advertising. We have not knowingly sold or shared personal information for those purposes during the preceding 12 months.

Providers may update over time as our Services change. Current provider privacy information is available from Cloudflare, Google, Gemini API data-use documentation, Firebase, Sentry, Intercom, and OpenAI.

8. International data transfers

We are based in Romania, and our providers (including Google Firebase for mobile analytics and crash reporting, and Google Gemini and OpenAI for web field suggestions) may process data in the European Economic Area, the United States, and other countries where they or their subprocessors operate. Those countries may have different data-protection laws. Where the GDPR, UK GDPR, or similar law requires safeguards, we use an adequacy decision, approved standard contractual clauses, or another lawful transfer mechanism, together with supplementary safeguards where appropriate. Contact us if you want more information about a relevant transfer mechanism.

9. How long we keep data

Retention depends on the data and feature:

  • Local projects and settings remain on your device or in browser storage until replaced, reset, cleared, or the app is uninstalled. Downloaded, exported, shared, and printed copies remain wherever you or a destination stored them.
  • Project transfers are designed to expire within 60 minutes. We attempt to delete the encrypted payload after successful import or at expiry. Non-reversible lookup tombstones used to prevent reuse may remain for up to 24 additional hours. Security and access logs may be kept longer where necessary for rate limiting, incident response, abuse prevention, and legal compliance.
  • Account and integration records remain while the account or integration is active and for a reasonable period afterward to complete deletion, prevent fraud, resolve disputes, maintain backups, and meet legal obligations. OAuth tokens and temporary import resources may remain until revoked, disconnected, expired, deleted by the relevant workflow, or removed under our retention process; provider, cache, and backup cycles may delay deletion.
  • Analytics and diagnostic data is retained according to our configured provider periods and only as long as reasonably necessary to measure trends, diagnose incidents, secure the Services, and improve reliability. We may keep aggregated or de-identified statistics longer.
  • Support, contractual, and transaction records remain as needed to handle the request or relationship and then for applicable limitation, accounting, tax, fraud-prevention, and recordkeeping periods.

We choose a retention period based on the amount, nature, and sensitivity of the data; the purpose for which we use it; security and abuse risks; available deletion controls; and legal requirements. Backups and provider caches may take additional time to cycle out, but access is restricted and the data is not restored except for continuity, security, or legal needs.

10. Security

We use administrative, technical, and organizational measures intended to protect personal data, including HTTPS, access controls, app-private storage, restricted WebView navigation, transfer encryption, rate limits, and credential scrubbing. No method of storage or transmission is completely secure, and we cannot guarantee absolute security. Protect your device, exported files, account credentials, QR links, encryption keys, and six-letter transfer codes. Notify us promptly if you believe the Services or your data have been compromised.

11. Your choices and privacy rights

Controls available to everyone

  • Clear or reset a web project in the designer, clear site data in your browser, or clear/uninstall the mobile app to remove local app data.
  • Deny or revoke camera, Bluetooth, and local-network access in device/browser settings. These permission controls do not disable native iOS Firebase analytics or crash reporting; see iOS app privacy.
  • Disconnect Shopify or another integration from the applicable account/service controls, where available.
  • If you have a Label Codes account, use any available account-deletion control or email contact@binosolutions.com with the subject "Delete my Label Codes account." We may need to verify that you control the account.
  • Email us to withdraw consent for future processing where consent is the legal basis. Withdrawal does not affect processing already performed lawfully.

EEA, UK, and similar rights

Subject to applicable law and exceptions, you may ask to access, correct, erase, or restrict your personal data; receive portable data you provided; object to processing based on legitimate interests or to direct marketing; and withdraw consent. You may also complain to your local supervisory authority. In Romania, the authority is the National Supervisory Authority for Personal Data Processing (ANSPDCP).

United States state privacy rights

If a state privacy law applies to us and to your data, you may have rights to confirm processing; access, correct, or delete personal data; obtain a portable copy; opt out of sale, targeted advertising, or certain profiling; limit certain uses of sensitive data; appeal a denied request; and receive equal service when exercising a right. Label Codes does not currently sell personal data, share it for cross-context behavioral advertising, or perform qualifying profiling for decisions with legal or similarly significant effects. California residents may also request the categories and specific pieces of personal information collected, the sources, purposes, and categories of recipients. The categories collected in the preceding 12 months are described in Section 2.

To exercise a right, email contact@binosolutions.com with the subject "Privacy request" and identify the Service you used. We may request information reasonably necessary to verify your identity and authority. An authorized agent may submit a request where allowed by law, but we may require proof of authorization and direct identity verification. We aim to respond within the period required by applicable law and will explain any denial and available appeal.

We can directly act only on data controlled by us. Data stored solely on your device must be removed using your device/browser controls. For data controlled by your employer or another Label Codes customer, submit the request to that organization; we will assist it as required by our agreement and law.

12. Children

The Services are designed for business and general productivity use, are not directed to children under 16, and may not be used by them. We do not knowingly collect personal data from a child under 16. If you believe a child under 16 has used the Services or provided personal data, contact us so we can investigate and delete it where required.

13. Changes to this Policy

We may update this Policy to reflect changes in the Services, providers, law, or our practices. We will post the updated version and revise the effective date. If a change materially affects how we use personal data, we will provide additional notice through the Services, by email, or by another reasonable method when required. Where consent is required for a new use, we will request it.

14. Contact us

Bino Solutions S.R.L.
CUI 30248106 · Reg. Com. J22/899/2012
Bulevardul Primăverii 17B, Bl. G5, Sc. A, Et. 1, Ap. 7
700171 Iași, Romania
contact@binosolutions.com

For the fastest handling, use the subject line "Label Codes privacy request."

Label Codes logo Label Codes

Professioneller Barcode-Etiketten-Generator mit Drag-and-Drop-Oberfläche. Erstellen Sie benutzerdefinierte Etiketten mit QR-Codes, Barcodes und Firmenlogos. Kostenloses Online-Tool.

Our Products

Label Codes Label Codes Blog ZapCount - AI Counter open_in_new Mobile Inventory open_in_new

Legal & Support

Contact Support Terms of Service Privacy Policy Attributions
© Label Codes. Alle Rechte vorbehalten.
Developed by Bino Solutions